# Winlogbeat - not getting all the logs

**URL:** <https://discuss.elastic.co/t/winlogbeat-not-getting-all-the-logs/302222>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [April 12, 2022, 12:11pm UTC](https://discuss.elastic.co/t/winlogbeat-not-getting-all-the-logs/302222 "2022-04-12T12:11:11Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gadula](https://avatars.discourse-cdn.com/v4/letter/g/34f0e0/32.png) [@Gadula](https://discuss.elastic.co/u/Gadula)\
**Post date:** [April 12, 2022, 12:11pm UTC](https://discuss.elastic.co/t/winlogbeat-not-getting-all-the-logs/302222/1 "2022-04-12T12:11:11Z")

</div>

Hello,  
I am newbie in Kibana, Elasticsearch and rest of tools in stack.  
So I'm not sure is the problem with Winlogbeat.

I have installed Winlogbeat on my servers and I am getting the logs correctly. They are visible in the Discover tab in Elasticsearch, but I don't see all the system generated logs there.

System events ID 1102 or 104 are very important to me as they indicate that the event log has been cleared, but I can't see these events in Elastic, among other things.

Below I put the contents of my winlogbeat.yml file.

```auto
########################## Winlogbeat Configuration ############################

fields:
  company: TEST
  environment: production
  os_type: windows

# ======================== Winlogbeat specific options =========================

winlogbeat.event_logs:
  - name: Application
    ignore_older: 30m
  - name: Security
    ignore_older: 30m
  - name: System
    ignore_older: 30m
  - name: Microsoft-windows-sysmon/operational
    ignore_older: 30m
  - name: Microsoft-windows-PowerShell/Operational
    ignore_older: 30m
    event_id: 4103, 4104
  - name: Windows PowerShell
    event_id: 400,600
    ignore_older: 30m
  - name: Microsoft-Windows-WMI-Activity/Operational
    event_id: 5857,5858,5859,5860,5861

# ====================== Elasticsearch template settings =======================

setup.template:
  name: "windows"
  pattern: "windows-*"
  settings.index.number_of_shards: 1

# ================================== Outputs ===================================

output:
  logstash:
    enabled: true
    hosts: ["XXX.XXX.XX.XX:5044"]
    index: "windows-test-%{+yyyy.MM.dd}"
    ssl:
      enabled: false

# ================================= Processors =================================

processors:
  - add_host_metadata:
      when.not.contains.tags: forwarded
  - add_cloud_metadata: ~

```

Thanks for the help in advance 🙂  
Maciej

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 10, 2022, 2:12pm UTC](https://discuss.elastic.co/t/winlogbeat-not-getting-all-the-logs/302222/2 "2022-05-10T14:12:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
