# Winlogbeat events not showing in AWS Elasticsearch

**URL:** <https://discuss.elastic.co/t/winlogbeat-events-not-showing-in-aws-elasticsearch/144572>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [August 15, 2018, 6:51pm UTC](https://discuss.elastic.co/t/winlogbeat-events-not-showing-in-aws-elasticsearch/144572 "2018-08-15T18:51:13Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![fionamacd](https://avatars.discourse-cdn.com/v4/letter/f/6a8cbe/32.png) [@fionamacd](https://discuss.elastic.co/u/fionamacd)\
**Post date:** [August 15, 2018, 6:51pm UTC](https://discuss.elastic.co/t/winlogbeat-events-not-showing-in-aws-elasticsearch/144572/1 "2018-08-15T18:51:13Z")

</div>

Hi,  
I am just starting out with ELK and setting it up on AWS and using AWS ElasticSearch Service.  
I have configured Filebeat to send files from my AWS Windows instance to an AWS Ubuntu instance running Logstash on it. This then sends them into an index in AWS ES.  
Now I am trying to do the same thing, but for Windows Event logs using winlogbeat. I want to send the events to the same logstash and then have it forward them into ES.

On the logstash instance I run in debug mode and I can see the winlogbeat events coming in - and no errors reported. When I go to Kibana on AWS I do not see any events have been loaded into any indexes.

Logstash input is:  
input {  
beats {  
port =\> 5044  
}  
output is:  
output {  
amazon\_es {  
hosts =\> "[search-cksw-es-iog34u5nroxxxx.us-east-1.es.amazonaws.com](http://search-cksw-es-iog34u5nroxxxx.us-east-1.es.amazonaws.com)"  
region =\> "us-east-1"  
port =\> "443"  
index =\> "test2"  
aws\_access\_key\_id =\> "AKIxxxx"  
aws\_secret\_access\_key =\> "gfcxxxx"  
flush\_size =\> 5  
}  
}

In the debug I can see lots of events like this:  
[DEBUG] 2018-08-15 18:49:18.311 [Ruby-0-Thread-7@[main]\>worker0: :1] pipeline - output received {"event"=\>{"event\_data"=\>{"param1"=\>"%%860", "param4"=\>"1.1.14305.0", "param5"=\>"1.255.236.0", "param2"=\>"4.10.209.0"}, "beat"=\>{"version"=\>"6.3.2", "name"=\>"winlogbeat", "hostname"=\>"DEV-CNK-01"}, "opcode"=\>"Info", "host"=\>{"name"=\>"winlogbeat"}, "type"=\>"wineventlog", "record\_number"=\>"105272", "event\_id"=\>1150, "@timestamp"=\>2017-10-30T12:07:50.000Z, "log\_name"=\>"System", "message"=\>"Endpoint Protection client is up and running in a healthy state.\n \tPlatform version: 4.10.209.0\n \tEngine version: 1.1.14305.0\n \tSignature version: 1.255.236.0", "fields"=\>{"env"=\>"staging"}, "tags"=\>["service-X", "web-tier", "beats\_input\_codec\_plain\_applied"], "computer\_name"=\>"DEV-CNK-01.ev.internal", "source\_name"=\>"Microsoft Antimalware", "level"=\>"Information", "keywords"=\>["Classic"], "@version"=\>"1"}}

Not sure what to check now?  
Fiona

---

<div class="post-metadata">

**Author:** ![chandra0651](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chandra0651/32/30484_2.png) [@chandra0651](https://discuss.elastic.co/u/chandra0651)\
**Post date:** [August 15, 2018, 8:45pm UTC](https://discuss.elastic.co/t/winlogbeat-events-not-showing-in-aws-elasticsearch/144572/2 "2018-08-15T20:45:54Z")

</div>

How about you try with regular ES output rather than using amazon es like below

```
elasticsearch {
       index = indexname;
       hosts => ["esurl:port"]
           ssl => true
         }
```

---

<div class="post-metadata">

**Author:** ![fionamacd](https://avatars.discourse-cdn.com/v4/letter/f/6a8cbe/32.png) [@fionamacd](https://discuss.elastic.co/u/fionamacd)\
**Post date:** [August 16, 2018, 3:26pm UTC](https://discuss.elastic.co/t/winlogbeat-events-not-showing-in-aws-elasticsearch/144572/3 "2018-08-16T15:26:03Z")

</div>

Thanks, but it is sending the filebeat input successfully to the AWS ES, just can't get the winlogbeat to also go there.

I did try changing the output as you suggested, but either with or without the port appended to the URL it failed to make the connection. I think it is because you need to use signed requests which is what the amazon\_es output lets you set up.

Here was an error:  
[WARN] 2018-08-16 15:21:42.463 [Ruby-0-Thread-4: :1] elasticsearch - Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[https://search-cksw-es-ixxxxx.us-east-1.es.amazonaws.com:9200/](https://search-cksw-es-ixxxxx.us-east-1.es.amazonaws.com:9200/)", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=\>"Elasticsearch Unreachable: [[https://search-cksw-es-ioxxxx.us-east-1.es.amazonaws.com:9200/](https://search-cksw-es-ioxxxx.us-east-1.es.amazonaws.com:9200/)][Manticore::ConnectTimeout] connect timed out"}

I modified the actual URL above for security reasons 🙂

I will give AWS Support a ping and see if they know anything.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 16, 2018, 4:49pm UTC](https://discuss.elastic.co/t/winlogbeat-events-not-showing-in-aws-elasticsearch/144572/4 "2018-08-16T16:49:29Z")

</div>

Even though you are using the AWS ES output you should still follow the same procedures we recommend (assuming the amazon\_es supports the same options).

- Write the data to a beat specific index. See how the ES output is configured here: [https://www.elastic.co/guide/en/elastic-stack-overview/6.3/get-started-elastic-stack.html#logstash-setup](https://www.elastic.co/guide/en/elastic-stack-overview/6.3/get-started-elastic-stack.html#logstash-setup)
- Manually install the Elasticsearch index template for Winlogbeat. [https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-template.html#load-template-manually](https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-template.html#load-template-manually)

You might be experiencing some kind of field conflict caused by not having the index template installed or because both Filebeat and Winlogbeat are writing to the same index. You could check your ES logs.

---

<div class="post-metadata">

**Author:** ![fionamacd](https://avatars.discourse-cdn.com/v4/letter/f/6a8cbe/32.png) [@fionamacd](https://discuss.elastic.co/u/fionamacd)\
**Post date:** [August 16, 2018, 7:21pm UTC](https://discuss.elastic.co/t/winlogbeat-events-not-showing-in-aws-elasticsearch/144572/5 "2018-08-16T19:21:45Z")

</div>

Ahah success!  
Not quite sure at this point what change I did that made it work, but I did use the manage\_template =\> false and the index tag shown in the example. Maybe there was a field conflict or something from the 2 indexes clashing before.  
Now I get have indexes like:  
winlogbeat-6.3.2-2015.05.05  
filebeat-6.3.2-2018.08.16  
Now I just need to start figuring out how to parse the log messages 🙂  
Thanks for the responses.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 16, 2018, 7:36pm UTC](https://discuss.elastic.co/t/winlogbeat-events-not-showing-in-aws-elasticsearch/144572/6 "2018-08-16T19:36:27Z")

</div>

> [@fionamacd](#):
>
> Now I just need to start figuring out how to parse the log messages 🙂

For Filebeat data, yep 😄.

If you are referring to Winlogbeat data, then why? Depending on the application, most of the data is already provided in a structured format under `event_data.*`. Usually you just need to apply some normalizations to establish some consistency between field names.

---

<div class="post-metadata">

**Author:** ![fionamacd](https://avatars.discourse-cdn.com/v4/letter/f/6a8cbe/32.png) [@fionamacd](https://discuss.elastic.co/u/fionamacd)\
**Post date:** [August 16, 2018, 8:09pm UTC](https://discuss.elastic.co/t/winlogbeat-events-not-showing-in-aws-elasticsearch/144572/7 "2018-08-16T20:09:49Z")

</div>

Yes, the winlogbeat logs look great - all nicely parsed like that!!!  
The filebeat logs are going to be fun....! 😱

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 13, 2018, 8:09pm UTC](https://discuss.elastic.co/t/winlogbeat-events-not-showing-in-aws-elasticsearch/144572/8 "2018-09-13T20:09:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
