# Add fields to winlogbeat events

**URL:** <https://discuss.elastic.co/t/add-fields-to-winlogbeat-events/182639>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 24, 2019, 11:43am UTC](https://discuss.elastic.co/t/add-fields-to-winlogbeat-events/182639 "2019-05-24T11:43:04Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ajhstn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ajhstn/32/24629_2.png) [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Post date:** [May 24, 2019, 11:43am UTC](https://discuss.elastic.co/t/add-fields-to-winlogbeat-events/182639/1 "2019-05-24T11:43:04Z")

</div>

Hello using winlogbeat and elasticsearch as the output (not logstash) can i create a key-value pari lookup database?

use case:  
For event\_id: 4625 i would like to include fields or do a lookup for the Status and Substatus fields, eg.

Is this best achieved with a processor?, such as below or something else?

```
processors:
  -add_fields:
    when:
      event_data.Status: 0xc000006d
        fields:
          "event_data.Status.Description": "This is either due to a bad username or authentication information"
```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 24, 2019, 9:38pm UTC](https://discuss.elastic.co/t/add-fields-to-winlogbeat-events/182639/2 "2019-05-24T21:38:39Z")

</div>

You could accomplish this with either a series of `add_fields` processors on the Winlogbeat side or using an [Ingest Node pipeline](https://www.elastic.co/guide/en/beats/winlogbeat/current/elasticsearch-output.html#pipeline-option-es) in Elasticsearch. With Ingest Node you would using the [script processor](https://www.elastic.co/guide/en/elasticsearch/reference/master/script-processor.html) to translate status codes.

---

<div class="post-metadata">

**Author:** ![ajhstn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ajhstn/32/24629_2.png) [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Post date:** [May 24, 2019, 9:47pm UTC](https://discuss.elastic.co/t/add-fields-to-winlogbeat-events/182639/3 "2019-05-24T21:47:27Z")

</div>

Thank you @andrewkroh could you please give me an example?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 24, 2019, 9:50pm UTC](https://discuss.elastic.co/t/add-fields-to-winlogbeat-events/182639/4 "2019-05-24T21:50:35Z")

</div>

For `add_fields` it would be a series of processors:

```auto
processors:
  - add_fields:
      when:
        event_data.Status: "0xc000006d"
      fields:
        event_data.Status_Description: This is either due to a bad username or authentication information.
      target: ""
  - add_fields:
      when:
        event_data.Status: "0x123"
      fields:
        event_data.Status_Description: One two three
      target: ""

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 24, 2019, 9:53pm UTC](https://discuss.elastic.co/t/add-fields-to-winlogbeat-events/182639/5 "2019-05-24T21:53:28Z")

</div>

And BTW in Winlogbeat 7.2.0 there will be a [new script processor](https://www.elastic.co/guide/en/beats/winlogbeat/7.2/processor-script.html) that could be used too, but it's not released yet. With that new script processor you could write a `switch` statement.

---

<div class="post-metadata">

**Author:** ![ajhstn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ajhstn/32/24629_2.png) [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Post date:** [May 25, 2019, 2:51am UTC](https://discuss.elastic.co/t/add-fields-to-winlogbeat-events/182639/6 "2019-05-25T02:51:33Z")

</div>

Oh right, so i was almost there i just had my syntax wrong.. Good to know.

Regarding efficiency, would the processor or the ingest node method be better?

---

<div class="post-metadata">

**Author:** ![ajhstn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ajhstn/32/24629_2.png) [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Post date:** [May 25, 2019, 3:24am UTC](https://discuss.elastic.co/t/add-fields-to-winlogbeat-events/182639/7 "2019-05-25T03:24:03Z")

</div>

Dang! `add_fields` is not available in version 6.4!!

---

<div class="post-metadata">

**Author:** ![martinr\_ubi](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@martinr\_ubi](https://discuss.elastic.co/u/martinr_ubi)\
**Post date:** [May 27, 2019, 10:30am UTC](https://discuss.elastic.co/t/add-fields-to-winlogbeat-events/182639/8 "2019-05-27T10:30:56Z")

</div>

mmm, you could try to use the fields setting, which adds fields and can be use per "event\_logs". (scoped to one "collector")  
[https://www.elastic.co/guide/en/beats/winlogbeat/6.4/configuration-winlogbeat-options.html#winlogbeat-configuration-fields](https://www.elastic.co/guide/en/beats/winlogbeat/6.4/configuration-winlogbeat-options.html#winlogbeat-configuration-fields)

You would filter on the event id, 4625, use the "fields" setting to add the human readable string you want for a particular status and use the drop-event processor to drop all the events which do not have the status corresponding to the human readable string you just put in the fields setting.  
Then rinse and repeat, add the same event\_logs entry n times always just changing the string in "fields" and status code you don't drop.  
So collect the same eventid through multiple collectors and always dropping the status that don't match (or go with...) the string. Once they're all there you should get what you want in the output.

Only thing I don't know is if winlogbeat allows you to filter on the same eventid multiple times. Never tried that but at face value I don't see why it would not be valid.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 24, 2019, 12:31pm UTC](https://discuss.elastic.co/t/add-fields-to-winlogbeat-events/182639/9 "2019-06-24T12:31:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
