# Winlogbeat.event\_logs not working properly

**URL:** <https://discuss.elastic.co/t/winlogbeat-event-logs-not-working-properly/136871>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [June 21, 2018, 1:10pm UTC](https://discuss.elastic.co/t/winlogbeat-event-logs-not-working-properly/136871 "2018-06-21T13:10:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Astarandel](https://avatars.discourse-cdn.com/v4/letter/a/4da419/32.png) [@Astarandel](https://discuss.elastic.co/u/Astarandel)\
**Post date:** [June 21, 2018, 1:10pm UTC](https://discuss.elastic.co/t/winlogbeat-event-logs-not-working-properly/136871/1 "2018-06-21T13:10:12Z")

</div>

Hello guys,

I'm testing a setup atm where Winlogbeat sends Windows events logs to Graylog server.

I wanted to limit the number of events Winlogbeat is collecting, so I tried to use winlogbeat.event\_logs.

Here is my winlogbeat.yml file:

```
fields:
  collector_node_id: graylog-collector-sidecar
  gl2_source_collector: 5b5a24c2-71b7-44ce-8310-e2d99f33b5bb

output:
  logstash:
    hosts:
    - 10.1.10.30:5044

path:
  data: C:\Program Files\graylog\collector-sidecar\cache\winlogbeat\data
  logs: C:\Program Files\graylog\collector-sidecar\logs

tags:
- windows

winlogbeat.event_logs:
  - name: Application
    level: critical, error, warning
  - name: System
    level: critical, error, warning
  - name: Security
    level: critical, error, warning

```

Unfortunately, I don't notice any difference in the number of events.

Can you please help me out? Thanks in advance!!

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [June 21, 2018, 1:13pm UTC](https://discuss.elastic.co/t/winlogbeat-event-logs-not-working-properly/136871/2 "2018-06-21T13:13:50Z")

</div>

Could you please format you config using `</>`? Also could you please share debug logs?

---

<div class="post-metadata">

**Author:** ![Astarandel](https://avatars.discourse-cdn.com/v4/letter/a/4da419/32.png) [@Astarandel](https://discuss.elastic.co/u/Astarandel)\
**Post date:** [June 21, 2018, 1:54pm UTC](https://discuss.elastic.co/t/winlogbeat-event-logs-not-working-properly/136871/3 "2018-06-21T13:54:52Z")

</div>

Hello Noémi,

thanks for your quick answer.

Sorry but I m a real newbie when it comes to Winlogbeat. I just started tests yesterday.

If by debug logs you mean the ones stored in:

C:\Program Files\Graylog\collector-sidecar\logs

Here they are.

 ![log2](https://us1.discourse-cdn.com/elastic/original/3X/2/1/21b32526c442e63e71082421b998f7008fb95848.JPG) ![log](https://us1.discourse-cdn.com/elastic/original/3X/9/5/956437c7f32af28f94fbfe356418383ea1dfe44f.JPG)

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [June 22, 2018, 8:39am UTC](https://discuss.elastic.co/t/winlogbeat-event-logs-not-working-properly/136871/4 "2018-06-22T08:39:41Z")

</div>

Based on your logs filtering conditions are passed to Winlogbeat correctly. You might need to filter out more events, if you would like to decrease the number of events further.

You could also filter based on event IDs. This could limit the unwanted events number. [https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#\_literal\_event\_logs\_event\_id\_literal](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#_literal_event_logs_event_id_literal)

---

<div class="post-metadata">

**Author:** ![Astarandel](https://avatars.discourse-cdn.com/v4/letter/a/4da419/32.png) [@Astarandel](https://discuss.elastic.co/u/Astarandel)\
**Post date:** [June 22, 2018, 10:50am UTC](https://discuss.elastic.co/t/winlogbeat-event-logs-not-working-properly/136871/5 "2018-06-22T10:50:03Z")

</div>

It's weird because I still see mostly messages that are tagged as "information". When I check my event history I don't see any decrease in the events amount. Is there any other way to test Winlogbeat outside the Graylog environment?

---

<div class="post-metadata">

**Author:** ![Astarandel](https://avatars.discourse-cdn.com/v4/letter/a/4da419/32.png) [@Astarandel](https://discuss.elastic.co/u/Astarandel)\
**Post date:** [June 22, 2018, 12:02pm UTC](https://discuss.elastic.co/t/winlogbeat-event-logs-not-working-properly/136871/6 "2018-06-22T12:02:15Z")

</div>

I have found the issue. Apparently Graylog overwrittes any conf changes if they are not done through its interface.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2018, 12:02pm UTC](https://discuss.elastic.co/t/winlogbeat-event-logs-not-working-properly/136871/7 "2018-07-20T12:02:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
