# Winlogbeat.event\_logs adding level causes data to stop flowing into Elasticsearch

**URL:** <https://discuss.elastic.co/t/winlogbeat-event-logs-adding-level-causes-data-to-stop-flowing-into-elasticsearch/160967>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [December 14, 2018, 8:29pm UTC](https://discuss.elastic.co/t/winlogbeat-event-logs-adding-level-causes-data-to-stop-flowing-into-elasticsearch/160967 "2018-12-14T20:29:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jeffpool](https://avatars.discourse-cdn.com/v4/letter/j/7c8e57/32.png) [@jeffpool](https://discuss.elastic.co/u/jeffpool)\
**Post date:** [December 14, 2018, 8:29pm UTC](https://discuss.elastic.co/t/winlogbeat-event-logs-adding-level-causes-data-to-stop-flowing-into-elasticsearch/160967/1 "2018-12-14T20:29:43Z")

</div>

When I add level to any name, Application, Security or System, to only get those level events, the connection from the server in question, Windows Server 2008, breaks. Removing the level, and the connection comes back.  
config snip;  
winlogbeat.event\_logs:

- name: Application  
ignore\_older: 72h
- name: Security
- name: System  
This works fine.

This does not;  
winlogbeat.event\_logs:

- name: Application  
level: error  
ignore\_older: 72h
- name: Security  
level: critical, error, warning
- name: System  
level: error,warning

Confusion abounds.

---

<div class="post-metadata">

**Author:** ![jeffpool](https://avatars.discourse-cdn.com/v4/letter/j/7c8e57/32.png) [@jeffpool](https://discuss.elastic.co/u/jeffpool)\
**Post date:** [January 10, 2019, 4:38pm UTC](https://discuss.elastic.co/t/winlogbeat-event-logs-adding-level-causes-data-to-stop-flowing-into-elasticsearch/160967/2 "2019-01-10T16:38:06Z")

</div>

Has anyone had this problem?  
Is it a rookie config error?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 27, 2019, 4:12pm UTC](https://discuss.elastic.co/t/winlogbeat-event-logs-adding-level-causes-data-to-stop-flowing-into-elasticsearch/160967/3 "2019-01-27T16:12:48Z")

</div>

Are you sure that it's not working? Or is it just that there are very few events with `level:error` or `level:warning`. Looking at my events, the vast majority are `information`.

```auto
"level: Descending",Count
Information,"2,499,092"
Error,"1,021"
Warning,189
Critical,1

```

One test you could do is to

1. Use the Windows Event Viewer to verify that events with level error, warning, or critical exist.
2. Stop Winlogbeat.
3. Backup and then delete/move the registry file at `C:\ProgramData\winlogbeat\.winlogbeat.yml` so that it starts reading from the beginning of each event log.
4. Remove `ignore_older` from the config file.
5. Add `tags: [level_test]` to the config file so that it's easy to identify events from this test in Elasticsearch.
6. Add `level: critical, error, warning` to each of the event\_logs in your config file.
7. Start Winlogbeat and see if any events are written to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2019, 4:27pm UTC](https://discuss.elastic.co/t/winlogbeat-event-logs-adding-level-causes-data-to-stop-flowing-into-elasticsearch/160967/4 "2019-02-24T16:27:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
