# Winlogbeat speeding up clocks on windows servers by 1 second every minute

**URL:** <https://discuss.elastic.co/t/winlogbeat-speeding-up-clocks-on-windows-servers-by-1-second-every-minute/135175>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [June 8, 2018, 3:16pm UTC](https://discuss.elastic.co/t/winlogbeat-speeding-up-clocks-on-windows-servers-by-1-second-every-minute/135175 "2018-06-08T15:16:53Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![Darren\_Stokes](https://avatars.discourse-cdn.com/v4/letter/d/f19dbf/32.png) [@Darren\_Stokes](https://discuss.elastic.co/u/Darren_Stokes)\
**Post date:** [June 8, 2018, 3:16pm UTC](https://discuss.elastic.co/t/winlogbeat-speeding-up-clocks-on-windows-servers-by-1-second-every-minute/135175/1 "2018-06-08T15:16:53Z")

</div>

Today I started to run winlogbeat on a number of Windows 2008 R2 servers and was succesfully transferring windows eventlogs to my elk stack without any problems.

We ran into a problem later on in the day with time across our domain and I'd found that one of our DCs was 5 minutes out. Monitoring the time of this server compared to the NTP servers I noticed that it was it was getting a second faster every minute. The only thing I'd changed today was to install the winlogbeat as a service. Once I stopped the service the time stopping getting increasingly ahead of the real time. I reset the clocks and monitored without winlogbeat running and the time stayed within a 2 second discepency. As soon as I started winlogbeat the time again became an extra second out after every minute. The reason my server was 5 minutes (300 seconds) out was because I'd started winbeatlog about approximately 5 hours previously (300 minutes at 1 second per minute = 300 seconds.).

Anyone else experienced a similar issue?

---

<div class="post-metadata">

**Author:** ![Darren\_Stokes](https://avatars.discourse-cdn.com/v4/letter/d/f19dbf/32.png) [@Darren\_Stokes](https://discuss.elastic.co/u/Darren_Stokes)\
**Post date:** [June 8, 2018, 4:00pm UTC](https://discuss.elastic.co/t/winlogbeat-speeding-up-clocks-on-windows-servers-by-1-second-every-minute/135175/2 "2018-06-08T16:00:58Z")

</div>

This only appears to happen if I run winlogbeat on a domain controller. If I monitor the time for 6 minutes it gets to 6 seconds out and just keeps going 1s faster per minute.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 8, 2018, 4:05pm UTC](https://discuss.elastic.co/t/winlogbeat-speeding-up-clocks-on-windows-servers-by-1-second-every-minute/135175/3 "2018-06-08T16:05:25Z")

</div>

I can't think of anything that Winlogbeat does that would affect time. I recall hearing about a similar issue a while back related to running Filebeat ([Filebeat Windows | Time sync](https://discuss.elastic.co/t/filebeat-windows-time-sync/121513)).

---

<div class="post-metadata">

**Author:** ![Darren\_Stokes](https://avatars.discourse-cdn.com/v4/letter/d/f19dbf/32.png) [@Darren\_Stokes](https://discuss.elastic.co/u/Darren_Stokes)\
**Post date:** [June 11, 2018, 11:15am UTC](https://discuss.elastic.co/t/winlogbeat-speeding-up-clocks-on-windows-servers-by-1-second-every-minute/135175/4 "2018-06-11T11:15:46Z")

</div>

The issue exists with 6.2.4, 6.2.3 and 6.2.0

It so far doesn't seem to exist with 6.0.0 of winlogbeat, so slowly trying to work out when it was introduced.

---

<div class="post-metadata">

**Author:** ![Darren\_Stokes](https://avatars.discourse-cdn.com/v4/letter/d/f19dbf/32.png) [@Darren\_Stokes](https://discuss.elastic.co/u/Darren_Stokes)\
**Post date:** [June 11, 2018, 11:31am UTC](https://discuss.elastic.co/t/winlogbeat-speeding-up-clocks-on-windows-servers-by-1-second-every-minute/135175/5 "2018-06-11T11:31:19Z")

</div>

It looks like the issue came in in version 6.1.0. Problem is there is a significant fix in that version that I'd want -

> Fix the registry file. It was not correctly storing event log names, and upon restart it would begin reading at the start of each event log.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 11, 2018, 12:36pm UTC](https://discuss.elastic.co/t/winlogbeat-speeding-up-clocks-on-windows-servers-by-1-second-every-minute/135175/6 "2018-06-11T12:36:21Z")

</div>

One thing that changed between 6.0 and 6.1 was the version of Go used to compile the Beat; we switched from 1.8. to 1.9. Go 1.9 is used on the 6.1, 6.2, and 6.3 branches.

- [https://github.com/elastic/beats/blob/v6.1.0/.go-version](https://github.com/elastic/beats/blob/v6.1.0/.go-version) - 1.9.2
- [https://github.com/elastic/beats/blob/v6.0.1/.go-version](https://github.com/elastic/beats/blob/v6.0.1/.go-version) - 1.8.3

We upgraded to Go 1.10 in master. I'd be curious to know if you see this issue with a binary that was compiled using Go 1.10. Do you want to try one of the snapshot builds that are created from master? They are [here](https://s3-us-west-2.amazonaws.com/beats-package-snapshots/index.html?prefix=winlogbeat/).

---

<div class="post-metadata">

**Author:** ![Darren\_Stokes](https://avatars.discourse-cdn.com/v4/letter/d/f19dbf/32.png) [@Darren\_Stokes](https://discuss.elastic.co/u/Darren_Stokes)\
**Post date:** [June 11, 2018, 1:21pm UTC](https://discuss.elastic.co/t/winlogbeat-speeding-up-clocks-on-windows-servers-by-1-second-every-minute/135175/7 "2018-06-11T13:21:38Z")

</div>

Similar issue with Go 1.10, if anything it may even be quicker

![image](https://us1.discourse-cdn.com/elastic/original/3X/d/3/d3d2d4cbed109d2501129aac926ff8c5731f743c.jpg) gained 1.6seconds in 1 minute

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 11, 2018, 1:23pm UTC](https://discuss.elastic.co/t/winlogbeat-speeding-up-clocks-on-windows-servers-by-1-second-every-minute/135175/8 "2018-06-11T13:23:19Z")

</div>

> <https://github.com/golang/go/issues/24489>

Sounds related.

---

<div class="post-metadata">

**Author:** ![Darren\_Stokes](https://avatars.discourse-cdn.com/v4/letter/d/f19dbf/32.png) [@Darren\_Stokes](https://discuss.elastic.co/u/Darren_Stokes)\
**Post date:** [June 11, 2018, 1:36pm UTC](https://discuss.elastic.co/t/winlogbeat-speeding-up-clocks-on-windows-servers-by-1-second-every-minute/135175/9 "2018-06-11T13:36:32Z")

</div>

Yes it does. So no chance of me using winlogbeat anytime soon then, as this issues seems to have gone quiet.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 11, 2018, 2:41pm UTC](https://discuss.elastic.co/t/winlogbeat-speeding-up-clocks-on-windows-servers-by-1-second-every-minute/135175/10 "2018-06-11T14:41:19Z")

</div>

You can pretty easily build v6.2.4 with Go 1.8.7. There's just one patch needed to the code because it used a go1.9 feature.

```auto
diff --git a/libbeat/logp/logger.go b/libbeat/logp/logger.go
index 04cfc91a0..d7625f92f 100644
--- a/libbeat/logp/logger.go
+++ b/libbeat/logp/logger.go
@@ -4,9 +4,6 @@ import (
        "go.uber.org/zap"
 )
 
-// LogOption configures a Logger.
-type LogOption = zap.Option
-
 // Logger logs messages to the configured output.
 type Logger struct {
        sugar *zap.SugaredLogger
@@ -15,7 +12,7 @@ type Logger struct {
 // NewLogger returns a new Logger labeled with the name of the selector. This
 // should never be used from any global contexts (instead create "per instance"
 // loggers).
-func NewLogger(selector string, options ...LogOption) *Logger {
+func NewLogger(selector string, options ...zap.Option) *Logger {
        log := loadLogger().rootLogger.
                WithOptions(zap.AddCallerSkip(1)).
                WithOptions(options...).

```

Here's the resulting binary if you want to test it: [https://s3.amazonaws.com/beats-files/testing-binaries/discuss-wlb-time-drift/winlogbeat.exe](https://s3.amazonaws.com/beats-files/testing-binaries/discuss-wlb-time-drift/winlogbeat.exe)

---

<div class="post-metadata">

**Author:** ![Darren\_Stokes](https://avatars.discourse-cdn.com/v4/letter/d/f19dbf/32.png) [@Darren\_Stokes](https://discuss.elastic.co/u/Darren_Stokes)\
**Post date:** [June 12, 2018, 11:34am UTC](https://discuss.elastic.co/t/winlogbeat-speeding-up-clocks-on-windows-servers-by-1-second-every-minute/135175/11 "2018-06-12T11:34:00Z")

</div>

Hi Andrew

That version works without any clock drift, so I think you've found the problem.

How can I go about getting a proper released version of this, or is that unlikely to happen?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 12, 2018, 11:31pm UTC](https://discuss.elastic.co/t/winlogbeat-speeding-up-clocks-on-windows-servers-by-1-second-every-minute/135175/12 "2018-06-12T23:31:01Z")

</div>

Can you please open a [new issue](https://github.com/elastic/beats/issues/new) in Github for this.

I don't think it's likely that there will be another 6.x release made with Go 1.8.x. I could build your the zip packages based on 6.2.4 using Go 1.8.7 if you like.

---

<div class="post-metadata">

**Author:** ![raouf.berrebiha](https://avatars.discourse-cdn.com/v4/letter/r/e9bcb4/32.png) [@raouf.berrebiha](https://discuss.elastic.co/u/raouf.berrebiha)\
**Post date:** [June 18, 2018, 11:44am UTC](https://discuss.elastic.co/t/winlogbeat-speeding-up-clocks-on-windows-servers-by-1-second-every-minute/135175/13 "2018-06-18T11:44:48Z")

</div>

I confirm this is an issue on 6.2.4  
I don't know if its fixed on 6.3 please reply to me if there is any fix to this issue

---

<div class="post-metadata">

**Author:** ![raouf.berrebiha](https://avatars.discourse-cdn.com/v4/letter/r/e9bcb4/32.png) [@raouf.berrebiha](https://discuss.elastic.co/u/raouf.berrebiha)\
**Post date:** [June 18, 2018, 1:48pm UTC](https://discuss.elastic.co/t/winlogbeat-speeding-up-clocks-on-windows-servers-by-1-second-every-minute/135175/14 "2018-06-18T13:48:24Z")

</div>

hi,  
thks for Sharing this binary file but i want to build my own please guide me to setup a docker developement for building the dilebeat for example  
best regard,

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [June 18, 2018, 2:03pm UTC](https://discuss.elastic.co/t/winlogbeat-speeding-up-clocks-on-windows-servers-by-1-second-every-minute/135175/15 "2018-06-18T14:03:25Z")

</div>

See the [Contribution Guide](https://www.elastic.co/guide/en/beats/devguide/current/beats-contributing.html#setting-up-dev-environment) for information on how to build beats.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 16, 2018, 2:03pm UTC](https://discuss.elastic.co/t/winlogbeat-speeding-up-clocks-on-windows-servers-by-1-second-every-minute/135175/16 "2018-07-16T14:03:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
