# Analysis logs for security events

**URL:** <https://discuss.elastic.co/t/analysis-logs-for-security-events/48893>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 1, 2016, 4:59pm UTC](https://discuss.elastic.co/t/analysis-logs-for-security-events/48893 "2016-05-01T16:59:02Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![Kennedy\_Kan1](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)\
**Post date:** [May 2, 2016, 3:08pm UTC](https://discuss.elastic.co/t/analysis-logs-for-security-events/48893/3 "2016-05-02T15:08:14Z")

</div>

I have seen the query example from [Reporting Windows Security Events in Kibana](https://discuss.elastic.co/t/reporting-windows-security-events-in-kibana/44748) but still quite couldn't understand how to do it.

Instead, I have installed the beats-input plugin and filter-translate plugin as to create the beats-input.conf. Here is the .conf file.

> input {  
> beats {  
> port =\> 5044  
> }  
> }  
> filter {  
> translate {  
> field =\> "status\_code"  
> destination =\> "description"  
> dictionary\_path =\> ["C:/logstash/dictionary.yaml"]  
> }  
> }  
> output {  
> elasticsearch {  
> hosts =\> "localhost:9200"  
> manage\_template =\> false  
> index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
> document\_type =\> "%{[@metadata][type]}"  
> }  
> }

where the dictionary.yaml stores data referenced from [Windows Security Log Encyclopedia](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/Default.aspx)

For example:

> "512": Windows NT is starting up  
> "513": Windows is shutting down  
> "514": An authentication package has been loaded by the Local Security Authority  
> "515": A trusted logon process has registered with the Local Security Authority  
> "516": Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits  
> "517": The audit log was cleared

But it seems that there is no any results (logs) received as seen from the kibana. However, when between I stop and start winlogbeat again, new log files are created as seen from ProgramData File.

I have found that when I start winlogbeat with elasticsearch as output then the logs can be displayed in kibana while it cant when start with logstash as output.

---

_[View the full topic](https://discuss.elastic.co/t/analysis-logs-for-security-events/48893)._
