# Elastic Agent - Windows logs + Tagging

**URL:** <https://discuss.elastic.co/t/elastic-agent-windows-logs-tagging/247032>\
**Category:** Beats\
**Tags:** elastic-stack-security, winlogbeat, elastic-agent\
**Created:** [September 1, 2020, 2:52am UTC](https://discuss.elastic.co/t/elastic-agent-windows-logs-tagging/247032 "2020-09-01T02:52:21Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![danielsnelling](https://avatars.discourse-cdn.com/v4/letter/d/76d3ee/32.png) [@danielsnelling](https://discuss.elastic.co/u/danielsnelling)\
**Post date:** [September 1, 2020, 2:52am UTC](https://discuss.elastic.co/t/elastic-agent-windows-logs-tagging/247032/1 "2020-09-01T02:52:21Z")

</div>

Hi, does anyone know if the Elastic Agent/Ingest Manager will be getting a Winlogbeat integration module?

Currently we are deploying Auditbeat/Filebeat/Metricbeat/Winlogbeat + Sysmon in a MSI bundle, as well as a separate Endgame sensor.  
We'd love to only deploy the Elastic Agent but it only appears to have Filebeat/Metricbeat modules + Elastic Security.

On a side note, does anyone know of a way to add a field/tag to Elastic Agent logs?  
We perform document level security for multiple departments based on a field called 'environment' and it would be handy to maintain this granularity.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [September 1, 2020, 6:14am UTC](https://discuss.elastic.co/t/elastic-agent-windows-logs-tagging/247032/2 "2020-09-01T06:14:13Z")

</div>

We plan to add support for winlogbeat to Elastic Agent in the future. I wanted to give you an issue to track it on your end but seems we don't have one yet. Interested to open one on Github? [https://github.com/elastic/beats/issues](https://github.com/elastic/beats/issues)

To add fields, you should be able to use the `add_field` processor inside each input: [https://www.elastic.co/guide/en/beats/filebeat/current/add-fields.html](https://www.elastic.co/guide/en/beats/filebeat/current/add-fields.html) Let me know if this works.

---

<div class="post-metadata">

**Author:** ![danielsnelling](https://avatars.discourse-cdn.com/v4/letter/d/76d3ee/32.png) [@danielsnelling](https://discuss.elastic.co/u/danielsnelling)\
**Post date:** [September 1, 2020, 6:32am UTC](https://discuss.elastic.co/t/elastic-agent-windows-logs-tagging/247032/3 "2020-09-01T06:32:54Z")

</div>

Thanks for the reply ruflin. I'll raise an issue in GitHub tomorrow.

RE adding fields, we are already doing this in \*Beat, but I wanted to know if it's achievable in Elastic Agent Fleet managed.

---

<div class="post-metadata">

**Author:** ![danielsnelling](https://avatars.discourse-cdn.com/v4/letter/d/76d3ee/32.png) [@danielsnelling](https://discuss.elastic.co/u/danielsnelling)\
**Post date:** [September 1, 2020, 6:54am UTC](https://discuss.elastic.co/t/elastic-agent-windows-logs-tagging/247032/4 "2020-09-01T06:54:32Z")

</div>

[https://github.com/elastic/beats/issues/20886](https://github.com/elastic/beats/issues/20886) raised

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [September 1, 2020, 7:21am UTC](https://discuss.elastic.co/t/elastic-agent-windows-logs-tagging/247032/5 "2020-09-01T07:21:39Z")

</div>

Thanks for the issue.

Unfortunately at the moment, we only support the processor part in standalone and not yet through Fleet. But we plan to add support for processors / your own additional configs in the near future.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 29, 2020, 9:21am UTC](https://discuss.elastic.co/t/elastic-agent-windows-logs-tagging/247032/6 "2020-09-29T09:21:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
