# Winlogbeat lost logs

**URL:** <https://discuss.elastic.co/t/winlogbeat-lost-logs/195127>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [August 14, 2019, 3:01am UTC](https://discuss.elastic.co/t/winlogbeat-lost-logs/195127 "2019-08-14T03:01:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![cmz729268499](https://avatars.discourse-cdn.com/v4/letter/c/48db29/32.png) [@cmz729268499](https://discuss.elastic.co/u/cmz729268499)\
**Post date:** [August 14, 2019, 3:01am UTC](https://discuss.elastic.co/t/winlogbeat-lost-logs/195127/1 "2019-08-14T03:01:02Z")

</div>

I installed winlogbeat6.4 on windows server 2008R2 and sent the log to logstash. When I set ignore\_older to 5S, I found that some logs were lost. What is the reason?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [August 14, 2019, 5:41pm UTC](https://discuss.elastic.co/t/winlogbeat-lost-logs/195127/2 "2019-08-14T17:41:37Z")

</div>

Probably timing

You're asking the windows event system to process and store an event, the windows OS to schedule winlogbeat, and winlogbeat to query events since it's last poll to find this new event before 5s elapse.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 11, 2019, 5:41pm UTC](https://discuss.elastic.co/t/winlogbeat-lost-logs/195127/3 "2019-09-11T17:41:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
