# Finding User Name & more

**URL:** https://discuss.elastic.co/t/finding-user-name-more/139942
**Category:** Beats
**Tags:** winlogbeat
**Created:** [July 13, 2018, 12:25pm UTC](https://discuss.elastic.co/t/finding-user-name-more/139942 "2018-07-13T12:25:14Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![Marcos\_Felix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcos_felix/32/32486_2.png) [@Marcos\_Felix](https://discuss.elastic.co/u/Marcos_Felix)
#### Post date: [July 13, 2018, 12:25pm UTC](https://discuss.elastic.co/t/finding-user-name-more/139942/1 "2018-07-13T12:25:14Z")

</div>

Hello,  
1st Question:  
I am forwarding logs from my collector environment to Kibana using winlogbeat  
I am interested in finding who done what.  
When I check a log I look for the user that done that, and I can't find - maybe I have bad filtering?  
I found this: Logon ID: 0xA42006C  
which seems to be hexadecimal, but I can't decipher into proper text.  
I guess i'd be looking on User Name, but can't find anything

2nd Question:  
How can I forward logs from winevt/logs ? I was thinking of entering the logs path into yml or putting the saved logs so whenever someone opens the saved logs from that folder it will automatically load it into winlogbeat  
Any clues?  
Thanks

---

<div class="post-metadata">

### Author: ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)
#### Post date: [July 13, 2018, 5:48pm UTC](https://discuss.elastic.co/t/finding-user-name-more/139942/2 "2018-07-13T17:48:14Z")

</div>

Hi,

> [@Marcos\_Felix](#):
>
> 1st Question:  
> I am forwarding logs from my collector environment to Kibana using winlogbeat  
> I am interested in finding who done what.  
> When I check a log I look for the user that done that, and I can't find - maybe I have bad filtering?  
> I found this: Logon ID: 0xA42006C  
> which seems to be hexadecimal, but I can't decipher into proper text.  
> I guess i'd be looking on User Name, but can't find anything

There should be some `user.*` fields with the information you are looking for. You can find [in the documentation](https://www.elastic.co/guide/en/beats/winlogbeat/6.3/exported-fields-eventlog.html) the list of fields collected.

> [@Marcos\_Felix](#):
>
> 2nd Question:  
> How can I forward logs from winevt/logs ? I was thinking of entering the logs path into yml or putting the saved logs so whenever someone opens the saved logs from that folder it will automatically load it into winlogbeat

To forward logs from files to Elasticsearch, you can use [`filebeat`](https://www.elastic.co/products/beats/filebeat).

---

<div class="post-metadata">

### Author: ![Marcos\_Felix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcos_felix/32/32486_2.png) [@Marcos\_Felix](https://discuss.elastic.co/u/Marcos_Felix)
#### Post date: [July 16, 2018, 8:22am UTC](https://discuss.elastic.co/t/finding-user-name-more/139942/3 "2018-07-16T08:22:42Z")

</div>

> [@jsoriano](#):
>
> To forward logs from files to Elasticsearch, you can use [`filebeat`](https://www.elastic.co/products/beats/filebeat).

if my filebeat is located on the Linux server and the logs saved is on Windows - how can I link the filebeat to collect from windows?

---

<div class="post-metadata">

### Author: ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)
#### Post date: [July 16, 2018, 3:57pm UTC](https://discuss.elastic.co/t/finding-user-name-more/139942/4 "2018-07-16T15:57:58Z")

</div>

You can also install filebeat in Windows, indeed it is recommended to install beats directly in each one of the nodes you want to monitor or collect logs from.

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [July 16, 2018, 10:41pm UTC](https://discuss.elastic.co/t/finding-user-name-more/139942/5 "2018-07-16T22:41:00Z")

</div>

> [@Marcos\_Felix](#):
>
> I found this: Logon ID: 0xA42006C

This doc explains the Logon ID and has other useful information about the fields contains in various events.

> <https://github.com/MicrosoftDocs/windows-itpro-docs/blob/main/windows/security/threat-protection/auditing/event-4624.md>

---

<div class="post-metadata">

### Author: ![Marcos\_Felix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcos_felix/32/32486_2.png) [@Marcos\_Felix](https://discuss.elastic.co/u/Marcos_Felix)
#### Post date: [July 17, 2018, 8:12am UTC](https://discuss.elastic.co/t/finding-user-name-more/139942/6 "2018-07-17T08:12:17Z")

</div>

> [@jsoriano](#):
>
> You can also install filebeat in Windows, indeed it is recommended to install beats directly in each one of the nodes you want to monitor or collect logs from.

That clears it up thank you. im also guessing by installing it on windows it doesnt get int he way of the Linux one. also i am only interested in the windows logs so i guess i can delete the Linux filebeat and it wont affect my winlogbeat right?

---

<div class="post-metadata">

### Author: ![Marcos\_Felix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcos_felix/32/32486_2.png) [@Marcos\_Felix](https://discuss.elastic.co/u/Marcos_Felix)
#### Post date: [July 17, 2018, 8:19am UTC](https://discuss.elastic.co/t/finding-user-name-more/139942/7 "2018-07-17T08:19:16Z")

</div>

Great read, thanks

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 14, 2018, 8:19am UTC](https://discuss.elastic.co/t/finding-user-name-more/139942/8 "2018-08-14T08:19:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
