# Winlogbeat too slow?

**URL:** <https://discuss.elastic.co/t/winlogbeat-too-slow/163586>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [January 9, 2019, 4:53pm UTC](https://discuss.elastic.co/t/winlogbeat-too-slow/163586 "2019-01-09T16:53:55Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![paniccontrol](https://avatars.discourse-cdn.com/v4/letter/p/b19c9b/32.png) [@paniccontrol](https://discuss.elastic.co/u/paniccontrol)\
**Post date:** [January 9, 2019, 4:53pm UTC](https://discuss.elastic.co/t/winlogbeat-too-slow/163586/1 "2019-01-09T16:53:55Z")

</div>

I am working on the configuration to recover the domain controllers logs : It seems that winlogbeat is slower than the speed of the logs generation.

So all the Security logs going to my Elastics have one hour delay (due to the parameter “ignore\_older: 1h”) and some logs are lost. The logs from other journal (system, applications, ..) arrive on time.  
I use version 6.2.4 but I also have the problem with the latest version (6.5.4).

After my filter, I’ve made some processing to filter these logs and remove the noise, but it seems to have no link with this delay : What could be the cause of my problem?

Here is my configuration :

name: Security  
batch\_read\_size: 512  
ignore\_older: 1h  
event\_id: 1100-1102,4608-4662,4667,4672-4675,4688-4693,4697-4713,4719-4742,4754-4758,4764-4769,4771-4780

output.kafka:  
enabled: true  
topic: windows\_ad  
compression: snappy  
retry.backoff: 5s  
bulk\_max\_size: 2048

Do you guys have the same issues ? How can I solve it ?

Regards,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2019, 4:54pm UTC](https://discuss.elastic.co/t/winlogbeat-too-slow/163586/2 "2019-02-06T16:54:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
