# Field 'Logon ID' not available

**URL:** <https://discuss.elastic.co/t/field-logon-id-not-available/173348>\
**Category:** Kibana\
**Created:** [March 21, 2019, 4:09pm UTC](https://discuss.elastic.co/t/field-logon-id-not-available/173348 "2019-03-21T16:09:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![smmaalam](https://avatars.discourse-cdn.com/v4/letter/s/6de8d8/32.png) [@smmaalam](https://discuss.elastic.co/u/smmaalam)\
**Post date:** [March 21, 2019, 4:09pm UTC](https://discuss.elastic.co/t/field-logon-id-not-available/173348/1 "2019-03-21T16:09:56Z")

</div>

Hi everyone,

I'm using Kibana 5.0 for visualizing Windows Event Logs like the following:

 ![Kibana](https://us1.discourse-cdn.com/elastic/original/3X/5/d/5d30f26cafd20e0430c753a89f0558b17eea4e0b.png)  
My Problem is, that there are two Logon ID's and Kibana is using the first one to be a field, but I need the second one for filtering. What can I do? Do I have to change the mapping in ElasticSearch? I'm new to the ELK-Stack. =)

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 22, 2019, 12:03pm UTC](https://discuss.elastic.co/t/field-logon-id-not-available/173348/2 "2019-03-22T12:03:32Z")

</div>

Hello,  
What are you using to ingest the Windows Event Logs in kibana? There might be a way to filter that ID out in order to have it as a separate field for you.

---

<div class="post-metadata">

**Author:** ![smmaalam](https://avatars.discourse-cdn.com/v4/letter/s/6de8d8/32.png) [@smmaalam](https://discuss.elastic.co/u/smmaalam)\
**Post date:** [March 22, 2019, 4:36pm UTC](https://discuss.elastic.co/t/field-logon-id-not-available/173348/3 "2019-03-22T16:36:45Z")

</div>

Hello Marius,

we are using Wazuh Agents to collect the data und had to change the decoders. Thank you for your help but the Problem is solved. =)

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 25, 2019, 12:05pm UTC](https://discuss.elastic.co/t/field-logon-id-not-available/173348/4 "2019-03-25T12:05:16Z")

</div>

It would be cool if you could share how you fixed the problem, for anybody else that might hit this snag.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 22, 2019, 12:16pm UTC](https://discuss.elastic.co/t/field-logon-id-not-available/173348/5 "2019-04-22T12:16:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
