# Account Name with "space" or "-" makes two log entries

**URL:** <https://discuss.elastic.co/t/account-name-with-space-or-makes-two-log-entries/75969>\
**Category:** Elasticsearch\
**Created:** [February 22, 2017, 1:03am UTC](https://discuss.elastic.co/t/account-name-with-space-or-makes-two-log-entries/75969 "2017-02-22T01:03:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ryan.rusiana](https://avatars.discourse-cdn.com/v4/letter/r/54ee81/32.png) [@ryan.rusiana](https://discuss.elastic.co/u/ryan.rusiana)\
**Post date:** [February 22, 2017, 1:03am UTC](https://discuss.elastic.co/t/account-name-with-space-or-makes-two-log-entries/75969/1 "2017-02-22T01:03:54Z")

</div>

HI,

I am relatively new to ELK. I have one cluster one node setup and almost everything are set to default.

All WIndows logs are sent to this instance. The primary goal for this installation is for daily log events monitoring.

Everything is working fine except for the logs with account name or groups that has a space or hypen i.e. user 1 or user-1 or group 1.

This happens when I go to Kibana to create a visualization for a sample report.

What is the best way to ensure that accounts with spaces or "-" won't get ignored and won't get treated separately?

Looking forward for your response.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 22, 2017, 1:32am UTC](https://discuss.elastic.co/t/account-name-with-space-or-makes-two-log-entries/75969/2 "2017-02-22T01:32:05Z")

</div>

> [@ryan.rusiana](#):
>
> All WIndows logs are sent to this instance.

How does this happen?

> [@ryan.rusiana](#):
>
> What is the best way to ensure that accounts with spaces or "-" won't get ignored and won't get treated separately?

Have a look at setting the mapping for that field to a keyword.

---

<div class="post-metadata">

**Author:** ![ryan.rusiana](https://avatars.discourse-cdn.com/v4/letter/r/54ee81/32.png) [@ryan.rusiana](https://discuss.elastic.co/u/ryan.rusiana)\
**Post date:** [February 22, 2017, 1:57am UTC](https://discuss.elastic.co/t/account-name-with-space-or-makes-two-log-entries/75969/3 "2017-02-22T01:57:55Z")

</div>

Windows logs are sent to one syslog server then goes to ELK.

We have a default filtering in logstash with minor changes but it was to remove unnecessary fields (see below):

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}  
filter {  
if [type] == "WindowsEventLog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program} %{DATA:syslog\_facility} %{DATA:evenitID} - %{DATA:token} %{GREEDYDATA:syslog\_message}" }  
}  
kv {  
remove\_field =\> ["LogonType", "Opcode", "AccountType", "AuthenticationPackageName", "Domain", "EventReceivedTime", "FileName", "ImpersonationLevel", "IpPort", "KeyLength", "Keywords", "LmPackageName", "LogonGuid", "LogonProcessName", "OpcodeValue", "PackageName", "PreAuthType", "PrivlegeList", "ProcessName", "ProvideGuid", "ServiceName", "ServiceSid", "SourceModuleType", "Status", "SubjectDomainName", "SubjectLogonId", "SubjectUserSid", "TargetDomainName", "TargetSid", "TargetUserSid", "Task", "ThreadID", "TicketEncryptionType", "TicketOptions", "TransmittedServices", "UserID", "Version", "Version", "eventlog\_channel", "eventlog\_record\_number", "eventlog\_severity"]  
}  
mutate {  
lowercase =\> ["EventType", "FileName", "Hostname", "Severity"]  
}  
mutate {  
rename =\> ["Hostname", "source\_host"]  
}  
mutate {  
gsub =\> ["source\_host",".example.com",""]  
}  
date {  
match =\> ["EventTime", "YYYY-MM-dd HH:mm:ss"]  
}  
mutate {  
rename =\> ["Severity", "eventlog\_severity"]  
rename =\> ["SeverityValue", "eventlog\_severity\_code"]  
rename =\> ["Channel", "eventlog\_channel"]  
rename =\> ["SourceName", "eventlog\_program"]  
rename =\> ["SourceModuleName", "nxlog\_input"]  
rename =\> ["Category", "eventlog\_category"]  
rename =\> ["EventID", "eventlog\_id"]  
rename =\> ["RecordNumber", "eventlog\_record\_number"]  
rename =\> ["ProcessID", "eventlog\_pid"]  
}

```
    if [SubjectUserName] =~ "." {
        mutate {
            replace => ["AccountName", "%{SubjectUserName}"]
        }
    }
    if [TargetUserName] =~ "." {
        mutate {
            replace => ["AccountName", "%{TargetUserName}"]
        }
    }
    if [FileName] =~ "." {
        mutate {
            replace => ["eventlog_channel", "%{FileName}"]
        }
    }

    mutate {
        lowercase => ["AccountName", "eventlog_channel"]
    }

```

}  
}

> [@warkolm](#):
>
> > [@ryan.rusiana](#):
> >
> > All WIndows logs are sent to this instance.
> 
> How does this happen?
> 
> > [@ryan.rusiana](#):
> >
> > What is the best way to ensure that accounts with spaces or "-" won't get ignored and won't get treated separately?
> 
> Have a look at setting the mapping for that field to a keyword.

> [@warkolm](#):
>
> > [@ryan.rusiana](#):
> >
> > All WIndows logs are sent to this instance.
> 
> How does this happen?
> 
> > [@ryan.rusiana](#):
> >
> > What is the best way to ensure that accounts with spaces or "-" won't get ignored and won't get treated separately?
> 
> Have a look at setting the mapping for that field to a keyword.

---

<div class="post-metadata">

**Author:** ![ryan.rusiana](https://avatars.discourse-cdn.com/v4/letter/r/54ee81/32.png) [@ryan.rusiana](https://discuss.elastic.co/u/ryan.rusiana)\
**Post date:** [February 22, 2017, 2:09am UTC](https://discuss.elastic.co/t/account-name-with-space-or-makes-two-log-entries/75969/4 "2017-02-22T02:09:02Z")

</div>

> [@warkolm](#):
>
> > [@ryan.rusiana](#):
> >
> > All WIndows logs are sent to this instance.
> 
> How does this happen?
> 
> > [@ryan.rusiana](#):
> >
> > What is the best way to ensure that accounts with spaces or "-" won't get ignored and won't get treated separately?
> 
> Have a look at setting the mapping for that field to a keyword.

[/quote]

Sorry for the response earlier. The fields that I'm referring to we're all set to "String".

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2017, 2:09am UTC](https://discuss.elastic.co/t/account-name-with-space-or-makes-two-log-entries/75969/5 "2017-03-22T02:09:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
