# Generically named event\_data.paramN on Windows XP and 2003

**URL:** <https://discuss.elastic.co/t/generically-named-event-data-paramn-on-windows-xp-and-2003/46329>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [April 5, 2016, 6:40am UTC](https://discuss.elastic.co/t/generically-named-event-data-paramn-on-windows-xp-and-2003/46329 "2016-04-05T06:40:23Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![tuankun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tuankun/32/8590_2.png) [@tuankun](https://discuss.elastic.co/u/tuankun)\
**Post date:** [April 5, 2016, 6:40am UTC](https://discuss.elastic.co/t/generically-named-event-data-paramn-on-windows-xp-and-2003/46329/1 "2016-04-05T06:40:23Z")

</div>

Hi sir,  
I installed the winlogbeat 1.2 on windows server 2003 to collect security log,then transfer to ELK.  
But I found a problem,winlogbeat 1.2 will take the "Description" section data into the "message" field in ELK. it did not divide the sub-attribute into independent field,such as "User Name",Logon ID","Source Network Address" and so on.  
also I tested the winlogbeat v5 test version,it could divide the sub-attribute into independent field,but the field name of the sub-attribute will be like "event\_data.param1","event\_data.param2","event\_data.param3"....,not the correct name.

```
Could anyone help me ? thanks you so much.

```

security log:  
Event Type: Success Audit  
Event Source: Security  
Event Category: Logon/Logoff  
Event ID: 528  
Date: 4/5/2016  
Time: 1:39:09 PM  
User: SERVER01\Administrator  
Computer: CNKUSBK1  
**Description:**  
**Successful Logon:**  
\*\* User Name: Administrator\*\*  
\*\* Domain: CNKUSBK1\*\*  
\*\* Logon ID: (0x2,0x1F7BC1FF)\*\*  
\*\* Logon Type: 10\*\*  
\*\* Logon Process: User32 \*\*  
\*\* Authentication Package: Negotiate\*\*  
\*\* Workstation Name: SERVER01\*\*  
\*\* Logon GUID: -\*\*  
\*\* Caller User Name: SERVER01$\*\*  
\*\* Caller Domain: WORKGROUP\*\*  
\*\* Caller Logon ID: (0x0,0x3E7)\*\*  
\*\* Caller Process ID: 216\*\*  
\*\* Transited Services: -\*\*  
\*\* Source Network Address: 192.168.1.100\*\*  
\*\* Source Port: 53831\*\*

**For more information, see Help and Support Center at [http://go.microsoft.com/fwlink/events.asp](http://go.microsoft.com/fwlink/events.asp).**

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 5, 2016, 5:28pm UTC](https://discuss.elastic.co/t/generically-named-event-data-paramn-on-windows-xp-and-2003/46329/2 "2016-04-05T17:28:38Z")

</div>

> [@tuankun](#):
>
> But I found a problem,winlogbeat 1.2 will take the "Description" section data into the "message" field in ELK. it did not divide the sub-attribute into independent field,such as "User Name",Logon ID","Source Network Address" and so on.

Winlogbeat 1.2 does not provide the `event_data` field. That was introduced in v5.

> [@tuankun](#):
>
> I tested the winlogbeat v5 test version,it could divide the sub-attribute into independent field,but the field name of the sub-attribute will be like "event\_data.param1","event\_data.param2","event\_data.param3"....,not the correct name.

Unfortunately, in Windows 2000, XP, and 2003 the message parameters are not named. The `message` associated with an event is stored as a [template](https://msdn.microsoft.com/en-us/library/windows/desktop/dd996907(v=vs.85).aspx) in a DLL or EXE file like "File %1 contains %2 which is in error." When an application logs an event it just provides an array of parameters (see NumStrings in [`EVENTLOGRECORD`](https://msdn.microsoft.com/en-us/library/windows/desktop/aa363646(v=vs.85).aspx)) and the parameters get substituted into the message template by index number.

Because the parameters are unnamed and there is no guaranteed format to the message template, Winlogbeat cannot provide descriptive names for these fields. **You could use Logstash to rename the `event_data.paramN` fields to a more descriptive name on a per event ID basis.**

Windows Vista and newer switched to a new format for the event log records where the parameters are named.

---

<div class="post-metadata">

**Author:** ![tuankun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tuankun/32/8590_2.png) [@tuankun](https://discuss.elastic.co/u/tuankun)\
**Post date:** [April 6, 2016, 12:24am UTC](https://discuss.elastic.co/t/generically-named-event-data-paramn-on-windows-xp-and-2003/46329/3 "2016-04-06T00:24:38Z")

</div>

thank you so much,andrewkroh,have you the time to release the stable version of winlogbeat v5? I can hardly wait.😀

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 6, 2016, 12:40am UTC](https://discuss.elastic.co/t/generically-named-event-data-paramn-on-windows-xp-and-2003/46329/4 "2016-04-06T00:40:29Z")

</div>

I don't have a date for the 5.0 GA. We released [5.0.0-alpha1](https://www.elastic.co/blog/elastic-stack-release-5-0-0-alpha-1) today and there will be few more releases prior to GA.

---

<div class="post-metadata">

**Author:** ![tuankun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tuankun/32/8590_2.png) [@tuankun](https://discuss.elastic.co/u/tuankun)\
**Post date:** [April 6, 2016, 1:48am UTC](https://discuss.elastic.co/t/generically-named-event-data-paramn-on-windows-xp-and-2003/46329/5 "2016-04-06T01:48:08Z")

</div>

Got it, I will test winlogbeat 5.0.0-alpha1,if no error，I will deploy it on all our our producation servers,thanks~~

---

<div class="post-metadata">

**Author:** ![dickepa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dickepa/32/8069_2.png) [@dickepa](https://discuss.elastic.co/u/dickepa)\
**Post date:** [April 12, 2016, 11:24am UTC](https://discuss.elastic.co/t/generically-named-event-data-paramn-on-windows-xp-and-2003/46329/6 "2016-04-12T11:24:57Z")

</div>

Hi Andrew, I have tried winlogbeat-5.0.0-alpha1-windows 64 but it's not sending data to my ELK stack. When I run it I do so using powershell run as admin "winlogbeat.exe -c winlogbeat.yml" and it seems to run without error message! However difficult to say since the cursor in ps just sits there and i am unable to see if winlogbeat is running in services.msc or get-service in powershell. All I know is that no data is being received.

Can you please advise more comprehensive instructions than the advice provided on the download page?

Thanks Paul

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 12, 2016, 1:21pm UTC](https://discuss.elastic.co/t/generically-named-event-data-paramn-on-windows-xp-and-2003/46329/7 "2016-04-12T13:21:30Z")

</div>

@dickepa, please start a new topic as I think this is mostly unrelated to the question here. For "comprehensive instructions" see the [Getting Started](https://www.elastic.co/guide/en/beats/winlogbeat/master/winlogbeat-installation.html) section in the documentation. You need to use `-e` and `-v` to get more verbose output to the console (and for really verbose output add `-d "*"`).

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 12, 2016, 3:32pm UTC](https://discuss.elastic.co/t/generically-named-event-data-paramn-on-windows-xp-and-2003/46329/8 "2016-04-12T15:32:49Z")

</div>


