# Copy winlog.user.name (if present) to user.name (if missing)

**URL:** <https://discuss.elastic.co/t/copy-winlog-user-name-if-present-to-user-name-if-missing/229313>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [April 22, 2020, 4:30pm UTC](https://discuss.elastic.co/t/copy-winlog-user-name-if-present-to-user-name-if-missing/229313 "2020-04-22T16:30:08Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![\_finack](https://avatars.discourse-cdn.com/v4/letter/_/e68b1a/32.png) [@\_finack](https://discuss.elastic.co/u/_finack)\
**Post date:** [April 22, 2020, 4:30pm UTC](https://discuss.elastic.co/t/copy-winlog-user-name-if-present-to-user-name-if-missing/229313/1 "2020-04-22T16:30:09Z")

</div>

For normalization purposes, I would like to copy the contents of `winlog.user.name` to `user.name` if the former is present but the latter is not.

I tried the following, but it does not work:

```
- copy_fields:
    when:
      and:
        - equals.user.name: ""
        - not.equals.winlog.user.name: ""
    fields:
      - from: winlog.user.name
        to: user.name 
    fail_on_error: false
    ignore_missing: true

```

There are some Windows events where Winlogbeat parses out the username to `winlog.user.name` but leaves `user.name` blank. For example, event ID 4104 (PowerShell script block logging).

Event ID 4104 is in the `Microsoft-Windows-PowerShell/Operational` and `PowerShellCore/Operational` log channels. I successfully set up a `copy_fields` processor in `winlogbeat.yml` for those log channels (see [this topic](https://discuss.elastic.co/t/user-name-field-for-event-id-4104/229296/3)), but it occurred to me that it's just better to check _any_ event that has `winlog.user.name` but not `user.name` and have it perform the field copy.

---

<div class="post-metadata">

**Author:** ![MarianaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marianad/32/42687_2.png) [@MarianaD](https://discuss.elastic.co/u/MarianaD)\
**Post date:** [April 23, 2020, 10:33am UTC](https://discuss.elastic.co/t/copy-winlog-user-name-if-present-to-user-name-if-missing/229313/2 "2020-04-23T10:33:30Z")

</div>

hi @_finack, is this the same issue as [User.name field for event ID 4104](https://discuss.elastic.co/t/user-name-field-for-event-id-4104/229296)? If not can you clarify?

---

<div class="post-metadata">

**Author:** ![\_finack](https://avatars.discourse-cdn.com/v4/letter/_/e68b1a/32.png) [@\_finack](https://discuss.elastic.co/u/_finack)\
**Post date:** [April 23, 2020, 10:07pm UTC](https://discuss.elastic.co/t/copy-winlog-user-name-if-present-to-user-name-if-missing/229313/3 "2020-04-23T22:07:50Z")

</div>

> [@MarianaD](#):
>
> hi @_finack, is this the same issue as [User.name field for event ID 4104](https://discuss.elastic.co/t/user-name-field-for-event-id-4104/229296)? If not can you clarify?

Not quite. The topic you referenced (mine also) was about event ID 4104 specifically. I was able to solve that one by doing the action based on the source log channel.

In this topic, I am searching for a way to copy `winlog.user.name` to `user.name` anytime the former exists (and is set to a value) and the latter does not, no matter what event ID or source log channel.

The example processor code in my OP does not work. It does not result in a populated `user.name` field for events where `winlog.user.name` is present but `user.name` isn't.

I'm assuming the issue is how I'm declaring the conditionals or the values for them, but I do not know how to fix it.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 23, 2020, 10:10pm UTC](https://discuss.elastic.co/t/copy-winlog-user-name-if-present-to-user-name-if-missing/229313/4 "2020-04-23T22:10:02Z")

</div>

Try using [has\_fields](https://www.elastic.co/guide/en/beats/winlogbeat/7.3/defining-processors.html#condition-has_fields) as a condition.

---

<div class="post-metadata">

**Author:** ![\_finack](https://avatars.discourse-cdn.com/v4/letter/_/e68b1a/32.png) [@\_finack](https://discuss.elastic.co/u/_finack)\
**Post date:** [April 23, 2020, 10:13pm UTC](https://discuss.elastic.co/t/copy-winlog-user-name-if-present-to-user-name-if-missing/229313/5 "2020-04-23T22:13:02Z")

</div>

> [@andrewkroh](#):
>
> Try using [has\_fields](https://www.elastic.co/guide/en/beats/winlogbeat/7.3/defining-processors.html#condition-has_fields) as a condition.

I will look into that. Thank you for the tip!

---

<div class="post-metadata">

**Author:** ![\_finack](https://avatars.discourse-cdn.com/v4/letter/_/e68b1a/32.png) [@\_finack](https://discuss.elastic.co/u/_finack)\
**Post date:** [April 27, 2020, 9:39pm UTC](https://discuss.elastic.co/t/copy-winlog-user-name-if-present-to-user-name-if-missing/229313/6 "2020-04-27T21:39:59Z")

</div>

> [@andrewkroh](#):
>
> Try using [has\_fields](https://www.elastic.co/guide/en/beats/winlogbeat/7.3/defining-processors.html#condition-has_fields) as a condition.

A working solution:

```
- copy_fields:
    when:
      and:
        - has_fields: ['winlog.user.name']
        - not.has_fields: ['user.name']
      fields:
        - from: winlog.user.name
          to: user.name 
      fail_on_error: false
      ignore_missing: true

```

Thanks again to @andrewkroh for the tip!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2020, 9:47pm UTC](https://discuss.elastic.co/t/copy-winlog-user-name-if-present-to-user-name-if-missing/229313/7 "2020-05-25T21:47:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
