# Winlogbeat only last log shows in Kibana

**URL:** <https://discuss.elastic.co/t/winlogbeat-only-last-log-shows-in-kibana/155004>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [November 1, 2018, 11:44am UTC](https://discuss.elastic.co/t/winlogbeat-only-last-log-shows-in-kibana/155004 "2018-11-01T11:44:26Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Loggeruk](https://avatars.discourse-cdn.com/v4/letter/l/48db29/32.png) [@Loggeruk](https://discuss.elastic.co/u/Loggeruk)\
**Post date:** [November 1, 2018, 11:44am UTC](https://discuss.elastic.co/t/winlogbeat-only-last-log-shows-in-kibana/155004/1 "2018-11-01T11:44:27Z")

</div>

Hi all, I am trying to setup my elastic server running logstash, kibana and elasticsearch (installed via a binami package)

Everything is running ok but when trying to gather windows logs from a machine using winlogbeat it seems a log is only coming through once every 24 hours, so when i goto create the index it only shows one log per day, which is also reflected in the discovery tab, with the @timestamp selected on the index i only ever see one log on the screen.

the winlogbeat setup is very basic

winlogbeat.event\_logs:

- name: Application  
ignore\_older: 48h
- name: Security  
ignore\_older: 48h
- name: System  
ignore\_older: 48h

the only other part setup was the logstash output which is as follows

output.logstash:  
hosts: ["my.ip.address.here:5044"]

am i missing something fundamental ? i am very new to all this - all running on Windows server by the way.

Should i be sending to logstash or elastic search in the yml file for winlogbeat?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 1, 2018, 12:01pm UTC](https://discuss.elastic.co/t/winlogbeat-only-last-log-shows-in-kibana/155004/2 "2018-11-01T12:01:33Z")

</div>

What does your Logstash config look like?

---

<div class="post-metadata">

**Author:** ![Loggeruk](https://avatars.discourse-cdn.com/v4/letter/l/48db29/32.png) [@Loggeruk](https://discuss.elastic.co/u/Loggeruk)\
**Post date:** [November 1, 2018, 12:05pm UTC](https://discuss.elastic.co/t/winlogbeat-only-last-log-shows-in-kibana/155004/3 "2018-11-01T12:05:12Z")

</div>

Hi Christian,

So i havent configured anything for Logstash, only for the winlogbeat agent on the server to monitor, maybe this is what I am missing but nothing so far in the reading has mentioned this ?

so to answer your question it would be completely default at the moment. I've found the yml file in the logstash config directory and everything is currently commented out.

---

<div class="post-metadata">

**Author:** ![Loggeruk](https://avatars.discourse-cdn.com/v4/letter/l/48db29/32.png) [@Loggeruk](https://discuss.elastic.co/u/Loggeruk)\
**Post date:** [November 1, 2018, 12:07pm UTC](https://discuss.elastic.co/t/winlogbeat-only-last-log-shows-in-kibana/155004/4 "2018-11-01T12:07:43Z")

</div>

oh ok maybe we are getting somewhere - if i change winlogbeat to send straight to elasticsearch and not logstash everything is now coming through, the indexing also shows winlogbeat and not logstash.

so do I leave it as this or should i be sending it via logstash ?

thanks

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 1, 2018, 12:21pm UTC](https://discuss.elastic.co/t/winlogbeat-only-last-log-shows-in-kibana/155004/5 "2018-11-01T12:21:58Z")

</div>

You can do either. [This blog post](https://www.elastic.co/blog/small-medium-or-large-scaling-elasticsearch-and-evolving-the-elastic-stack-to-fit) shows how the Elastic Stack scales and how the different pieces fit together.

---

<div class="post-metadata">

**Author:** ![Loggeruk](https://avatars.discourse-cdn.com/v4/letter/l/48db29/32.png) [@Loggeruk](https://discuss.elastic.co/u/Loggeruk)\
**Post date:** [November 1, 2018, 12:28pm UTC](https://discuss.elastic.co/t/winlogbeat-only-last-log-shows-in-kibana/155004/6 "2018-11-01T12:28:03Z")

</div>

thanks, ill take a look. Do you have any good resources for learning how to visualise the data? so for example i would like to see failed logon attempts and times or those attempts etc ?

thanks again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2018, 12:28pm UTC](https://discuss.elastic.co/t/winlogbeat-only-last-log-shows-in-kibana/155004/7 "2018-11-29T12:28:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
