# WinlogBeats not making it through to Elastic

**URL:** <https://discuss.elastic.co/t/winlogbeats-not-making-it-through-to-elastic/167525>\
**Category:** Logstash\
**Created:** [February 7, 2019, 8:22pm UTC](https://discuss.elastic.co/t/winlogbeats-not-making-it-through-to-elastic/167525 "2019-02-07T20:22:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![koocaroo](https://avatars.discourse-cdn.com/v4/letter/k/8edcca/32.png) [@koocaroo](https://discuss.elastic.co/u/koocaroo)\
**Post date:** [February 7, 2019, 8:22pm UTC](https://discuss.elastic.co/t/winlogbeats-not-making-it-through-to-elastic/167525/1 "2019-02-07T20:22:22Z")

</div>

The current setup is My Workstation \> Logstash \> ElasticSearch

I can see via tcpdump that i am getting traffic from my host to logstash although its not what i would expect to see, i also dont see any traffic leaving the logstash box to Elastic search. Below are the Beats, pipeline.yml, and winlogbeats.conf in the /etc/logstah/conf.d configurations. Also yes, i manually loaded the template and got the successful return. Yes i can curl 9200 of the elastic server.

Am i missing something?

Logstash config:

input {  
beats {  
port =\> 5044  
}  
}

output {  
elasticsearch {  
hosts =\> "192.168.20.35:9200"  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
}  
}

Pipeline config:

- pipeline.id: WindowsHostLogging  
path.config: "/etc/logstash/conf.d/windows-host-logs.conf"

Beats config:

winlogbeat.event\_logs:

- name: Security  
event\_id: -5156, -5152, -5158

setup.template.settings:  
index.number\_of\_shards: 3

output.logstash:  
hosts: "192.168.1.243:5044"

---

<div class="post-metadata">

**Author:** ![koocaroo](https://avatars.discourse-cdn.com/v4/letter/k/8edcca/32.png) [@koocaroo](https://discuss.elastic.co/u/koocaroo)\
**Post date:** [February 7, 2019, 8:28pm UTC](https://discuss.elastic.co/t/winlogbeats-not-making-it-through-to-elastic/167525/2 "2019-02-07T20:28:49Z")

</div>

I only see SYN packets from my host to log stash. nothing from logstash to elastic:

15:26:45.840311 IP 192.168.1.182.54357 \> 192.168.1.243.5044: Flags [S], seq 2101056925, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0  
15:26:48.841634 IP 192.168.1.182.54357 \> 192.168.1.243.5044: Flags [S], seq 2101056925, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0  
15:26:54.850542 IP 192.168.1.182.54357 \> 192.168.1.243.5044: Flags [S], seq 2101056925, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 7, 2019, 9:10pm UTC](https://discuss.elastic.co/t/winlogbeats-not-making-it-through-to-elastic/167525/3 "2019-02-07T21:10:29Z")

</div>

I assume that tcpdump is running on the machine running the filebeat. Do you see the same packets on the machine running logstash?

Could be a firewall is blocking the traffic.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 7, 2019, 9:10pm UTC](https://discuss.elastic.co/t/winlogbeats-not-making-it-through-to-elastic/167525/4 "2019-03-07T21:10:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
