Icon

Winlogbeat

Winlogbeat ships Windows event logs to Elasticsearch or Logstash. It reads from one or more event logs using Windows APIs, filters events based on user-configured criteria, and sends event data to configured outputs. It can capture application, hardware, security, and system events and can be installed as a Windows service.
Latest: 9.4.0
Last checked: Feb 8, 2026 4:48pm
Rank: 400/15140
Monitored via:
Winget Request more monitors
Follow to track new versions in your feed.
Report

Overview

0
License: UnknownInstaller: UnknownWinget: Available

Version & Lifecycle

0
Current: 9.4.0 N-2: 9.3.3 Avg cadence: Every 21 days

Top Contributors

Top sitewide contributors:

  1. Anbarasan
  2. nico_k
  3. Bob
  4. Vigneshwaran

Community Notes

Command-line note • January 11, 2026
0

Winlogbeat – Command-line note

For unattended deployment of the Winlogbeat MSI, you can install it silently and pre-stage configuration by wrapping the vendor MSI with a script that: 1) runs the MSI with standard silent options (for example via msiexec /qn in your tool of choice), 2) drops a managed winlogbeat.yml into C:ProgramDataElasticBeatswinlogbeatwinlogbeat.yml, and 3) then starts the installed Windows service that the MSI creates but does not start by default.

Release Notes & Updates

0
Avg cadence:
Updates • 0

Help us match vulnerabilities

No vulnerability match yet. Pick the right product:

Looking for matching products…
Don’t see it? Paste a CPE

Also known as

Other names people use for this app — helps search and matching.

Winlogbeat