# Winlogbeat logs only show that it is 6kb

**URL:** <https://discuss.elastic.co/t/winlogbeat-logs-only-show-that-it-is-6kb/327789>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 15, 2023, 9:07pm UTC](https://discuss.elastic.co/t/winlogbeat-logs-only-show-that-it-is-6kb/327789 "2023-03-15T21:07:20Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![iqworks](https://avatars.discourse-cdn.com/v4/letter/i/a9a28c/32.png) [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Post date:** [March 15, 2023, 9:07pm UTC](https://discuss.elastic.co/t/winlogbeat-logs-only-show-that-it-is-6kb/327789/1 "2023-03-15T21:07:20Z")

</div>

Hi, I am trying to get my Sysmon data to winlogbeat and then to security onion.

(unfortunatly, the sysmon.xml and winlogbeat.yml are too big to put here. I wish i could just attach them as files)

I am having two issues.  
1 – the winlogbeat logs where being fed continually, but now it is only getting the initial service start data.  
i might be mistaken , but i thought i saw these logs get full. It showed things like {"log.level":"error","@timestamp":"2023-02-08T **10:32:09.341-0800**","log.logger":"publisher\_pipeline\_output","log.origin":{"file.name":"pipeline/client\_worker.go","file.line":150},"message":" **Failed to connect to backoff** (**elasticsearch(**[**http://localhost:9200**](http://localhost:9200))): Get "[[http://localhost:9200](http://localhost:9200)]([http://localhost:9200/](http://localhost:9200/))": dial tcp [::1]:9200: connectex: No connection could be made because the target machine actively refused it.","service.name":"winlogbeat","ecs.version":"1.6.0"}

```auto
 

```

2 – I cannot seem to get my Sysmon data into security onion kibana. There are so many combinations of settings between Sysmon xml and winlogbeat.yml

---

<div class="post-metadata">

**Author:** ![Chenhui\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chenhui_wang/32/78869_2.png) [@Chenhui\_Wang](https://discuss.elastic.co/u/Chenhui_Wang)\
**Post date:** [March 16, 2023, 1:40am UTC](https://discuss.elastic.co/t/winlogbeat-logs-only-show-that-it-is-6kb/327789/2 "2023-03-16T01:40:26Z")

</div>

Hi @iqworks , probably you could post this to [Beats - Discuss the Elastic Stack](https://discuss.elastic.co/c/elastic-stack/beats/28) and I believe this can be better answered.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 16, 2023, 5:17am UTC](https://discuss.elastic.co/t/winlogbeat-logs-only-show-that-it-is-6kb/327789/3 "2023-03-16T05:17:46Z")

</div>

> [@iqworks](#):
>
> "message":" **Failed to connect to backoff** (**elasticsearch(** [**http://localhost:9200**](http://localhost:9200))):

That means winlogbeat can not connect to elasticsearch...

You have a connectivity issue...

Is elasticsearch running on the same server as winlogbeat?

Can you telnet or curl the elasticsearch endpoint?

> [@iqworks](#):
>
> (unfortunatly, the sysmon.xml and winlogbeat.yml are too big to put here. I wish i could just attach them as files)

You can anonymize them and put on pastebin or gist etc.

---

<div class="post-metadata">

**Author:** ![iqworks](https://avatars.discourse-cdn.com/v4/letter/i/a9a28c/32.png) [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Post date:** [March 16, 2023, 2:39pm UTC](https://discuss.elastic.co/t/winlogbeat-logs-only-show-that-it-is-6kb/327789/4 "2023-03-16T14:39:46Z")

</div>

thanks stephenb and Chenhui\_Wan for responding. are there any particular sections of winlogbeat or elasticsearch that you would like to look at? Ha, I thought this was the beats forum, I will post on beats as well. thx

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 16, 2023, 2:56pm UTC](https://discuss.elastic.co/t/winlogbeat-logs-only-show-that-it-is-6kb/327789/5 "2023-03-16T14:56:06Z")

</div>

I already fixed the tags...your fine

The output section on winlogbeat.yml would be the first thing

> [@stephenb](#):
>
> Is elasticsearch running on the same server as winlogbeat?
> 
> Can you telnet or curl the elasticsearch endpoint from the winlogbeat host?

Can you answer these ^^^

---

<div class="post-metadata">

**Author:** ![iqworks](https://avatars.discourse-cdn.com/v4/letter/i/a9a28c/32.png) [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Post date:** [March 16, 2023, 3:59pm UTC](https://discuss.elastic.co/t/winlogbeat-logs-only-show-that-it-is-6kb/327789/6 "2023-03-16T15:59:03Z")

</div>

I will try the telnet right now.

---

<div class="post-metadata">

**Author:** ![iqworks](https://avatars.discourse-cdn.com/v4/letter/i/a9a28c/32.png) [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Post date:** [March 16, 2023, 7:17pm UTC](https://discuss.elastic.co/t/winlogbeat-logs-only-show-that-it-is-6kb/327789/7 "2023-03-16T19:17:13Z")

</div>

I see now why my logs only contain 6kb of data. When I looked at the Current winlogbeat service parms.

"D:\vm workstation\winlogbeat\winlogbeat.exe" --environment=windows\_service -c "D:\vm workstation\winlogbeat\winlogbeat.yml" **--path.home**"D:\vm workstation\winlogbeat" **--path.data**  **_"C:\ProgramData\winlogbeat" --path.logs "C:\ProgramData\winlogbeat\logs" -E logging.files.redirect\_stderr=true._**

This is why all the log data went to the programdata folder and not my vm workstation folder.

I need to be sending my path.data and path.logs to "D:\vm workstation\winlogbeat" and not _ **"C:\ProgramData\winlogbeat\logs".** _ I am trying to google what the syntax is to changes these paths in my winlogbeat.yml?  
So I have to look at the syntax for changing the #path.data: ${path.home}/data and the path.logs. Would you happen to know that off the top of your head?  
I saw this  
path.logs: /var/log/  
path.logs: /var/data/  
i think i need to do  
d:/vm workstation/winlogbeat/var/log?  
then /var/data? the Path.home looks like it is setup correctly.  
thanks for your time stephan

---

<div class="post-metadata">

**Author:** ![iqworks](https://avatars.discourse-cdn.com/v4/letter/i/a9a28c/32.png) [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Post date:** [March 16, 2023, 7:20pm UTC](https://discuss.elastic.co/t/winlogbeat-logs-only-show-that-it-is-6kb/327789/8 "2023-03-16T19:20:33Z")

</div>

I have to take some time to learn about  
anonymize them and put on pastebin or gist etc. But thanks for the tip about the connection not working, I will look at that some more.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 16, 2023, 7:25pm UTC](https://discuss.elastic.co/t/winlogbeat-logs-only-show-that-it-is-6kb/327789/9 "2023-03-16T19:25:08Z")

</div>

Hmm Curious are you confusing the logs that winlogbeat produces when it runs vs the logs you want winlog beat to harvest?

This is where winlogbeat send its **own** logs not the logs it reads and send to elastic.  
_ **-path.logs "C:\ProgramData\winlogbeat\logs"** _

Where winlogbeat reads logs and ships them to elastic is in the winlogbeat.yml or modules yml

Also did you get the telnet to work?

If you are new I would try a very basic example which you can follow with the [quickstart guide](https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-installation-configuration.html)

We often see folks following someones else post or blog etc that is out of date or wrong...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2023, 7:25pm UTC](https://discuss.elastic.co/t/winlogbeat-logs-only-show-that-it-is-6kb/327789/10 "2023-04-13T19:25:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
