# Adding to security module the parse of event.id equals to 4663

**URL:** <https://discuss.elastic.co/t/adding-to-security-module-the-parse-of-event-id-equals-to-4663/231488>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 7, 2020, 8:44am UTC](https://discuss.elastic.co/t/adding-to-security-module-the-parse-of-event-id-equals-to-4663/231488 "2020-05-07T08:44:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aleix\_Abrie\_Prat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aleix_abrie_prat/32/47196_2.png) [@Aleix\_Abrie\_Prat](https://discuss.elastic.co/u/Aleix_Abrie_Prat)\
**Post date:** [May 7, 2020, 8:44am UTC](https://discuss.elastic.co/t/adding-to-security-module-the-parse-of-event-id-equals-to-4663/231488/1 "2020-05-07T08:44:12Z")

</div>

Hello everyone,

I want to have control of file access using Winlogbeat with parsing event with id 4663...

I am modifying the "security" module so that it can read the events with that id. I have seen that there is a variable with all codes called "msobjsMessageTable" and the access code is of the form "%% 4423" for example.

The piece of code I make is:

```auto
var code = evt.Get("winlog.event_data.AccessList");
code = code.replace("%%","");
evt.Put("winlog.access.code", code);
var accesslistdescription = msobjsMessageTable[code];
if (!accesslistdescription) {
    evt.Put("winlog.acess.code_description", "Error");
    return;
}
evt.Put("winlog.acess.code_description", accesslistdescription);

```

But the variable "accesslistdescription" always return "Error" event though the code is specified inside the variable "msobjsMessageTable"....

What am I doing wrong?

Thank you very much in advance... I am really stuck in this and I don't know why ☹

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 7, 2020, 2:33pm UTC](https://discuss.elastic.co/t/adding-to-security-module-the-parse-of-event-id-equals-to-4663/231488/2 "2020-05-07T14:33:41Z")

</div>

There's already an example of this in the Security module. You can pull that out into a reusable function. Then use that function in a processor for 4663.

> <https://github.com/elastic/beats/blob/d152d0833debbdea35ba763b5c9c1c181054dbe7/x-pack/winlogbeat/module/security/config/winlogbeat-security.js#L1958-L1973>

---

<div class="post-metadata">

**Author:** ![Aleix\_Abrie\_Prat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aleix_abrie_prat/32/47196_2.png) [@Aleix\_Abrie\_Prat](https://discuss.elastic.co/u/Aleix_Abrie_Prat)\
**Post date:** [May 8, 2020, 11:03am UTC](https://discuss.elastic.co/t/adding-to-security-module-the-parse-of-event-id-equals-to-4663/231488/3 "2020-05-08T11:03:42Z")

</div>

Hi @andrewkroh,

Thanks for the help! I have adapted my code with the example you have given me and it is working!

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2020, 11:03am UTC](https://discuss.elastic.co/t/adding-to-security-module-the-parse-of-event-id-equals-to-4663/231488/4 "2020-06-05T11:03:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
