# Field \[winlog.event\_data.ProcessCreationTime\] of type \[keyword\] does not support custom formats

**URL:** <https://discuss.elastic.co/t/field-winlog-event-data-processcreationtime-of-type-keyword-does-not-support-custom-formats/235489>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [June 3, 2020, 7:54am UTC](https://discuss.elastic.co/t/field-winlog-event-data-processcreationtime-of-type-keyword-does-not-support-custom-formats/235489 "2020-06-03T07:54:46Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 3, 2020, 7:58pm UTC](https://discuss.elastic.co/t/field-winlog-event-data-processcreationtime-of-type-keyword-does-not-support-custom-formats/235489/3 "2020-06-03T19:58:24Z")

</div>

Where do you see this error at? What action were you doing when it happens?

The fields under `winlog.event_data.*` will all have a mapping type of `keyword` if the index template from Winlogbeat [was installed](https://www.elastic.co/guide/en/beats/winlogbeat/7.7/winlogbeat-template.html#winlogbeat-template) properly.

These `winlog.event_data.*` are not all know apriori since any event can establish its own parameter names. But the data will always be mapped to a `keyword`.

If it's an issue with a Kibana index pattern not knowing about a particular `winlog.event_data` field then you can [refresh the Kibana index pattern](https://www.elastic.co/guide/en/kibana/7.7/managing-fields.html#_manage_your_index_pattern) to pick up any new fields from the index mappings.

---

_[View the full topic](https://discuss.elastic.co/t/field-winlog-event-data-processcreationtime-of-type-keyword-does-not-support-custom-formats/235489)._
