Analysis logs for security events

The reason I was suggesting you try Winlogbeat 5.0.0-alpha1 is because of https://github.com/elastic/beats/pull/1153. It provides more detailed information from the events.

Check out this thread regarding Kibana export: How to make a table like Excel sheet with Kibana?