# Issues with additional event logs enabled

**URL:** <https://discuss.elastic.co/t/issues-with-additional-event-logs-enabled/242416>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [July 23, 2020, 10:38pm UTC](https://discuss.elastic.co/t/issues-with-additional-event-logs-enabled/242416 "2020-07-23T22:38:43Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![rmoat](https://avatars.discourse-cdn.com/v4/letter/r/8797f3/32.png) [@rmoat](https://discuss.elastic.co/u/rmoat)\
**Post date:** [July 23, 2020, 10:38pm UTC](https://discuss.elastic.co/t/issues-with-additional-event-logs-enabled/242416/1 "2020-07-23T22:38:44Z")

</div>

Hello,

I am trying to get events from two separate logs on our domain controllers, and just realized today that the entire Security log was not being sent to Kibana by winlogbeat after I tried to send events from a second log. (The second log was sending to Kibana, but nothing from Security).

Here is an example of what I was using for the config:

`winlogbeat.event_logs:`  
`- name: Security`  
`processors:`  
`- script:`  
`lang: javascript`  
` id: security`  
` file: ${path.home}/module/security/config/winlogbeat-security.js`  
` - drop_event.when.not.or:`  
#EventID: 4625 An account failed to logon  
` - equals.winlog.event_id: 4625`  
#EventID: 4723 An attempt was made to change an account's password  
`- equals.winlog.event_id: 4723`

\<I have about **30** additional event ids I am pulling but only including the first couple events above\>

Below that, I have this:

`- name: Microsoft-AzureADPasswordProtection-DCAgent/Admin `  
`processors:`  
`- drop_event.when.not.or: `  
` - equals.winlog.event_id: 10012`  
# Event ID: 10013 PasswordSetErrors  
`- equals.winlog.event_id: 10013`  
# Event ID: 10014 PasswordChangesValidated  
` - equals.winlog.event_id: 10014`  
# Event ID: 10015 PasswordSetsValidated  
`- equals.winlog.event_id: 10015`

It was only pulling in the events from the **Microsoft-AzureADPasswordProtection-DCAgent/Admin** log, and all Security events weren't being pulled in.

I tried just pulling in all MIcrosoft-AzureADPasswordProtection-DCAgent/Admin logs by using only:  
`- name: Microsoft-AzureADPasswordProtection-DCAgent/Admin`

But I just get errors saying an expected key was missing.

If I move it up above Security, then I get all of the security events, but nothing from the Azure logs. I'm not sure what's going on:

`- name: Microsoft-AzureADPasswordProtection-DCAgent/Admin`  
` - name: Security`  
` processors:`  
` - script:`  
` lang: javascript`  
` id: security`  
` file: ${path.home}/module/security/config/winlogbeat-security.js`  
` - drop_event.when.not.or:`  
#EventID: 4625 An account failed to logon  
` - equals.winlog.event_id: 4625`  
#EventID: 4723 An attempt was made to change an account's password  
`- equals.winlog.event_id: 4723`  
`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2020, 12:38am UTC](https://discuss.elastic.co/t/issues-with-additional-event-logs-enabled/242416/2 "2020-08-21T00:38:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
