# Winlogbeat events not parsed

**URL:** <https://discuss.elastic.co/t/winlogbeat-events-not-parsed/318518>\
**Category:** Logstash\
**Created:** [November 9, 2022, 8:03am UTC](https://discuss.elastic.co/t/winlogbeat-events-not-parsed/318518 "2022-11-09T08:03:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vitkon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitkon/32/97669_2.png) [@vitkon](https://discuss.elastic.co/u/vitkon)\
**Post date:** [November 9, 2022, 8:03am UTC](https://discuss.elastic.co/t/winlogbeat-events-not-parsed/318518/1 "2022-11-09T08:03:58Z")

</div>

Hello,  
I am using elasticstack v8. The messages are sent from winlogbeat -\> logstash -\> elastic. The message is arrived unparsed.  
Logstash config:

```auto
input {
        beats {
                port => "5044"
                client_inactivity_timeout => 360
                ssl => true
                ssl_cettificate => "/app/logstash/certs/${HOSTNAME}.cer"
                ssl_key => "/app/logstash/certs/${HOSTNAME}-pkcs8.key"
                tls_min_version => 1.2
        }
}
filter {
   mutate{ add_tag=> ["${PIPELINE_TAG}"] }
}
output {
        elasticsearch {
                 hosts => ["https://X.X.X.X:9200","https://X.X.X.X:9200","https://X.X.X.X:9200"]
                  index => "winlogbeat-%{[@metadata][version]}"
                 user => "XX"
                 password => "XX"
                 ssl => true
                 ssl_certificate_verification => "true"
                 cacert => "/app/logstash/certs/ca/ca.cer"
                 manage_template => false
                 ilm_enabled => true
                 pipeline => "winlogbeat-8.0.0-routing"
                
        }
}

```

winlogbeat config:

```auto
winlogbeat.event_logs:
  - name: Application
    ignore_older: 72h
  - name: Security
  - name: System
  - name: ForwardedEvents
    tags: ["forwarder"]

setup.template.settings:
  index.number_of_shards: 1

max_procs: 1
keystore.path: ${path.home}/winlogbeat.keystore

output.logstash:
  hosts: ["https://server1:5044", "https://server2:5044"]
  loadbalance : false
  worker: 1
  pipelining: 0
  bulk_max_size: 2048
  backoff.max: 300s
  ssl:
    enabled: true
    verification_mode: full
    supported_protocol: [TLSv1.2, TLSv1.3]
    certificate_authorities: ${path.home}/rootCA.cer
processors:
   - translate_sid:
       field: winlog.event_data.MemberSid
       account_name_target: user.name
       domain_target: user.domain
       ignore_missing: true
       ignore_failure: true

```

I loaded the winlogbeat pipelines modules manually into elasticsearch with the  
PS \> command .\winlogbeat.exe setup --pipelines

The messages are received to elastic but they are not indexed

 ![winlog](https://us1.discourse-cdn.com/elastic/original/3X/c/d/cd713cb32f5751e9f7115bdf9ecb62c760cf5694.png)

Any suggestions where I missed the configuration

---

<div class="post-metadata">

**Author:** ![vitkon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitkon/32/97669_2.png) [@vitkon](https://discuss.elastic.co/u/vitkon)\
**Post date:** [November 11, 2022, 9:08am UTC](https://discuss.elastic.co/t/winlogbeat-events-not-parsed/318518/2 "2022-11-11T09:08:50Z")

</div>

I didn't find the root of the problem, reinstalled the cluster and connected winlogbeat again, everything worked

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 9, 2022, 9:08am UTC](https://discuss.elastic.co/t/winlogbeat-events-not-parsed/318518/3 "2022-12-09T09:08:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
