# ECS: Converting winglogbeats for Sysmon/Security to Logstash

**URL:** <https://discuss.elastic.co/t/ecs-converting-winglogbeats-for-sysmon-security-to-logstash/231902>\
**Category:** Beats\
**Tags:** ecs-elastic-common-schema, beats-module, winlogbeat\
**Created:** [May 10, 2020, 6:55pm UTC](https://discuss.elastic.co/t/ecs-converting-winglogbeats-for-sysmon-security-to-logstash/231902 "2020-05-10T18:55:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![elkn00b](https://avatars.discourse-cdn.com/v4/letter/e/b9bd4f/32.png) [@elkn00b](https://discuss.elastic.co/u/elkn00b)\
**Post date:** [May 10, 2020, 6:55pm UTC](https://discuss.elastic.co/t/ecs-converting-winglogbeats-for-sysmon-security-to-logstash/231902/1 "2020-05-10T18:55:42Z")

</div>

I'm in the process of converting the winlogbeats javascript to Logstash, and I want to be sure I'm correctly interpreting some of the javascript.

In the snip below, is the winlogbeats.js template for Sysmon separating the binary from the file path and putting just the binary into the process.name, process.executable, process.parent.executable, and process.parent.name ECS fields?

```auto
    var setProcessNameUsingExe = function (evt) {
        setProcessNameFromPath(evt, "process.executable", "process.name");
    };

    var setParentProcessNameUsingExe = function (evt) {
        setProcessNameFromPath(
            evt,
            "process.parent.executable",
            "process.parent.name"
        );
    };

    var setProcessNameFromPath = function (evt, pathField, nameField) {
        var name = evt.Get(nameField);
        if (name) {
            return;
        }
        var exe = evt.Get(pathField);
        evt.Put(nameField, **path.basename(exe)**);
    };

```

Also, because the **path.basename(exe)** contains the 'exe' string, would it only do that for exe files?

Regards,

Matt

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 11, 2020, 11:36pm UTC](https://discuss.elastic.co/t/ecs-converting-winglogbeats-for-sysmon-security-to-logstash/231902/2 "2020-05-11T23:36:03Z")

</div>

> [@elkn00b](#):
>
> is the winlogbeats.js template for Sysmon separating the binary from the file path and putting just the binary into the process.name, process.executable

It sets the `process.name` field with the [basename](https://nodejs.org/api/path.html#path_path_basename_path_ext) of the `process.executable` if and only if `process.name` is not set.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2020, 11:36pm UTC](https://discuss.elastic.co/t/ecs-converting-winglogbeats-for-sysmon-security-to-logstash/231902/3 "2020-06-08T23:36:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
