# Winlogbeat Fatal Error 8.7.0+ name already used

**URL:** <https://discuss.elastic.co/t/winlogbeat-fatal-error-8-7-0-name-already-used/337093>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [June 28, 2023, 2:00pm UTC](https://discuss.elastic.co/t/winlogbeat-fatal-error-8-7-0-name-already-used/337093 "2023-06-28T14:00:46Z")\
**Posts on this page:** 1\
**Showing post:** 11

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 6, 2023, 7:10pm UTC](https://discuss.elastic.co/t/winlogbeat-fatal-error-8-7-0-name-already-used/337093/11 "2023-07-06T19:10:35Z")

</div>

> [@dwissm1](#):
>
> ```auto
> winlogbeat.event_logs:
> - name: Application
> event_id: 1000, 1002
> ignore_older: 72h
> level: error
> provider:
> - Application Error
> - Application Hang
> - name: Application
> event_id: 1001
> ignore_older: 72h
> level: info
> provider:
> - Windows Error Reporting
> 
> ```

If you run two separate readers on the same channel (e.g. `Application`) you should set an explicit `id` value such that each reader can independently store a bookmark/checkpoint into the registry. By default the `name` value is used in the registry. So with this config both readers are clobbering each other's state. After a restart the readers may not begin at the correct starting point because of this.

The docs for `id` are at [Configure Winlogbeat | Winlogbeat Reference [8.11] | Elastic](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#_event_logs_id).

So change it like this:

```auto
  - name: Application
    id: application-error-hang # <-- Set a unique ID here.
    event_id: 1000, 1002
    ignore_older: 72h
    level: error
    provider:
      - Application Error
      - Application Hang
  - name: Application
    id: application-wer # <-- Set a unique ID here.
    event_id: 1001
    ignore_older: 72h
    level: info
    provider:
      - Windows Error Reporting

```

The panic was not intentionally added to enforce this best practice. It was an unintended side-effect of instrumenting each event log reader with its own [metrics](https://www.elastic.co/guide/en/beats/winlogbeat/master/metrics-winlogbeat.html) that you can view if you add this to your config. The unique ID is used to associate each reader instance to its metrics.

```yaml
# Exposes metrics at http://127.0.0.1:5066/inputs/?pretty
http.host: 127.0.0.1
http.port: 5066

```

---

_[View the full topic](https://discuss.elastic.co/t/winlogbeat-fatal-error-8-7-0-name-already-used/337093)._
