# Winlogbeat - How to determine correct channel names

**URL:** <https://discuss.elastic.co/t/winlogbeat-how-to-determine-correct-channel-names/136722>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [June 20, 2018, 3:00pm UTC](https://discuss.elastic.co/t/winlogbeat-how-to-determine-correct-channel-names/136722 "2018-06-20T15:00:10Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![L33T](https://avatars.discourse-cdn.com/v4/letter/l/dbc845/32.png) [@L33T](https://discuss.elastic.co/u/L33T)\
**Post date:** [June 20, 2018, 3:00pm UTC](https://discuss.elastic.co/t/winlogbeat-how-to-determine-correct-channel-names/136722/1 "2018-06-20T15:00:10Z")

</div>

Hi,

How do you set which event logs are collection in the winlogbeat.yml config file. I have some event logs for Hyper-V that are Application And Service Logs and are not in the windows logs section of the event viewer?

e.g. event log: Applications and service logs\microsoft\windows\Hyper-V-VMMS

thanks in advance.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 20, 2018, 3:13pm UTC](https://discuss.elastic.co/t/winlogbeat-how-to-determine-correct-channel-names/136722/2 "2018-06-20T15:13:44Z")

</div>

You add a new item to the `winlogbeat.event_logs` list. See [https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#configuration-winlogbeat-options-event\_logs-name](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#configuration-winlogbeat-options-event_logs-name).

```auto
winlogbeat.event_logs:
  - name: '<Name of the event log>'

```

---

<div class="post-metadata">

**Author:** ![L33T](https://avatars.discourse-cdn.com/v4/letter/l/dbc845/32.png) [@L33T](https://discuss.elastic.co/u/L33T)\
**Post date:** [June 20, 2018, 3:21pm UTC](https://discuss.elastic.co/t/winlogbeat-how-to-determine-correct-channel-names/136722/3 "2018-06-20T15:21:46Z")

</div>

Done that mate but cannot get any events for those in the Application and Service logs. Hard to describe without pictures ☹

My config:  
ignore\_older: 72h  
- name: Security  
event\_id: -4776  
- name: System  
- name: Hyper-V-High\_Availabilty  
- name: Hyper-V-VMMS  
- name: Hyper-V-Hypervisor

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 20, 2018, 3:48pm UTC](https://discuss.elastic.co/t/winlogbeat-how-to-determine-correct-channel-names/136722/4 "2018-06-20T15:48:19Z")

</div>

> [@L33T](#):
>
> Done that

So you ran the command listed in the docs to get the event log names?

`PS C:\> Get-WinEvent -ListLog * | Format-List -Property LogName`

I think you can make it `Get-WinEvent -ListLog * | Format-List -Property LogName | Select-String -Pattern "Hyper-V"` to filter. Please share the command's output.

---

<div class="post-metadata">

**Author:** ![L33T](https://avatars.discourse-cdn.com/v4/letter/l/dbc845/32.png) [@L33T](https://discuss.elastic.co/u/L33T)\
**Post date:** [June 20, 2018, 4:00pm UTC](https://discuss.elastic.co/t/winlogbeat-how-to-determine-correct-channel-names/136722/5 "2018-06-20T16:00:06Z")

</div>

Ah forgot about that 😉

Would that cover all sub folder items also as Hyper-V has a bunch of folders within the root hyper-v.

Thanks,

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 20, 2018, 4:14pm UTC](https://discuss.elastic.co/t/winlogbeat-how-to-determine-correct-channel-names/136722/6 "2018-06-20T16:14:32Z")

</div>

Each channel must be individually declared in the `winlogbeat.event_logs` list in order for it to be read.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 18, 2018, 6:14pm UTC](https://discuss.elastic.co/t/winlogbeat-how-to-determine-correct-channel-names/136722/7 "2018-07-18T18:14:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
