# Winlogbeat: Logstash as forensic investigator

**URL:** <https://discuss.elastic.co/t/winlogbeat-logstash-as-forensic-investigator/67612>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [November 30, 2016, 12:45pm UTC](https://discuss.elastic.co/t/winlogbeat-logstash-as-forensic-investigator/67612 "2016-11-30T12:45:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![xsallowed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xsallowed/32/28971_2.png) [@xsallowed](https://discuss.elastic.co/u/xsallowed)\
**Post date:** [November 30, 2016, 12:45pm UTC](https://discuss.elastic.co/t/winlogbeat-logstash-as-forensic-investigator/67612/1 "2016-11-30T12:45:22Z")

</div>

Hi  
I am trying to parse log files collected as part of forensic investigation from windows machine and wondering how can i make winlogbeat to parse logs from files and ship it to logstash server?

Do we have a winlogbeat for linux as well so that i can run winlogbeat on my linux machine to ship logs to logstash or if there is any other way to read these files?

Regards  
TS

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 30, 2016, 2:29pm UTC](https://discuss.elastic.co/t/winlogbeat-logstash-as-forensic-investigator/67612/2 "2016-11-30T14:29:04Z")

</div>

Winlogbeat cannot directly read .evt or .evtx files. It uses the Windows APIs to read from the events logs since the file format is proprietary. There are some libraries people have written by reverse engineering the format. It would be cool to integrate those into Winlogbeat (then it could run on linux too), but no one has contributed this feature. There is a mention of the feature in [https://github.com/elastic/beats/issues/465#issuecomment-163352546](https://github.com/elastic/beats/issues/465#issuecomment-163352546) but we have no firm plans for implementing it.

---

<div class="post-metadata">

**Author:** ![xsallowed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xsallowed/32/28971_2.png) [@xsallowed](https://discuss.elastic.co/u/xsallowed)\
**Post date:** [December 3, 2016, 11:18am UTC](https://discuss.elastic.co/t/winlogbeat-logstash-as-forensic-investigator/67612/3 "2016-12-03T11:18:12Z")

</div>

Thank you for your reply. I have just started using ELK stack and absolutely in love with it. Thanks for liberating me from splunk but I am anxious to see what else i can do with ELK as a forensic investigator.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 31, 2016, 11:18am UTC](https://discuss.elastic.co/t/winlogbeat-logstash-as-forensic-investigator/67612/4 "2016-12-31T11:18:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
