# Winlogbeat performance

**URL:** <https://discuss.elastic.co/t/winlogbeat-performance/323571>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [January 20, 2023, 8:11am UTC](https://discuss.elastic.co/t/winlogbeat-performance/323571 "2023-01-20T08:11:05Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![MarcoVu](https://avatars.discourse-cdn.com/v4/letter/m/59ef9b/32.png) [@MarcoVu](https://discuss.elastic.co/u/MarcoVu)\
**Post date:** [January 20, 2023, 8:11am UTC](https://discuss.elastic.co/t/winlogbeat-performance/323571/1 "2023-01-20T08:11:05Z")

</div>

So i have some Windows Event collector servers which collects events from workstations, and decided to send all collected events to Elasticsearch with Winlogbeat (8.4.1 version), but regardless of any of settings that i found related to performance (batch\_read\_size, bulk\_max\_size, workers etc) i am always stuck at about 50 events per second, it almost never changes whatever i do with winlogbeat settings ... It looks like Winlogbeat is very slow at reading events from eventlog. Any advice?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 17, 2023, 10:11am UTC](https://discuss.elastic.co/t/winlogbeat-performance/323571/2 "2023-02-17T10:11:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
