# How to add an event created time in Winlogbeat.yml for version 6.3

**URL:** <https://discuss.elastic.co/t/how-to-add-an-event-created-time-in-winlogbeat-yml-for-version-6-3/205674>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [October 29, 2019, 1:18pm UTC](https://discuss.elastic.co/t/how-to-add-an-event-created-time-in-winlogbeat-yml-for-version-6-3/205674 "2019-10-29T13:18:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Post date:** [October 29, 2019, 1:18pm UTC](https://discuss.elastic.co/t/how-to-add-an-event-created-time-in-winlogbeat-yml-for-version-6-3/205674/1 "2019-10-29T13:18:17Z")

</div>

Hi all,

The goal is to have the event that the raw log from event viewer was first generated inside the windows event log. That way I will have two time stamps one from the pipeline @timestamp and a event\_created timestamp.

I have managed to get this working for the latest version of winlogbeat by adding the following processor to my winlogbeat.yml file:

processors:

- add\_locale:  
format: abbreviation

This adds some fields like:

"created": "2019-10-29T12:43:44.741Z", "timezone": "GMT", "kind": "event"

However with version 6.3 (currently what we are using for prod) it only adds local timezone instead of an actual timestamp.

Any ideas? Thanks in advance

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 26, 2019, 1:18pm UTC](https://discuss.elastic.co/t/how-to-add-an-event-created-time-in-winlogbeat-yml-for-version-6-3/205674/2 "2019-11-26T13:18:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
