# How to add a field with description for a specific Windows Event ID?

**URL:** <https://discuss.elastic.co/t/how-to-add-a-field-with-description-for-a-specific-windows-event-id/268617>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 29, 2021, 12:47am UTC](https://discuss.elastic.co/t/how-to-add-a-field-with-description-for-a-specific-windows-event-id/268617 "2021-03-29T00:47:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![nael\_uchiha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nael_uchiha/32/86213_2.png) [@nael\_uchiha](https://discuss.elastic.co/u/nael_uchiha)\
**Post date:** [March 29, 2021, 12:47am UTC](https://discuss.elastic.co/t/how-to-add-a-field-with-description-for-a-specific-windows-event-id/268617/1 "2021-03-29T00:47:33Z")

</div>

Hello,  
I need to add some fields and descriptions for a Windows Event ID.  
For example, `for winlog.event_id = 1111 create a field named rule.description: Our descroption`

Thank you for your help!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 30, 2021, 2:20pm UTC](https://discuss.elastic.co/t/how-to-add-a-field-with-description-for-a-specific-windows-event-id/268617/2 "2021-03-30T14:20:32Z")

</div>

You could use the [`add_fields` processor](https://www.elastic.co/guide/en/beats/winlogbeat/current/add-fields.html) with a `when` condition.

```auto
processors:
  - add_fields:
      when.equals.winlog.event_id: 1111
      target: rule
      fields:
        description: Our description

```

---

<div class="post-metadata">

**Author:** ![nael\_uchiha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nael_uchiha/32/86213_2.png) [@nael\_uchiha](https://discuss.elastic.co/u/nael_uchiha)\
**Post date:** [March 30, 2021, 6:31pm UTC](https://discuss.elastic.co/t/how-to-add-a-field-with-description-for-a-specific-windows-event-id/268617/3 "2021-03-30T18:31:40Z")

</div>

Thanks for your help  
Unfortunately, it seems that winlogbeat does not add the field. I don't see it in Kibana

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 30, 2021, 7:14pm UTC](https://discuss.elastic.co/t/how-to-add-a-field-with-description-for-a-specific-windows-event-id/268617/4 "2021-03-30T19:14:06Z")

</div>

Please share the configuration that you are using. Surround it with three backticks before and after to preserve the formatting/spacing.

---

<div class="post-metadata">

**Author:** ![nael\_uchiha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nael_uchiha/32/86213_2.png) [@nael\_uchiha](https://discuss.elastic.co/u/nael_uchiha)\
**Post date:** [March 30, 2021, 11:30pm UTC](https://discuss.elastic.co/t/how-to-add-a-field-with-description-for-a-specific-windows-event-id/268617/5 "2021-03-30T23:30:48Z")

</div>

Actually it was a formatting/spacing issue, I didn't know that spacing is very important for winlogbeat!  
It works now.  
Thank you very much andrew for your help 👍

---

<div class="post-metadata">

**Author:** ![nael\_uchiha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nael_uchiha/32/86213_2.png) [@nael\_uchiha](https://discuss.elastic.co/u/nael_uchiha)\
**Post date:** [March 31, 2021, 12:22am UTC](https://discuss.elastic.co/t/how-to-add-a-field-with-description-for-a-specific-windows-event-id/268617/6 "2021-03-31T00:22:43Z")

</div>

Another question please:  
If I have more when statement: if event id = 1111 then add field description= test-1111, if event id = 2222 then add field description = test-2222...., I have to create more processors or I can just use 1 processors with more when statements?

```auto
processors:
  - add_fields:
      when.equals.winlog.event_id: 1111
      target: rule
      fields:
        id: 1111
        description: User Disabled       
      when.equals.winlog.event_id: 2222
      target: rule
      fields:
        id: 2222
        description: User enabled`

```

I want to put a specific id and description for some event IDs, is this the correct way to do it?

Thank you for your help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2021, 2:22am UTC](https://discuss.elastic.co/t/how-to-add-a-field-with-description-for-a-specific-windows-event-id/268617/7 "2021-04-28T02:22:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
