# Filtering Windows Event Logs

**URL:** <https://discuss.elastic.co/t/filtering-windows-event-logs/60889>\
**Category:** Logstash\
**Created:** [September 19, 2016, 1:19pm UTC](https://discuss.elastic.co/t/filtering-windows-event-logs/60889 "2016-09-19T13:19:02Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![ANU\_SARA\_VARGHESE](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anu_sara_varghese/32/51487_2.png) [@ANU\_SARA\_VARGHESE](https://discuss.elastic.co/u/ANU_SARA_VARGHESE)\
**Post date:** [September 19, 2016, 1:19pm UTC](https://discuss.elastic.co/t/filtering-windows-event-logs/60889/1 "2016-09-19T13:19:02Z")

</div>

Hi,

I am creating a POC of ELK for analysing windows event logs. I am not getting how to apply filters on these event logs. Is there any pattern defined to be directly used in the Grok filter like for Syslogs?

If not then, how can I define my own regex for the event logs and use them in the logstash filter?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 19, 2016, 1:23pm UTC](https://discuss.elastic.co/t/filtering-windows-event-logs/60889/2 "2016-09-19T13:23:25Z")

</div>

How are you getting the events into Logstash? Winlogbeat?

---

<div class="post-metadata">

**Author:** ![ANU\_SARA\_VARGHESE](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anu_sara_varghese/32/51487_2.png) [@ANU\_SARA\_VARGHESE](https://discuss.elastic.co/u/ANU_SARA_VARGHESE)\
**Post date:** [September 19, 2016, 2:01pm UTC](https://discuss.elastic.co/t/filtering-windows-event-logs/60889/3 "2016-09-19T14:01:52Z")

</div>

Hi Magnus,

I am getting the events through tcp port into the logstash shipper and then through a MQ(redis) into the Logstash indexer.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 19, 2016, 2:03pm UTC](https://discuss.elastic.co/t/filtering-windows-event-logs/60889/4 "2016-09-19T14:03:34Z")

</div>

And what's sending the events via TCP? What I'm really getting at is what do the events currently look like? Output from a `stdout { codec => rubydebug }` output would be useful.

---

<div class="post-metadata">

**Author:** ![ANU\_SARA\_VARGHESE](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anu_sara_varghese/32/51487_2.png) [@ANU\_SARA\_VARGHESE](https://discuss.elastic.co/u/ANU_SARA_VARGHESE)\
**Post date:** [September 19, 2016, 7:35pm UTC](https://discuss.elastic.co/t/filtering-windows-event-logs/60889/5 "2016-09-19T19:35:02Z")

</div>

Hi Magnus,

I get windows event log as (If I am not wrong it is snare syslog format)

Test\_Host MSWinEventLog 0 Security 3027 Fri May 24 09:30:43 2013 593  
Security Administrator User Success Audit LE5678WSP Detailed  
Tracking A process has exited:Process ID: 656 User Name:  
Administrator Domain: LE5678WSP Logon ID: (0x0,0x6C52)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 19, 2016, 7:39pm UTC](https://discuss.elastic.co/t/filtering-windows-event-logs/60889/6 "2016-09-19T19:39:40Z")

</div>

> I get windows event log as (If I am not wrong it is snare syslog format)

You're getting Windows events over syslog? What's sending that?

Please show output from a `stdout { codec => rubydebug }` output.

---

<div class="post-metadata">

**Author:** ![ANU\_SARA\_VARGHESE](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anu_sara_varghese/32/51487_2.png) [@ANU\_SARA\_VARGHESE](https://discuss.elastic.co/u/ANU_SARA_VARGHESE)\
**Post date:** [September 19, 2016, 7:44pm UTC](https://discuss.elastic.co/t/filtering-windows-event-logs/60889/7 "2016-09-19T19:44:12Z")

</div>

It's a TIBCO product CLMS which is sending the logs

---

<div class="post-metadata">

**Author:** ![ANU\_SARA\_VARGHESE](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anu_sara_varghese/32/51487_2.png) [@ANU\_SARA\_VARGHESE](https://discuss.elastic.co/u/ANU_SARA_VARGHESE)\
**Post date:** [September 20, 2016, 5:33am UTC](https://discuss.elastic.co/t/filtering-windows-event-logs/60889/8 "2016-09-20T05:33:15Z")

</div>

Hi Magnus,

**Here is the output from stdout { codec =\> rubydebug }**

\<13\>Aug 23 17:58:25 ::ffff:123.123.123.123 Aug 3 17:58:26 123.123.123.123 MSWinEventLog 0 Security 0 Tue Aug 23 12:28:20 2012 4776 Microsoft-Windows-Security-Auditing Unknown Success Audit [domainname.com](http://domainname.com) Credential Validation The computer attempted to validate the credentials for an account. Authentication Package: MICROSOFT\_AUTHENTICATION\_PACKAGE\_V1\_0 Logon Account: username Source Workstation: workplacename Error Code: 0x0 14307364  
{  
"message" =\> "\<13\>Aug 23 17:58:25 ::ffff:123.123.123.123 Aug 3 17:58:26 123.123.123.123 MSWinEventLog\t0\tSecurity\t0\tTue Aug 23 12:28:20 2012\t4776\tMicrosoft-Windows-Security-Auditing\t\tUnknown\tSuccess Audit\[tdomainname.com](http://tdomainname.com)\tCredential Validation\t\tThe computer attempted to validate the credentials for an account. Authentication Package: MICROSOFT\_AUTHENTICATION\_PACKAGE\_V1\_0 Logon Account: username Source Workstation: workplacename Error Code: 0x0\t14307364",  
"@version" =\> "1",  
"@timestamp" =\> "2016-09-20T05:28:36.438Z",  
"host" =\> "ip-10-0-0-10",  
"tags" =\> [  
[0] "\_grokparsefailure"  
],  
"wins\_client\_ip" =\> "123.123.123.123"  
}

**The configuration used is**

input {  
stdin {}  
}  
filter {  
grok {  
match =\> {"message" =\> "%{SYSLOGBASE}"}  
}  
grok {  
match =\> {"message" =\> "%{IPV4:wins\_client\_ip}" }  
}  
}  
output {  
stdout {  
codec =\> rubydebug  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 20, 2016, 8:29am UTC](https://discuss.elastic.co/t/filtering-windows-event-logs/60889/9 "2016-09-20T08:29:02Z")

</div>

Okay. I don't have time to help you fix the grok expression, but once you extract the timestamp and the other initial fields you should be able to use a csv filter to split the remaining string on the tab characters.

---

<div class="post-metadata">

**Author:** ![ANU\_SARA\_VARGHESE](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anu_sara_varghese/32/51487_2.png) [@ANU\_SARA\_VARGHESE](https://discuss.elastic.co/u/ANU_SARA_VARGHESE)\
**Post date:** [September 21, 2016, 11:27am UTC](https://discuss.elastic.co/t/filtering-windows-event-logs/60889/10 "2016-09-21T11:27:04Z")

</div>

Hi Magnus,

I tried out csv filter but is it not going with the logs as I am not getting fields as per my need. So now I am trying to create custom patterns. I have tried out something like this

ACCNAME (?=.\*Account Name:\s\w+\s)

by creating a new pattern file.

I then called it inside the config file patterns\_dir =\> ["/opt/logstash/patterns"]

grok {  
patterns\_dir =\> ["/opt/logstash/patterns"]  
match =\> {"message" =\> "%{ACCNAME:accName}" }  
}

But I am not getting any field for this. This regex is working otherwise.

Is this the correct way of calling the custom patterns or is it the deprected one? Is there any other way for this?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 21, 2016, 11:41am UTC](https://discuss.elastic.co/t/filtering-windows-event-logs/60889/11 "2016-09-21T11:41:16Z")

</div>

> I tried out csv filter but is it not going with the logs as I am not getting fields as per my need.

If you show us what you tried and what the results were we can help you.

> ACCNAME (?=.\*Account Name:\s\w+\s)

There's no "Account Name" in the message.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:37am UTC](https://discuss.elastic.co/t/filtering-windows-event-logs/60889/12 "2017-07-06T04:37:37Z")

</div>


