# WinLogBeats.exe version

**URL:** <https://discuss.elastic.co/t/winlogbeats-exe-version/163254>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [January 7, 2019, 6:07pm UTC](https://discuss.elastic.co/t/winlogbeats-exe-version/163254 "2019-01-07T18:07:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![brodiemac](https://avatars.discourse-cdn.com/v4/letter/b/ac8455/32.png) [@brodiemac](https://discuss.elastic.co/u/brodiemac)\
**Post date:** [January 7, 2019, 6:07pm UTC](https://discuss.elastic.co/t/winlogbeats-exe-version/163254/1 "2019-01-07T18:07:12Z")

</div>

I'm tasked with deploying this in our organization and keeping it up to date. I'm having a difficult with the latter part of this as the winlogbeat.exe application doesn't have a version in its properties. How is anyone dealing with this minor inconvenience?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 27, 2019, 4:03pm UTC](https://discuss.elastic.co/t/winlogbeats-exe-version/163254/2 "2019-01-27T16:03:09Z")

</div>

I don't know what tooling you use, but I've used Ansible to manage some installs on Windows. As part of the playbook it inspects the binary's version by calling `winlogbeat.exe version` and reading the output.

There might be a way for the Beats release process to add some additional metadata to the Windows binaries. The project looks interesting: [https://github.com/josephspurrier/goversioninfo](https://github.com/josephspurrier/goversioninfo)

---

<div class="post-metadata">

**Author:** ![TimoHar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timohar/32/27257_2.png) [@TimoHar](https://discuss.elastic.co/u/TimoHar)\
**Post date:** [February 4, 2019, 10:02pm UTC](https://discuss.elastic.co/t/winlogbeats-exe-version/163254/3 "2019-02-04T22:02:27Z")

</div>

Calling the executable with the version command will spit out the version. Dump that to a file, and read the file with whatever you use. You can put this on a scheduled task as needed.  
`filebeat.exe version`

in our case:  
`C:\Program Files\Beats\filebeat\filebeat.exe' version> "C:\ProgramData\Beats\version.filebeat.txt`

---

<div class="post-metadata">

**Author:** ![brodiemac](https://avatars.discourse-cdn.com/v4/letter/b/ac8455/32.png) [@brodiemac](https://discuss.elastic.co/u/brodiemac)\
**Post date:** [February 5, 2019, 12:29pm UTC](https://discuss.elastic.co/t/winlogbeats-exe-version/163254/4 "2019-02-05T12:29:32Z")

</div>

I've tried version, wmic datafile get version, and filever. None of them return a version for winlogbeat.exe or they return an error because there is no file version encoded into the file itself.

 ![2019-02-05_072848](https://us1.discourse-cdn.com/elastic/original/3X/b/7/b7e6dcc64a5ad04e680f655351d9bbfca2e03921.png)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 5, 2019, 7:31pm UTC](https://discuss.elastic.co/t/winlogbeats-exe-version/163254/5 "2019-02-05T19:31:52Z")

</div>

If you are running a command, it'd be helpful to see the full command as well as any output you are receiving.

---

<div class="post-metadata">

**Author:** ![TimoHar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timohar/32/27257_2.png) [@TimoHar](https://discuss.elastic.co/u/TimoHar)\
**Post date:** [February 14, 2019, 2:30pm UTC](https://discuss.elastic.co/t/winlogbeats-exe-version/163254/6 "2019-02-14T14:30:47Z")

</div>

added empasis is mine.

Command is " **winlogbeat version**". For earlier versions, you might need to use " **winlogbeat -version**"

```
C:\Program Files\Beats\winlogbeat>winlogbeat version
winlogbeat version 6.4.1 (amd64), libbeat 6.4.1 [37b5f2d2a20f2734b2373a454b4b4cbb2627e841 built 2018-09-13 21:33:42 +0000 UTC]
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 14, 2019, 2:31pm UTC](https://discuss.elastic.co/t/winlogbeats-exe-version/163254/7 "2019-03-14T14:31:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
