# Filter with winlogbeat

**URL:** <https://discuss.elastic.co/t/filter-with-winlogbeat/324621>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [February 3, 2023, 8:47am UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621 "2023-02-03T08:47:49Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![BeyondRAM](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/beyondram/32/117322_2.png) [@BeyondRAM](https://discuss.elastic.co/u/BeyondRAM)\
**Post date:** [February 3, 2023, 8:47am UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621/1 "2023-02-03T08:47:50Z")

</div>

Hello I got winlogbeat on my file server which brings up specifics ressources from an file audit, 4663, 4670 and 4659 events, well file activy actually.

I got an issue, I want to create a dashboard with the files the most used and also the folders the most used. But I just can't to this for folders, because of the filter operators :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/9/f97ebded82cc6e1fa2eb93526ced620294a34a2e.png)

Here is the files activity but as you can see the most used file, is actually a folder not a file. And when I'm trying to filter the data with a path, it just doesn't work at all.

I mean there is no "contains" filter, it's really embarassing, I would like to know which folders are the most used.

I'm using the "winlog.event\_data.ObjectName" field which corresponds to the path of a file :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/1/01d44451ca99c8a759afcc53a94c4048c2d8e495.png)

Is there currently a way to make a "contains" filter just to get all data that contains a certain path for example?

Here is what I got when I try to filter by a folder :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/c/acb866361591a20c2f968d3a8dd12cbc0a44c19a.png)

But it's kind of strange because the most used files in the dashboard is not a file but a folder C:\Windows\servicing\Packages

So I'm wondering why? I am not able to filter by saying "hey just give me the data thats contains this path" but the dashboard actually can wtf

I would like to get data of which folders and which files are the most used and maybe generate some report every month to get the top 250 files and top 250 folders activity.

Is it possible? If it's not, ELK is definitively useless for my use and it's sad, I am able to list which users are the most active but I can't with files and folders just because of the operators.

Does anybody has an idea?

---

<div class="post-metadata">

**Author:** ![Ayush\_Mathur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ayush_mathur/32/77134_2.png) [@Ayush\_Mathur](https://discuss.elastic.co/u/Ayush_Mathur)\
**Post date:** [February 3, 2023, 1:33pm UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621/2 "2023-02-03T13:33:29Z")

</div>

@BeyondRAM  
When querying for Windows paths, you need escape some characters in KQL. There were few related posts which I found on discussion forum itself, may be try searching for your issues first 🙂

Nevertheless, you can refer: [Wildcard filter on a Windows path - #3 by willemdh](https://discuss.elastic.co/t/wildcard-filter-on-a-windows-path/258035/3) or [Issue on query string query for URL search](https://discuss.elastic.co/t/issue-on-query-string-query-for-url-search/152863) based on if its on Discover tab or DevConsole respectively.

Also, I would suggest you to use `path_hierarchy` tokenizer for your your field which stores filesystem paths. For more information, please refer **[Path hierarchy tokenizer | Elasticsearch Guide [8.6] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-pathhierarchy-tokenizer.html)**

---

<div class="post-metadata">

**Author:** ![BeyondRAM](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/beyondram/32/117322_2.png) [@BeyondRAM](https://discuss.elastic.co/u/BeyondRAM)\
**Post date:** [February 3, 2023, 2:11pm UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621/3 "2023-02-03T14:11:42Z")

</div>

Thanks @Ayush_Mathur gonna try this, was wondering also how to load "older" events, like when I setup winlogbeat it actually only load new logs. How to force him to load the olders ones too?

I tried "start\_position: beginning" in winlogbeat.yml but it seems not to work after repushing the winlogbeat conf and reloading winlogbeat service on server.

Like this :

```auto
winlogbeat.event_logs:
  - name: Security
    event_id: 4659, 4663, 4670
    start_position: beginning

```

Well idk if it's actually possible to load older events than "the futures" ones

Thanks for the answer im gonna test it

---

<div class="post-metadata">

**Author:** ![Ayush\_Mathur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ayush_mathur/32/77134_2.png) [@Ayush\_Mathur](https://discuss.elastic.co/u/Ayush_Mathur)\
**Post date:** [February 3, 2023, 2:58pm UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621/4 "2023-02-03T14:58:35Z")

</div>

Sory, not sure really about sending old logs from winlogbeat. But there should be some option for `ignore_older` which would tell beats to ignore any entry older than this timeframe. May be try giving larger value.  
In worst case, if you can deal with duplicate logs for some time (or if it's a test server), try deleting the registry and restart winlogbeat. This should ensure events are read from very first entry, unless ofcourse your event file has not archived or deleted.

---

<div class="post-metadata">

**Author:** ![BeyondRAM](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/beyondram/32/117322_2.png) [@BeyondRAM](https://discuss.elastic.co/u/BeyondRAM)\
**Post date:** [February 6, 2023, 10:55am UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621/5 "2023-02-06T10:55:21Z")

</div>

Well I tried both solutions from the topics an error for this method [Issue on query string query for URL search](https://discuss.elastic.co/t/issue-on-query-string-query-for-url-search/152863)

And no error for this one [Wildcard filter on a Windows path - #3 by willemdh](https://discuss.elastic.co/t/wildcard-filter-on-a-windows-path/258035/3)

But no results

I guess it's impossible to do what I want...

But I mean that's sad to have to search and test a lot of things just to do a ctrl + F in ELK which is amazing

Thanks for the answer @Ayush_Mathur

---

<div class="post-metadata">

**Author:** ![Ayush\_Mathur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ayush_mathur/32/77134_2.png) [@Ayush\_Mathur](https://discuss.elastic.co/u/Ayush_Mathur)\
**Post date:** [February 7, 2023, 8:00am UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621/6 "2023-02-07T08:00:11Z")

</div>

@BeyondRAM , have you tried configuring `path_hierarchy ` tokenizer for your filesystem paths ?

> **[Path hierarchy tokenizer | Elasticsearch Guide \[8.6\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-pathhierarchy-tokenizer.html)**

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [February 8, 2023, 9:44am UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621/7 "2023-02-08T09:44:45Z")

</div>

Although the path\_hierarchy tokenizer might be a workaround, it is not really user friendly and make things overcomplex. Besides, this would require us to override the builtin mappings, which is currently nearly impossible to do effectively, as with the new index / component templates every update the mappings get overwritten again.  
It doesn't seem too much to ask from a search engine / siem to be able to wildcard search a Windows file path by default?

---

<div class="post-metadata">

**Author:** ![BeyondRAM](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/beyondram/32/117322_2.png) [@BeyondRAM](https://discuss.elastic.co/u/BeyondRAM)\
**Post date:** [February 8, 2023, 10:00am UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621/8 "2023-02-08T10:00:06Z")

</div>

Well that's what I thought, I read a couple of things about path\_hierrachy tokenizer but it's a lot to do for a simple feature. I mean that's complex and it takes lot of time when you are not very familar with all those things 😕

I hope something gonna be done in the futures updates, idk but I was very suprised when I didn't found the "contains" filter like wtf 😭 😭

---

<div class="post-metadata">

**Author:** ![BeyondRAM](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/beyondram/32/117322_2.png) [@BeyondRAM](https://discuss.elastic.co/u/BeyondRAM)\
**Post date:** [February 28, 2023, 8:24am UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621/9 "2023-02-28T08:24:20Z")

</div>

Just up to not be closed

---

<div class="post-metadata">

**Author:** ![BeyondRAM](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/beyondram/32/117322_2.png) [@BeyondRAM](https://discuss.elastic.co/u/BeyondRAM)\
**Post date:** [March 22, 2023, 3:17pm UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621/10 "2023-03-22T15:17:10Z")

</div>

Will never die

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [May 25, 2023, 9:15am UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621/13 "2023-05-25T09:15:43Z")

</div>

Just answering to keep this open as this really is problematic that we cant wildcard search in an efficient way on Windows paths..

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 25, 2023, 1:31pm UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621/14 "2023-05-25T13:31:29Z")

</div>

> [@willemdh](#):
>
> Just answering to keep this open as this really is problematic that we cant wildcard search in an efficient way on Windows paths..

I think that if this is needed, it needs to have a Github issue, without it Elastic will not even look on this issue.

Also, you can use wildcard query on the field `winlog.event_data.ObjectName`, it just need to be done on the discover search bar, not using the filter options of discover.

For example, using `winlog.event_data.ObjectName: *System32*` will show only documents where the string _System32_ is on the path.

Using `winlog.event_data.ObjectName: (*System32* AND *Speech*)` will show only documents where both _System32_ and _Speech_ are on the path.

---

<div class="post-metadata">

**Author:** ![BeyondRAM](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/beyondram/32/117322_2.png) [@BeyondRAM](https://discuss.elastic.co/u/BeyondRAM)\
**Post date:** [May 25, 2023, 2:00pm UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621/15 "2023-05-25T14:00:01Z")

</div>

Thanks for the tip man this helped me really much !

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [May 25, 2023, 5:10pm UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621/16 "2023-05-25T17:10:40Z")

</div>

Wondering if it also works with `C:\\SomePath*` or `?:\\SomePath\SomeOtherPath*` on for example `process.working_directory`

I'll try testing this asap, see also [Wildcard filter on a Windows path - #3 by willemdh](https://discuss.elastic.co/t/wildcard-filter-on-a-windows-path/258035/3)

Imho it would be nice to see this working in filters too though, as those are used in Elastic SIEM?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 22, 2023, 7:11pm UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621/17 "2023-06-22T19:11:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
