# Enrich information with the administrator flag

**URL:** <https://discuss.elastic.co/t/enrich-information-with-the-administrator-flag/186062>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [June 17, 2019, 12:16pm UTC](https://discuss.elastic.co/t/enrich-information-with-the-administrator-flag/186062 "2019-06-17T12:16:46Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 17, 2019, 12:16pm UTC](https://discuss.elastic.co/t/enrich-information-with-the-administrator-flag/186062/1 "2019-06-17T12:16:46Z")

</div>

Hi all

I try to enrich the information that I send to Logstash.

I'd like to add a field in the winlogbeat index with a label like administrator and in this field I'd like to set YES for the user that is admin of the pc/server or NO for the user that is not admin of the pc/server.

Is it possible? At the moment I don't found solution...

Thank you  
Franco

---

<div class="post-metadata">

**Author:** ![vasek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vasek/32/136636_2.png) [@vasek](https://discuss.elastic.co/u/vasek)\
**Post date:** [June 17, 2019, 12:22pm UTC](https://discuss.elastic.co/t/enrich-information-with-the-administrator-flag/186062/2 "2019-06-17T12:22:12Z")

</div>

Yes. It is possible using Logstash Mutate plugin.

```
filter {
  mutate {
    add_tag => ["tag-name"]
  }
}

```

There is more information:  
[https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html)

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 17, 2019, 12:42pm UTC](https://discuss.elastic.co/t/enrich-information-with-the-administrator-flag/186062/3 "2019-06-17T12:42:08Z")

</div>

Hi @vasek I could add a tag ADMIN for the administrators user in the logstash filter, but how could I found the administrators user? In the winlogbeat.yml file could I set this configuration?

I need an example

Thank you  
Franco

---

<div class="post-metadata">

**Author:** ![vasek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vasek/32/136636_2.png) [@vasek](https://discuss.elastic.co/u/vasek)\
**Post date:** [June 17, 2019, 12:56pm UTC](https://discuss.elastic.co/t/enrich-information-with-the-administrator-flag/186062/4 "2019-06-17T12:56:28Z")

</div>

In ~~winlogbeat~~ filebeat you can add field for specific log file. This can be useful if you have separated log for adminstrators and users.. e.g.: adminsitrators.log, users.logs.

If you have mixed content in log.. you have to parse eveng, for example using Grok patterns in logstash. Based on result of parsing you can tag events.

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 17, 2019, 1:00pm UTC](https://discuss.elastic.co/t/enrich-information-with-the-administrator-flag/186062/5 "2019-06-17T13:00:32Z")

</div>

Ok I like the idea to have two log, one for administrators and one for users. How could I set the winlogbeat.yml file to have this 2 files?

Thank you  
Franco

---

<div class="post-metadata">

**Author:** ![vasek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vasek/32/136636_2.png) [@vasek](https://discuss.elastic.co/u/vasek)\
**Post date:** [June 17, 2019, 1:01pm UTC](https://discuss.elastic.co/t/enrich-information-with-the-administrator-flag/186062/6 "2019-06-17T13:01:33Z")

</div>

Sry. I thought about filebeat.. I am going to edit answer.

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 17, 2019, 1:18pm UTC](https://discuss.elastic.co/t/enrich-information-with-the-administrator-flag/186062/7 "2019-06-17T13:18:01Z")

</div>

Thank you @vasek. I'm waiting your reply...

Franco

---

<div class="post-metadata">

**Author:** ![vasek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vasek/32/136636_2.png) [@vasek](https://discuss.elastic.co/u/vasek)\
**Post date:** [June 17, 2019, 1:23pm UTC](https://discuss.elastic.co/t/enrich-information-with-the-administrator-flag/186062/8 "2019-06-17T13:23:05Z")

</div>

Based on eventID you can filter some messages.

There is some event ID list:  
[https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx)

Or try to parse events using Grok patterns in logstash. Based on result of parsing you can tag events.

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 17, 2019, 2:25pm UTC](https://discuss.elastic.co/t/enrich-information-with-the-administrator-flag/186062/9 "2019-06-17T14:25:57Z")

</div>

I know this list but I don't have a grok patterns to give me the result of user admin or user simple.

Do you have some idea?

Thank you  
Franco

---

<div class="post-metadata">

**Author:** ![vasek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vasek/32/136636_2.png) [@vasek](https://discuss.elastic.co/u/vasek)\
**Post date:** [June 17, 2019, 2:53pm UTC](https://discuss.elastic.co/t/enrich-information-with-the-administrator-flag/186062/10 "2019-06-17T14:53:18Z")

</div>

**1) Tag events based on selected eventID**

if ( [eventID] == 42 or [eventID] == 2019 ) {  
do something ... e.g.: add tag or field to document  
}

**2) Parsing Windows Events**  
Look at a document which is collected by Filebeat from Windows server. You can use CURL utility or Kibana to see this document. You will parse field where message is present.

You can test your Grok pattern in _Kibana - Dev Tools - Grok Debugger_. There is [nice explanation](https://www.elastic.co/guide/en/kibana/current/xpack-grokdebugger.html).

There is some [prepared Grok Reg Exp](https://github.com/logstash-plugins/logstash-patterns-core/tree/master/patterns).

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 17, 2019, 3:07pm UTC](https://discuss.elastic.co/t/enrich-information-with-the-administrator-flag/186062/11 "2019-06-17T15:07:43Z")

</div>

Thank you @vasek I know all information that you give me.

I found a script in windows that give in output all administrator users. Is it possible in winlogbeat to check if the event capture is created by one of this users (that I could store in a text file)?

Thank you  
Franco

---

<div class="post-metadata">

**Author:** ![vasek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vasek/32/136636_2.png) [@vasek](https://discuss.elastic.co/u/vasek)\
**Post date:** [June 17, 2019, 3:35pm UTC](https://discuss.elastic.co/t/enrich-information-with-the-administrator-flag/186062/12 "2019-06-17T15:35:06Z")

</div>

I am not sure that you can do it on Winlogbeat side. You can definitely filter based on e.g.:

- winlogbeat.event\_logs
- event\_logs.event\_id

More about filtering [here](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html).

Filtering messages on Logstash could be fine.. try [Logstash translate filter plugin](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html).

You can provide list of users to this plugin.

Good luck.

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [June 17, 2019, 10:10pm UTC](https://discuss.elastic.co/t/enrich-information-with-the-administrator-flag/186062/13 "2019-06-17T22:10:36Z")

</div>

Hi,

please allow me to come back to the original question and how identify, which mode the actual beat is running at the moment.  
I hope I understood you correctly.

You can always identify which context the beat is running in using environment variables combines with conditionals:  
[https://www.elastic.co/guide/en/beats/winlogbeat/current/using-environ-vars.html#using-environ-vars](https://www.elastic.co/guide/en/beats/winlogbeat/current/using-environ-vars.html#using-environ-vars)  
[https://www.elastic.co/guide/en/beats/winlogbeat/master/defining-processors.html#defining-processors](https://www.elastic.co/guide/en/beats/winlogbeat/master/defining-processors.html#defining-processors)

With the help of that I can give you following differences:

```auto
CMD without admin mode
  env variable: SESSIONNAME=Console
CMD with admin mode
  missing env variable SESSIONNAME

```

Now the difference between a program execute in admin mode or in a service context

```auto
CMD with admin mode:
  APPDATA=C:\Users\%USERNAME%\AppData\Roaming
  LOCALAPPDATA=C:\Users\%USERNAME%\AppData\Local
  TEMP=C:\Users\%USERNAME%\AppData\Local\Temp
  TMP=C:\Users\%USERNAME%\AppData\Local\Temp
  USERNAME=%USERNAME%
  USERPROFILE=C:\Users\H4PC

CMD with Service mode:
  APPDATA=C:\WINDOWS\system32\config\systemprofile\AppData\Roaming
  LOCALAPPDATA=C:\WINDOWS\system32\config\systemprofile\AppData\Local
  TEMP=C:\WINDOWS\TEMP
  TMP=C:\WINDOWS\TEMP
  USERNAME=%COMPUTERNAME%$
  USERPROFILE=C:\WINDOWS\system32\config\systemprofile

```

These contexts belong to Windows 10 but should be similar under a Windows Server version.

So hope that helps a bit additionally.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 15, 2019, 10:22pm UTC](https://discuss.elastic.co/t/enrich-information-with-the-administrator-flag/186062/14 "2019-07-15T22:22:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
