Winlogbeat is a Beat dedicated to the Windows platform. Winlogbeat is installed as a Windows service on Windows XP or later versions. It reads from many event logs using Windows APIs. It can also filter events on the basis of user-configured criteria. After this, it sends the event data to the configured output, such as Elasticsearch or Logstash. Basically, Winlogbeat captures event data such as application events, hardware events, security events, and system events.