# Winlogbeat setup without direct access to elasticsearch/kibana

**URL:** <https://discuss.elastic.co/t/winlogbeat-setup-without-direct-access-to-elasticsearch-kibana/296949>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [February 11, 2022, 8:37am UTC](https://discuss.elastic.co/t/winlogbeat-setup-without-direct-access-to-elasticsearch-kibana/296949 "2022-02-11T08:37:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![siginigin](https://avatars.discourse-cdn.com/v4/letter/s/4bbf92/32.png) [@siginigin](https://discuss.elastic.co/u/siginigin)\
**Post date:** [February 11, 2022, 8:37am UTC](https://discuss.elastic.co/t/winlogbeat-setup-without-direct-access-to-elasticsearch-kibana/296949/1 "2022-02-11T08:37:23Z")

</div>

Hello,

I have windows servers that have access to logstash, but don't have direct access to Elasticsearch cluster nor kibana. How can I properly setup winlobeat to import dashboards/pipelines/indices/... ?  
Other beats are not the problem, because they can be installed on linux server that have direct access to Elasticsearch, but I don't have such windows there.

Thank you.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [February 11, 2022, 11:23am UTC](https://discuss.elastic.co/t/winlogbeat-setup-without-direct-access-to-elasticsearch-kibana/296949/2 "2022-02-11T11:23:45Z")

</div>

You have to load everything manually.

- Index template: [Load the Elasticsearch index template | Winlogbeat Reference [8.0] | Elastic](https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-template.html#load-template-manually-alternate)
- Dashboards: we do not have an official guide for this. One hack that comes to my mind is moving the `_meta/kibana` dir of Winlogbeat to a Linux machine, set `setup.dashboards.directory` to the path to the kibana directory and change, `setup.template.pattern` to `winlogbeat-{beat.version}` and `setup.template.enabled: false` then run `./{beatname} setup --dashboards` This should work in theory, but you might have some issues.
- Pipelines: we do not have support for this.

---

<div class="post-metadata">

**Author:** ![siginigin](https://avatars.discourse-cdn.com/v4/letter/s/4bbf92/32.png) [@siginigin](https://discuss.elastic.co/u/siginigin)\
**Post date:** [February 14, 2022, 7:42am UTC](https://discuss.elastic.co/t/winlogbeat-setup-without-direct-access-to-elasticsearch-kibana/296949/3 "2022-02-14T07:42:27Z")

</div>

Hi Noémi,

thank you for your answer.  
I understand I'll have to upload it by myself. Because of time pressure I set aside one windows server and gave it access to Elasticsearch and kibana. But still I want to have a manner how to do it without separate machine.

Regarding dashboards, I found directory c:\program files\winlogbeat\kibana and there seems to be all the dashboards, so I can download them and upload to elastic via API.

We don't use elastic pipelines, we have logstash to do the hard work, so this should'nt be issue for now.

But I see problem with manual installation of index templates, that have to be downloaded first from existing installation. Isn't there somewhere a simple guide how to create index template for winlogbeat? We already create our own index templates through API via ansible, I only need to know correct parameters for this index to be fully compatible. AFAIK is it enough to create template with ECS, or is there more to do?

ILM is also not the problem as it can be uploaded via API, but I noticed ILM for beats are not assigned to indices but to alias of indices, am I right?

Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 14, 2022, 9:43am UTC](https://discuss.elastic.co/t/winlogbeat-setup-without-direct-access-to-elasticsearch-kibana/296949/4 "2022-03-14T09:43:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
