# Winlogbeat - seems always start from oldest eventlog entry

**URL:** <https://discuss.elastic.co/t/winlogbeat-seems-always-start-from-oldest-eventlog-entry/42603>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [February 24, 2016, 3:14pm UTC](https://discuss.elastic.co/t/winlogbeat-seems-always-start-from-oldest-eventlog-entry/42603 "2016-02-24T15:14:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rthl](https://avatars.discourse-cdn.com/v4/letter/r/9f8e36/32.png) [@rthl](https://discuss.elastic.co/u/rthl)\
**Post date:** [February 24, 2016, 3:14pm UTC](https://discuss.elastic.co/t/winlogbeat-seems-always-start-from-oldest-eventlog-entry/42603/1 "2016-02-24T15:14:28Z")

</div>

Right no i try to evaluate elk for Windows eventlogs using winlogbeat. no matter what i put in the "ignore\_older"-Var, winlogbeat seems always to start from the oldest available eventlog-entry. So it takes very long to come up in elasticsearch.

is this the expected behaviour?  
I would expect the shipping to start from the oldest entry specified by the "ignore\_older"-var.

Thanks  
Robert

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 24, 2016, 4:28pm UTC](https://discuss.elastic.co/t/winlogbeat-seems-always-start-from-oldest-eventlog-entry/42603/2 "2016-02-24T16:28:41Z")

</div>

> [@rthl](#):
>
> winlogbeat seems always to start from the oldest available eventlog-entry

The first time it is run it starts from the oldest record. When it restarts it resumes from its previous read position. This information is persisted to the registry\_file which is a YAML file. The location of this file is specified in config file. You could open the file to inspect the record ID (the read position) for each event log.

The ignore\_older setting is implemented as a filter on the output. It has to read the event before it can decide to drop the record.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 12, 2016, 1:58pm UTC](https://discuss.elastic.co/t/winlogbeat-seems-always-start-from-oldest-eventlog-entry/42603/3 "2016-04-12T13:58:25Z")

</div>

In version 5 of Winlogbeat the implementation of `ignore_older` has changed on Windows Vista and newer. Winlogbeat now uses a time-based query when requesting events from Windows so that only events newer than the `ignore_older` period are returned to Winlogbeat. This will make Winlogbeat output events more quickly the first time you run it when using `ignore_older`.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 15, 2016, 2:01pm UTC](https://discuss.elastic.co/t/winlogbeat-seems-always-start-from-oldest-eventlog-entry/42603/4 "2016-04-15T14:01:29Z")

</div>

This topic was automatically closed after 3 days. New replies are no longer allowed.
