Hi @joshablett, first off these modification should not be necessary. The provided index template should be setting the type of these fields to be not_analyzed strings. What version of Winlogbeat are you using?
I did not see you mention in your steps that you actually installed the index template to Elasticsearch. Before you index any data in Elasticsearch you need to HTTP PUT the index template into ES unless you have configured Winlogbeat to automatically install the template (if you are changing an already installed template then you need also overwrite: true). https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-template.html
You can check that the template is installed with curl http://localhost:9200/_template/winlogbeat?pretty.
Here is the template setting from my winlogbeat.yml file:
# A template is used to set the mapping in Elasticsearch
# By default template loading is disabled and no template is loaded.
# These settings can be adjusted to load your own template or overwrite existing ones
# Template name. By default the template name is winlogbeat.
# Path to template file
# Overwrite existing template
Hi Andrew - sorry for the delay. I've actually updated to the 5.0.0 winlogbeat alpha to get the parsed fields. With a clean install, I'm still not seeing the .raw option. Should I follow the same steps to troubleshoot this version?