# Add 'process.args\_count' to Windows Security ingest pipeline

**URL:** <https://discuss.elastic.co/t/add-process-args-count-to-windows-security-ingest-pipeline/382903>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [October 22, 2025, 8:15pm UTC](https://discuss.elastic.co/t/add-process-args-count-to-windows-security-ingest-pipeline/382903 "2025-10-22T20:15:07Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![elkn00b](https://avatars.discourse-cdn.com/v4/letter/e/b9bd4f/32.png) [@elkn00b](https://discuss.elastic.co/u/elkn00b)\
**Post date:** [October 22, 2025, 8:15pm UTC](https://discuss.elastic.co/t/add-process-args-count-to-windows-security-ingest-pipeline/382903/1 "2025-10-22T20:15:07Z")

</div>

Hello All,

We’ve had this fix in place for a while, but I noticed when checking open issues that an enhancement request existed to add `process.args_count` to the Elastic Agent integrations.

I’ve reviewed the code for both the ingest pipeline for Elastic Agent and for Winlogbeat and the fix would be the same. That being said, we have it working live for Winlogbeat, so I figured I’d open a PR for what I know is working and then suggest another similar PR for Elastic Agent.

It’s [PR 47266](https://github.com/elastic/beats/pull/47266).

I’ll recap the TL;DR I put into the PR here as well for ease of reference:

> I reviewed the ingest pipeline used for Sysmon and the _Script_ processor that implements the "Windows-like SplitCommandLine" logic. [Lines 542 to 546](https://github.com/elastic/integrations/blob/f75ddbefe1c3a95648ba13b8f16441404874574b/packages/windows/data_stream/forwarded/elasticsearch/ingest_pipeline/sysmon_operational.yml#L542) implement the logic for Sysmon, so I adapted those lines into the correct order of operations defined in the Security ingest pipeline, [inserted at line 3718](https://github.com/elastic/beats/blob/93e2ae9ee695ce7aad443a9b32eef0dddb984457/x-pack/winlogbeat/module/security/ingest/security_standard.yml#L3718).

I couldn’t figure out how to apply labels, so I just want to make sure I submitted the PR correctly since it’s my first one.

I’d appreciate if an Elastic Team Member could review and let me know.

Thank you!

---

<div class="post-metadata">

**Author:** ![elkn00b](https://avatars.discourse-cdn.com/v4/letter/e/b9bd4f/32.png) [@elkn00b](https://discuss.elastic.co/u/elkn00b)\
**Post date:** [October 28, 2025, 12:26am UTC](https://discuss.elastic.co/t/add-process-args-count-to-windows-security-ingest-pipeline/382903/2 "2025-10-28T00:26:45Z")

</div>

I finally figured out how to add the changelog fragment. Hoping that was the last pending item to get traction on a review!
