# Winlogbeat MSI create service

**URL:** <https://discuss.elastic.co/t/winlogbeat-msi-create-service/227267>\
**Category:** Beats\
**Tags:** windows-installer, winlogbeat\
**Created:** [April 9, 2020, 7:46am UTC](https://discuss.elastic.co/t/winlogbeat-msi-create-service/227267 "2020-04-09T07:46:50Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![bernhard.fluehmann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bernhard.fluehmann/32/71755_2.png) [@bernhard.fluehmann](https://discuss.elastic.co/u/bernhard.fluehmann)\
**Post date:** [April 9, 2020, 7:46am UTC](https://discuss.elastic.co/t/winlogbeat-msi-create-service/227267/1 "2020-04-09T07:46:50Z")

</div>

I have installed Winlogbeat 7.6.2 with the new MSI installer. The installer works very well and simplifies installation and maintenance of beats on Windows hosts. The only problem is that the installer does not contain an option to run the beat as a service. As well, there is no create-service script available anymore as with older versions. As a workaround I have modified the service script of 7.4.2 to fit to the new directory structure. Please let me know the reason why the service creation part is missing and what your proposed solution is to run a beat as a service using MSI.  
Kind regards  
Bernhard

---

<div class="post-metadata">

**Author:** ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)\
**Post date:** [April 9, 2020, 8:16am UTC](https://discuss.elastic.co/t/winlogbeat-msi-create-service/227267/2 "2020-04-09T08:16:33Z")

</div>

Hi @bernhard.fluehmann - Before I share more information with you, the MSI for Winlogbeat is still in Beta version.

From my understanding, the MSI creates the service. However, as raised in this [issue](https://github.com/elastic/beats/issues/16773), there is a lack of documentation around the steps required for installing/configuring Winlogbeat when using the MSI.

---

<div class="post-metadata">

**Author:** ![bernhard.fluehmann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bernhard.fluehmann/32/71755_2.png) [@bernhard.fluehmann](https://discuss.elastic.co/u/bernhard.fluehmann)\
**Post date:** [April 9, 2020, 8:46am UTC](https://discuss.elastic.co/t/winlogbeat-msi-create-service/227267/3 "2020-04-09T08:46:53Z")

</div>

Hi @ropc - Thank you for your fast reply. I am aware about the Beta state. Nevertheless MSI is the preferred way to install software on windows and I guess people start using it as soon as it is available even if not GA. As a side note, MSI for Elasticsearch is now in beta since 6.8 which is a long time. I have just opened an issue with a request to put it to GA.

Thank you for pointing me to the [issue](https://github.com/elastic/beats/issues/16773). As described there it seems that the installer should actually create the service, which is not the case on my installs (Windows Server 2019 and Windows 10). As already mentioned, creating the service manually works. This is why I thought the service piece was missing in the installer.

---

<div class="post-metadata">

**Author:** ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)\
**Post date:** [April 9, 2020, 9:01am UTC](https://discuss.elastic.co/t/winlogbeat-msi-create-service/227267/4 "2020-04-09T09:01:11Z")

</div>

You're welcome @bernhard.fluehmann. Do take note that Winlogbeat is not supported on Windows 10 and it is supported on Windows Server 2019 starting from version 7.4.x. Please refer to our [support matrix](https://www.elastic.co/support/matrix#matrix_os) for further details.

---

<div class="post-metadata">

**Author:** ![bernhard.fluehmann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bernhard.fluehmann/32/71755_2.png) [@bernhard.fluehmann](https://discuss.elastic.co/u/bernhard.fluehmann)\
**Post date:** [April 9, 2020, 9:52am UTC](https://discuss.elastic.co/t/winlogbeat-msi-create-service/227267/5 "2020-04-09T09:52:19Z")

</div>

Ok. The reason why I installed it on Windows 10 was to double check with another version. If Win 10 is not supported, fine. Let's focus on Windows 2019 then. What I am interested in is to know if the service creation is missing at all or just on my install. The [issue](https://github.com/elastic/beats/issues/16773) deals more with documentation issues which is not a problem for me since I understand the file structure and it makes sense. If run with defaults, the installer even opens the ProgramData folder where the config file has to be placed, which is very handy.

---

<div class="post-metadata">

**Author:** ![ygel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ygel/32/55561_2.png) [@ygel](https://discuss.elastic.co/u/ygel)\
**Post date:** [April 9, 2020, 1:47pm UTC](https://discuss.elastic.co/t/winlogbeat-msi-create-service/227267/6 "2020-04-09T13:47:39Z")

</div>

Hello @bernhard.fluehmann!

Please let me clarify this a bit. Beats MSI packages do install windows services where appropriate and add CLI support as well. They do not start the service though. Reason for that is outlined in the last screen of the installer - package doesn't contain a good configuration file.

We plan to add support for configuration migration on upgrades as well as bundling user-supplied configuration files to be installed when MSI runs.

About Windows 10: while Win10 is a client SKU and not officially supported, it shares vast amounts of code with server SKUs. There is no technical reason that I am aware of that would preclude Winlogbeat from working on a Professional variant, I cannot vouch for Home variant.

Have a great day!

![image](https://us1.discourse-cdn.com/elastic/original/3X/5/3/535a571f8d5f623296fa66951b7827348b9ee74d.png)

---

<div class="post-metadata">

**Author:** ![bernhard.fluehmann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bernhard.fluehmann/32/71755_2.png) [@bernhard.fluehmann](https://discuss.elastic.co/u/bernhard.fluehmann)\
**Post date:** [April 9, 2020, 3:19pm UTC](https://discuss.elastic.co/t/winlogbeat-msi-create-service/227267/7 "2020-04-09T15:19:36Z")

</div>

Hi @ygel  
Thank you for the explanation. It finally got it working. As described in the helptext the display name of the service is `Elastic <beatname> <version>`. I missed that peace since in zip beat package, name and displayname were the same 🙂. Thanks again for your fast help @ygel and @ropc

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2020, 3:19pm UTC](https://discuss.elastic.co/t/winlogbeat-msi-create-service/227267/8 "2020-05-07T15:19:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
