# How to display the PC user's name when displaying log information collected with Winlogbeat in Kibana

**URL:** <https://discuss.elastic.co/t/how-to-display-the-pc-users-name-when-displaying-log-information-collected-with-winlogbeat-in-kibana/357117>\
**Category:** Kibana\
**Created:** [April 10, 2024, 7:58am UTC](https://discuss.elastic.co/t/how-to-display-the-pc-users-name-when-displaying-log-information-collected-with-winlogbeat-in-kibana/357117 "2024-04-10T07:58:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![YUUTA.INOUE-JPN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuuta.inoue-jpn/32/117963_2.png) [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Post date:** [April 10, 2024, 7:58am UTC](https://discuss.elastic.co/t/how-to-display-the-pc-users-name-when-displaying-log-information-collected-with-winlogbeat-in-kibana/357117/1 "2024-04-10T07:58:29Z")

</div>

Hello from Japan  
I have a question for my respected Elastic engineers.  
I have been working on collecting Windows log information collected using Winlogbeat into Elasticsearch and visualizing it using Kibana.  
These efforts faced a number of challenges.

A typical example is that Kibana can only visualize the host name of the PC sending logs.  
I used to use version 7 of the Elastic Stack (mainly Elasticsearch, Kibana, and Winlogbeat).  
At that time, I succeeded in linking the PC host name and the PC user using the method below.

①I transition the screen as shown below.

```auto
Kibana→management→indexpattern→scriptfield

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/c/ecb6960b0aa3e957f86a999ee51bdcb198b68333.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/7/77fe74f3b72ed5282ebf161ac13b4f209f7f6ae4.png)

②I loaded the script field below into Kibana.

```auto
if (doc['agent.hostname'].value == 'PC-HostName') { return 'YUUTA' }
else if (doc['agent.hostname'].value == 'PC-HostName2') { return 'INOUE' }

```

However, after upgrading Elastic Stack to version 8, we discovered that this mechanism no longer works.  
We were very troubled. (This is because information about computer users cannot be grasped instantly.)  
\*It is unfortunate that we accidentally discovered that these are written in the official Elasticseach documentation.

> **[Manage data views | Kibana Guide \[8.13\] | Elastic](https://www.elastic.co/guide/en/kibana/current/managing-data-views.html)**

The method we were able to implement in V7 was to statically replace it on the Kibana screen, but it helped us.  
I would like to implement a similar method in Version 8, but is there a way?

My ElasticStack environment is as follows.

```auto
Kibana 8.11.1 

```

```auto
Elasticseach 8.11.1

```

```auto
Winlogbeat 8.11.1

```

Please help me  
regards  
Thank you

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [April 30, 2024, 9:22am UTC](https://discuss.elastic.co/t/how-to-display-the-pc-users-name-when-displaying-log-information-collected-with-winlogbeat-in-kibana/357117/2 "2024-04-30T09:22:35Z")

</div>

Hi!

In Elasticsearch 8 runtime fields replaced scripts. The code is pretty much the same, and a lookup as you have would be something like this (using the Kibana Flights dataset)

```auto
// First check the field exists
if (doc['Carrier'].size() == 0) {
    emit("😱");
} else if (doc['Carrier'].value == "ES-Air") {
    emit("E");
} else if (doc['Carrier'].value == "Logstash Airways") {
    emit("L")
} else if (doc['Carrier'].value == "Kibana Airlines") {
    emit("K")
} else if (doc['Carrier'].value == "JetBeats") {
    emit("B")
} else {
    // Always return something
    emit("🤔");
}

```

This code would be placed in the **Set value** section in the **Add field** interface

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/2/722b611ae1ff9dec26207b15e79532a57fab2024.png)

Hope it helps.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 30, 2024, 11:02am UTC](https://discuss.elastic.co/t/how-to-display-the-pc-users-name-when-displaying-log-information-collected-with-winlogbeat-in-kibana/357117/3 "2024-04-30T11:02:01Z")

</div>

Adding to this great answer that you could also do that using `lookup` from another index as described in:

> **[Enrich your Elasticsearch documents within Elasticsearch](https://www.elastic.co/blog/enrich-your-elasticsearch-documents-within-elasticsearch)**
>
> With Elasticsearch, we know that joins should be done "at index time" instead of query time. This blog post starts a series of three posts as there are many approaches we can take within the Elastic e...

😉
