# Winlogbeat output to Graylog

**URL:** <https://discuss.elastic.co/t/winlogbeat-output-to-graylog/104533>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [October 19, 2017, 9:57am UTC](https://discuss.elastic.co/t/winlogbeat-output-to-graylog/104533 "2017-10-19T09:57:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![justas](https://avatars.discourse-cdn.com/v4/letter/j/9fc29f/32.png) [@justas](https://discuss.elastic.co/u/justas)\
**Post date:** [October 19, 2017, 9:57am UTC](https://discuss.elastic.co/t/winlogbeat-output-to-graylog/104533/1 "2017-10-19T09:57:42Z")

</div>

Hi All,

I have an issue. My winlogbeat sends duplicate and even in one event I found x150 same messages in graylog where in windows event logs there is only 1 message.

Winlogbeat: 5.5.2  
Graylog: 2.3.0  
Elasticsearch: 5.5.2

winlogbeat.event\_logs:  
name: ForwardedEvents  
batch\_read\_size: 512

output.logstash: # used by Graylog  
hosts: [“GraylogIP:5044”]  
ssl.enabled: true  
ssl.verification\_mode: none  
compression\_level: 3  
bulk\_max\_size: 512

There can be 100x events with the same “winlogbeat\_record\_number” however different graylog message code. All those 100x messages are identical. Anyone is facing the same issue?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 23, 2017, 12:32pm UTC](https://discuss.elastic.co/t/winlogbeat-output-to-graylog/104533/2 "2017-10-23T12:32:59Z")

</div>

No idea about Graylog. But winlogbeat resends events on failure (missing ACK). Checks logs and metrics in logs about send failures.

---

<div class="post-metadata">

**Author:** ![justas](https://avatars.discourse-cdn.com/v4/letter/j/9fc29f/32.png) [@justas](https://discuss.elastic.co/u/justas)\
**Post date:** [October 24, 2017, 4:44am UTC](https://discuss.elastic.co/t/winlogbeat-output-to-graylog/104533/3 "2017-10-24T04:44:43Z")

</div>

I have these messages from time to time (every 30 seconds):

2017-10-24T00:15:32+03:00 INFO Non-zero metrics in the last 30s:  
libbeat.logstash.call\_count.PublishEvents=30  
libbeat.logstash.publish.read\_bytes=1050  
libbeat.logstash.publish.write\_bytes=811609  
libbeat.logstash.published\_and\_acked\_events=2841  
libbeat.publisher.published\_events=2841  
published\_events.ForwardedEvents=2841  
published\_events.total=2841  
read\_errors.1734=10  
uptime={"server\_time":"2017-10-23T21:15:32.5831811Z",  
"start\_time":"2017-10-3T10:01:31.4012226Z",  
"uptime":"11h14m1.1819585s",  
"uptime\_ms":"40441181958"}

I cannot find what that means "non-zero metrics". From what I see, all correct here.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 24, 2017, 12:54pm UTC](https://discuss.elastic.co/t/winlogbeat-output-to-graylog/104533/4 "2017-10-24T12:54:12Z")

</div>

Do the duplicates only occur after restarting Winlogbeat?

If so you are seeing [https://github.com/elastic/beats/issues/3731#issuecomment-290452499](https://github.com/elastic/beats/issues/3731#issuecomment-290452499) which we plan on making some changes in a 6.x minor release to fix. But as long as you aren't restarting often the problem is minimal, and if you using a Logstash fingerprint filter you can completely work around the issue.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 24, 2017, 12:55pm UTC](https://discuss.elastic.co/t/winlogbeat-output-to-graylog/104533/5 "2017-10-24T12:55:44Z")

</div>

This is no error message. The message is printed every 30 seconds, printing out only metrics that have changed since the last 30 seconds.

The `published_and_acked_events` metric indicates events have been successfully published. No retries or fails it seems.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 21, 2017, 12:56pm UTC](https://discuss.elastic.co/t/winlogbeat-output-to-graylog/104533/6 "2017-11-21T12:56:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
