# Duplicate Windows User Names when filtering

**URL:** <https://discuss.elastic.co/t/duplicate-windows-user-names-when-filtering/79709>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 23, 2017, 8:45am UTC](https://discuss.elastic.co/t/duplicate-windows-user-names-when-filtering/79709 "2017-03-23T08:45:08Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![frederict](https://avatars.discourse-cdn.com/v4/letter/f/c5a1d2/32.png) [@frederict](https://discuss.elastic.co/u/frederict)\
**Post date:** [March 23, 2017, 8:45am UTC](https://discuss.elastic.co/t/duplicate-windows-user-names-when-filtering/79709/1 "2017-03-23T08:45:08Z")

</div>

Hi,

I'm new here and I am trying to set up a Windows centralised log for the first time with ELK. So far, everything is working out for me.

I want to make a visualisation in Kibana to view succesful account logons on the Windows domain. It's working fine, but i'm seeing duplicate account names when I split rows on event\_data.TargetUserName. These usernames are the same, but the spelling is different.

Example: I want to see in the table how many times a user has succesfully loged on, how many different computers and how many unique IP Addresses the user has 'used'. This is one of the data tables given as a template with Winlogbeat.

But I get multiple rows for the same usernames, with different spelling. Eg I see a row with user "Bob", but also a row for user "bob", which is the same account. The person just spelled his username with lower case characters on the logon screen.

Any idea on how to filter these duplicates out? Or do I need to change this (I don't know how) on the Windows side? Maybe there is a way to always force a user to log in with lower/upper case characters only?

Thanks in advance,  
Frederic

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 23, 2017, 10:11am UTC](https://discuss.elastic.co/t/duplicate-windows-user-names-when-filtering/79709/2 "2017-03-23T10:11:29Z")

</div>

You can lowercase your data using ingest node feature with a lowercase processor.

Or use the new Normalizer feature in your mapping on your `.keyword` fields.

---

<div class="post-metadata">

**Author:** ![maddin2016](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maddin2016/32/16599_2.png) [@maddin2016](https://discuss.elastic.co/u/maddin2016)\
**Post date:** [March 23, 2017, 10:31am UTC](https://discuss.elastic.co/t/duplicate-windows-user-names-when-filtering/79709/3 "2017-03-23T10:31:55Z")

</div>

Active Directory saves all attributes case rare. For example `Bob`. You can search for `bob` or `BOB` and always get `Bob` as the result. So on windows side there is no chance to change this behavior. What you can do is to send these events to logstash and then `lowercase` or `uppercase` this field. See [here](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-lowercase)

---

<div class="post-metadata">

**Author:** ![maddin2016](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maddin2016/32/16599_2.png) [@maddin2016](https://discuss.elastic.co/u/maddin2016)\
**Post date:** [March 23, 2017, 10:33am UTC](https://discuss.elastic.co/t/duplicate-windows-user-names-when-filtering/79709/4 "2017-03-23T10:33:24Z")

</div>

@dadoonet, doesn't recognize your answer 🙈

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 23, 2017, 12:41pm UTC](https://discuss.elastic.co/t/duplicate-windows-user-names-when-filtering/79709/5 "2017-03-23T12:41:22Z")

</div>

Seems like even though Windows records both `Bob` and `bob`, they are both the same user. So this would be a good candidate for the normalizer. We could update index template for this field.

> <https://github.com/elastic/beats/issues/3582>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2017, 12:41pm UTC](https://discuss.elastic.co/t/duplicate-windows-user-names-when-filtering/79709/6 "2017-04-20T12:41:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
