# Install winlogbeat.template.json

**URL:** <https://discuss.elastic.co/t/install-winlogbeat-template-json/65746>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [November 11, 2016, 3:09am UTC](https://discuss.elastic.co/t/install-winlogbeat-template-json/65746 "2016-11-11T03:09:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![MSAdmin](https://avatars.discourse-cdn.com/v4/letter/m/f04885/32.png) [@MSAdmin](https://discuss.elastic.co/u/MSAdmin)\
**Post date:** [November 11, 2016, 3:09am UTC](https://discuss.elastic.co/t/install-winlogbeat-template-json/65746/1 "2016-11-11T03:09:03Z")

</div>

I've been trying to setup [monitoring for failed logins](https://www.elastic.co/blog/monitoring-windows-logons-with-winlogbeat). I have winlogbeat running on my server and its feeding event logs over to my elastic server. When I loaded the JSON file (winlogbeat-account-usage-dashboard.json) from that page, I get an error saying:

Error  
Saved Objects: Could not locate that index-pattern-field (id: event\_data.LogonType)

And then when I load the dashboard I get errors in all the frames like "Could not locate that visualization (id: Total-Successful-Logons-1)"

I tried to push the winlogbeat.template.json from my windows server via PS, since I figured that would insert the index-pattern-field I need. But I kept getting error 400. So, I resorted to putting the winlogbeat.template.json in my home folder on the server and running:

sudo curl -XPUT [http://localhost:9200/\_template/winlogbeat](http://localhost:9200/_template/winlogbeat) -d @./winlogbeat.template.json

and I get

{"error":{"root\_cause":[{"type":"parse\_exception","reason":"Failed to derive xcontent"}],"type":"parse\_exception","reason":"Failed to derive xcontent"},"status":400}

I tried replacing localhost with the IP address and got the same error. I also tried with and without the sudo. Any suggestions?

---

<div class="post-metadata">

**Author:** ![MSAdmin](https://avatars.discourse-cdn.com/v4/letter/m/f04885/32.png) [@MSAdmin](https://discuss.elastic.co/u/MSAdmin)\
**Post date:** [November 11, 2016, 3:19am UTC](https://discuss.elastic.co/t/install-winlogbeat-template-json/65746/2 "2016-11-11T03:19:18Z")

</div>

Something I just noticed: when I'm looking in the Discover tab, event\_data.LogonType is an available data type. So I'm not sure why I can't load the JSON from the example site either.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 14, 2016, 2:33pm UTC](https://discuss.elastic.co/t/install-winlogbeat-template-json/65746/3 "2016-11-14T14:33:16Z")

</div>

> [@MSAdmin](#):
>
> Saved Objects: Could not locate that index-pattern-field (id: event\_data.LogonType)

All of the `event_data.*` fields are dynamic since that aren't known up front by Winlogbeat. After you have indexed some events you'll likely need to refresh the fields for the index pattern in Kibana. (Management -\> Index Patterns -\> winlogbeat-\* -\> Click Refresh Icon Button)

> [@MSAdmin](#):
>
> I tried to push the winlogbeat.template.json from my windows server via PS, since I figured that would insert the index-pattern-field I need.

By default Winlogbeat 5.x will install the index template to Elasticsearch if you are using the ES output. You can check if the index template is already installed with `curl http://localhost:9200/_template/winlogbeat`. There should also be some log output saying that it installed the template.

This index template is used by Elasticsearch. The "index-pattern-field" is a separate thing that is part of the Kibana index pattern.

> [@MSAdmin](#):
>
> {"error":{"root\_cause":[{"type":"parse\_exception","reason":"Failed to derive xcontent"}],"type":"parse\_exception","reason":"Failed to derive xcontent"},"status":400}

I wonder if that file is corrupted in some way. Maybe an editor made some line ending or encoding changes. Can you try the Powershell command again on a clean version of the file taken directly from the zip file.

> [@MSAdmin](#):
>
> And then when I load the dashboard I get errors in all the frames like "Could not locate that visualization (id: Total-Successful-Logons-1)"

I can try to retest that dashboard today on a clean ES/Kibana.

---

<div class="post-metadata">

**Author:** ![MSAdmin](https://avatars.discourse-cdn.com/v4/letter/m/f04885/32.png) [@MSAdmin](https://discuss.elastic.co/u/MSAdmin)\
**Post date:** [November 22, 2016, 4:28pm UTC](https://discuss.elastic.co/t/install-winlogbeat-template-json/65746/4 "2016-11-22T16:28:13Z")

</div>

Actually, just the "Management -\> Index Patterns -\> winlogbeat-\* -\> Click Refresh Icon Button" fixed the problem I was having. That caused the proper fields to be available so I could upload the templates. Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2016, 4:28pm UTC](https://discuss.elastic.co/t/install-winlogbeat-template-json/65746/5 "2016-12-20T16:28:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
