# Double escaping in expected due to windows events

**URL:** <https://discuss.elastic.co/t/double-escaping-in-expected-due-to-windows-events/356734>\
**Category:** Elastic Security\
**Created:** [April 4, 2024, 5:03am UTC](https://discuss.elastic.co/t/double-escaping-in-expected-due-to-windows-events/356734 "2024-04-04T05:03:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![nahuel978](https://avatars.discourse-cdn.com/v4/letter/n/5fc32e/32.png) [@nahuel978](https://discuss.elastic.co/u/nahuel978)\
**Post date:** [April 4, 2024, 5:03am UTC](https://discuss.elastic.co/t/double-escaping-in-expected-due-to-windows-events/356734/1 "2024-04-04T05:03:38Z")

</div>

Hello everyone! I was studying the system/security decoder and I noticed that in the expected ones, the paths of records or files are with double backslashes. I understand that it is to escape the bar that already brings the windows event. But here comes my doubt. What event do they take? the overview event or the xml event? because the xml event already comes with the escape, so the output in elastic should have 4 backslashes instead of 2. unless it is not the xml event that is being taken. I have this doubt since I saw that the events are in evtx format. example: [integrations/packages/system/data\_stream/security/\_dev/test/pipeline/test-4670-windowssrv2016.json at 3d69d50f4c2aede1e9b7472485a6a06d8619d702 · elastic/integrations · GitHub](https://github.com/elastic/integrations/blob/3d69d50f4c2aede1e9b7472485a6a06d8619d702/packages/system/data_stream/security/_dev/test/pipeline/test-4670-windowssrv2016.json#L41)

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [April 4, 2024, 10:34am UTC](https://discuss.elastic.co/t/double-escaping-in-expected-due-to-windows-events/356734/2 "2024-04-04T10:34:22Z")

</div>

Winlogbeat is unmarshalling the xml

Are you sure you're reading/viewing the xml data correctly?

---

<div class="post-metadata">

**Author:** ![nahuel978](https://avatars.discourse-cdn.com/v4/letter/n/5fc32e/32.png) [@nahuel978](https://discuss.elastic.co/u/nahuel978)\
**Post date:** [April 4, 2024, 12:26pm UTC](https://discuss.elastic.co/t/double-escaping-in-expected-due-to-windows-events/356734/3 "2024-04-04T12:26:57Z")

</div>

Hi lesio! The confusion arises when you see how the events are in your xml view:

 ![Captura desde 2024-04-04 09-12-21](https://us1.discourse-cdn.com/elastic/original/3X/7/1/712a3fcfbb8d3fb45c210e7944fe3219f273c3df.png)

I noticed that in its general view the paths come out with a backslash and in the xml view they come out with two backslashes (due to the escape character). When transforming this into json, shouldn't it be escaped again to preserve the two backslashes, leaving \\ instead of \?

---

<div class="post-metadata">

**Author:** ![Yamin\_Tian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yamin_tian/32/80373_2.png) [@Yamin\_Tian](https://discuss.elastic.co/u/Yamin_Tian)\
**Post date:** [April 4, 2024, 5:14pm UTC](https://discuss.elastic.co/t/double-escaping-in-expected-due-to-windows-events/356734/4 "2024-04-04T17:14:34Z")

</div>

Anyone can correct me. I did some digging on the source code, it seems in transforming the event into json, winlogbeat isn't trying to preserve the format of `raw` XML input, rather, it preserves the information.  
This should be the `UnmarshalXML` function Leszek mentioned:

> <https://github.com/elastic/beats/blob/master/winlogbeat/eventlog/wineventlog.go#L346>

which eventually calls into this decode function to decode the raw XML:

> <https://github.com/elastic/beats/blob/main/libbeat/common/encoding/xml/decode.go#L55>

It seems when dealing with Windows paths, the goal is to be able to locate the original paths from the json. I believe the path strings we see in json is expected.

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [April 5, 2024, 1:56pm UTC](https://discuss.elastic.co/t/double-escaping-in-expected-due-to-windows-events/356734/5 "2024-04-05T13:56:03Z")

</div>

I see, honestly I didn't even know the xml view exist in Kibana.

It is somewhat confusing that in some places the paths must be escaped and in others not. I stepped on this problem a few times, but I forgot where it was.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2024, 1:56pm UTC](https://discuss.elastic.co/t/double-escaping-in-expected-due-to-windows-events/356734/6 "2024-05-03T13:56:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
