# Fields not populated

**URL:** <https://discuss.elastic.co/t/fields-not-populated/189390>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [July 8, 2019, 5:08pm UTC](https://discuss.elastic.co/t/fields-not-populated/189390 "2019-07-08T17:08:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![GregL](https://avatars.discourse-cdn.com/v4/letter/g/c57346/32.png) [@GregL](https://discuss.elastic.co/u/GregL)\
**Post date:** [July 8, 2019, 5:08pm UTC](https://discuss.elastic.co/t/fields-not-populated/189390/1 "2019-07-08T17:08:13Z")

</div>

I have installed the 7.2 versions of elasticsearch, logstash and kibana. Trying to follow this blog:

> **[Monitoring Windows Logons with Winlogbeat](https://www.elastic.co/blog/monitoring-windows-logons-with-winlogbeat)**
>
> How to use the Winlogbeat and Kibana to visualize logon events from Windows event logs.

However when filtering down to event\_id 4624 the TargetUserName and targetDomainName fields don't seem to be populated in kibana, they are populated in other events. The Blog seems to be aimed at the 5.x version. Has things changed that much that the blog is obsolete now ?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 8, 2019, 5:19pm UTC](https://discuss.elastic.co/t/fields-not-populated/189390/2 "2019-07-08T17:19:32Z")

</div>

A lot of fields were renamed for the 7.0 release to avoid future conflicts with [Elastic Common Schema](https://www.elastic.co/guide/en/ecs/current/index.html). You can see a list of changes in the [Breaking Changes](https://www.elastic.co/guide/en/beats/libbeat/7.2/breaking-changes-7.0.html#id-1.8.7.22) docs. `event_id` is `winlog.event_id`. And anything under `event_data` is under `winlog.event_data`.

Winlogbeat 7.2 adds a module that's enabled by default for the Security log that maps fields to ECS. See [https://www.elastic.co/guide/en/beats/winlogbeat/7.2/winlogbeat-module-security.html](https://www.elastic.co/guide/en/beats/winlogbeat/7.2/winlogbeat-module-security.html). Specifically it does some renames:

> <https://github.com/elastic/beats/blob/d21cf680bc8b7e923ea257a2050cacebec81763d/x-pack/winlogbeat/module/security/config/winlogbeat-security.js#L28-L35>

---

<div class="post-metadata">

**Author:** ![GregL](https://avatars.discourse-cdn.com/v4/letter/g/c57346/32.png) [@GregL](https://discuss.elastic.co/u/GregL)\
**Post date:** [July 8, 2019, 6:13pm UTC](https://discuss.elastic.co/t/fields-not-populated/189390/3 "2019-07-08T18:13:16Z")

</div>

Thanks for the info. I knew about the the remapping to winlog. but the other field remapping I was unaware of. It is almost working as expected now!. Seems the wildcard filter \*$ to filter out service accounts is not working.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 10, 2019, 1:11am UTC](https://discuss.elastic.co/t/fields-not-populated/189390/4 "2019-07-10T01:11:06Z")

</div>

There were some changes to Kibana to replace the Lucene query syntax with KQL (Kibana Query Language). Perhaps that is affecting the wildcard behavior. You can try turning off KQL in Kibana and then see if `*$` works. There's a toggle on the right hand side of the search field IIRC.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 7, 2019, 1:11am UTC](https://discuss.elastic.co/t/fields-not-populated/189390/5 "2019-08-07T01:11:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
