WARNING: Version 5.6 of Winlogbeat has passed its EOL date.

This documentation is no longer being maintained and may be removed. If you are running this version, we strongly advise you to upgrade. For the latest information, see the current release documentation.

Overview »
Elastic Docs

Winlogbeat Reference


  • Winlogbeat Reference: other versions:
  • Overview
  • Getting Started With Winlogbeat
    • Step 1: Installing Winlogbeat
    • Step 2: Configuring Winlogbeat
    • Step 3: Configuring Winlogbeat to Use Logstash
    • Step 4: Loading the Index Template in Elasticsearch
    • Step 5: Starting Winlogbeat
    • Step 6: Loading Sample Kibana Dashboards
    • Command Line Options
    • Directory Layout
  • Upgrading Winlogbeat
  • Configuring Winlogbeat
    • Configuration Options (Reference)
      • Winlogbeat
      • General
      • Elasticsearch Output
      • Logstash Output
      • Kafka Output
      • Redis Output
      • File Output
      • Console Output
      • SSL
      • Output Codec
      • Paths
      • Dashboards
      • Logging
    • Processors
      • add_cloud_metadata
      • decode_json_fields
      • drop_event
      • drop_fields
      • include_fields
    • Filtering and Enhancing the Exported Data
    • Configuring Winlogbeat to Use Ingest Node
    • Using Environment Variables in the Configuration
    • YAML Tips and Gotchas
  • Exported Fields
    • Beat Fields
    • Cloud Provider Metadata Fields
    • Common Winlogbeat Fields
    • Event Log Record Fields
  • Securing Winlogbeat
    • Securing Communication With Elasticsearch
    • Securing Communication With Logstash by Using SSL
  • Troubleshooting
    • Getting Help
    • Debugging
    • Frequently Asked Questions
Overview »

Most Popular

Video

Get Started with Elasticsearch

Video

Intro to Kibana

Video

ELK for Logs & Metrics