# Generically named event\_data.paramN on Windows XP and 2003

**URL:** <https://discuss.elastic.co/t/generically-named-event-data-paramn-on-windows-xp-and-2003/46329>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [April 5, 2016, 6:40am UTC](https://discuss.elastic.co/t/generically-named-event-data-paramn-on-windows-xp-and-2003/46329 "2016-04-05T06:40:23Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 5, 2016, 5:28pm UTC](https://discuss.elastic.co/t/generically-named-event-data-paramn-on-windows-xp-and-2003/46329/2 "2016-04-05T17:28:38Z")

</div>

> [@tuankun](#):
>
> But I found a problem,winlogbeat 1.2 will take the "Description" section data into the "message" field in ELK. it did not divide the sub-attribute into independent field,such as "User Name",Logon ID","Source Network Address" and so on.

Winlogbeat 1.2 does not provide the `event_data` field. That was introduced in v5.

> [@tuankun](#):
>
> I tested the winlogbeat v5 test version,it could divide the sub-attribute into independent field,but the field name of the sub-attribute will be like "event\_data.param1","event\_data.param2","event\_data.param3"....,not the correct name.

Unfortunately, in Windows 2000, XP, and 2003 the message parameters are not named. The `message` associated with an event is stored as a [template](https://msdn.microsoft.com/en-us/library/windows/desktop/dd996907(v=vs.85).aspx) in a DLL or EXE file like "File %1 contains %2 which is in error." When an application logs an event it just provides an array of parameters (see NumStrings in [`EVENTLOGRECORD`](https://msdn.microsoft.com/en-us/library/windows/desktop/aa363646(v=vs.85).aspx)) and the parameters get substituted into the message template by index number.

Because the parameters are unnamed and there is no guaranteed format to the message template, Winlogbeat cannot provide descriptive names for these fields. **You could use Logstash to rename the `event_data.paramN` fields to a more descriptive name on a per event ID basis.**

Windows Vista and newer switched to a new format for the event log records where the parameters are named.

---

_[View the full topic](https://discuss.elastic.co/t/generically-named-event-data-paramn-on-windows-xp-and-2003/46329)._
