# Event id processor fails to start service

**URL:** <https://discuss.elastic.co/t/event-id-processor-fails-to-start-service/174545>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 29, 2019, 1:43pm UTC](https://discuss.elastic.co/t/event-id-processor-fails-to-start-service/174545 "2019-03-29T13:43:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eric\_Bonjour](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eric_bonjour/32/43099_2.png) [@Eric\_Bonjour](https://discuss.elastic.co/u/Eric_Bonjour)\
**Post date:** [March 29, 2019, 1:43pm UTC](https://discuss.elastic.co/t/event-id-processor-fails-to-start-service/174545/1 "2019-03-29T13:43:51Z")

</div>

I'm trying to follow the configuration that is detailed on this page - [https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html).

I am running winlogbeat version 6.2.3

I have the following in my config:

- name: Security  
event\_id: ...  
processors:
  - drop\_event.when.not.or:
    - equals.event\_id: 4625
    - equals.event\_id: 4767
    - equals.event\_id: 4741
    - equals.event\_id: 4720
    - equals.event\_id: 662
    - equals.event\_id: 4758
    - equals.event\_id: 4743
    - equals.event\_id: 4729
    - equals.event\_id: 4756
    - equals.event\_id: 4742
    - equals.event\_id: 5137
    - equals.event\_id: 631
    - equals.event\_id: 635
    - equals.event\_id: 658
    - equals.event\_id: 4727
    - equals.event\_id: 4730
    - equals.event\_id: 4726
    - equals.event\_id: 4624
    - equals.event\_id: 4732
    - equals.event\_id: 4757
    - equals.event\_id: 5136
    - equals.event\_id: 4731
    - equals.event\_id: 4754
    - equals.event\_id: 634
    - equals.event\_id: 638
    - equals.event\_id: 4734
    - equals.event\_id: 630
    - equals.event\_id: 4728
    - equals.event\_id: 4733
    - equals.event\_id: 4740
    - equals.event\_id: 5141  
ignore\_older: 72h

This is the error I receive when testing the config:

.\winlogbeat.exe test config -c .\winlogbeat.yml

Exiting: Failed to create new event log. 1 error: Invalid event log key 'processors' found. Valid keys are api, batch\_read\_size, event\_id, fields, fields\_under\_root, forwarded, ignore\_older, include\_xml, level, name, provider, tags

What am I missing that is causing this to not work correctly?

---

<div class="post-metadata">

**Author:** ![Eric\_Bonjour](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eric_bonjour/32/43099_2.png) [@Eric\_Bonjour](https://discuss.elastic.co/u/Eric_Bonjour)\
**Post date:** [March 29, 2019, 2:03pm UTC](https://discuss.elastic.co/t/event-id-processor-fails-to-start-service/174545/2 "2019-03-29T14:03:13Z")

</div>

Looks like its a bug!  
Would be great to include that in either the specific documentation for 6.2 or the release notes for 6.3.

Also documentation shouldn't include "event\_id: ..."  
Fails with "Exiting: Failed to create new event log. 1 error: invalid event ID query component ('...')"

This is not correct and should include something that actually works.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 1, 2019, 3:14pm UTC](https://discuss.elastic.co/t/event-id-processor-fails-to-start-service/174545/3 "2019-04-01T15:14:58Z")

</div>

I'm working on fixes for both issues.

> <https://github.com/elastic/beats/pull/11572>

> <https://github.com/elastic/beats/pull/11571>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 29, 2019, 3:15pm UTC](https://discuss.elastic.co/t/event-id-processor-fails-to-start-service/174545/4 "2019-04-29T15:15:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
