INFO :
"_index": "logstash-2016.06.10",
"_type": "eventlog",
"_id": "AVU4pSR0yeP15vt6ARUS",
"_score": null,
"_source": {
"EventTime": "2016-06-09 23:13:57",
"Hostname": "KOZHIKODE.ontashindia.local",
"Keywords": -9214364837600035000,
"EventType": "AUDIT_SUCCESS",
"SeverityValue": 2,
"Severity": "INFO",
"EventID": 4634,
"SourceName": "Microsoft-Windows-Security-Auditing",
"ProviderGuid": "{54849625-5478-4994-A5BA-3E3B0328C30D}",
"Version": 0,
"Task": 12545,
"OpcodeValue": 0,
"RecordNumber": 18518828,
"ProcessID": 548,
"ThreadID": 580,
"Channel": "Security",
"Message": "An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tKOZHIKODE$\r\n\tAccount Domain:\t\tONTASHINDIA\r\n\tLogon ID:\t\t0x1DBDAF7B\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.",
"Category": "Logoff",
"Opcode": "Info",
"TargetUserSid": "S-1-5-18",
"TargetUserName": "KOZHIKODE$",
"TargetDomainName": "ONTASHINDIA",
"TargetLogonId": "0x1dbdaf7b",
"LogonType": "3",
"EventReceivedTime": "2016-06-10 10:19:34",
"SourceModuleName": "eventlog",
"SourceModuleType": "im_msvistalog",
"@version": "1",
"@timestamp": "2016-06-10T04:49:54.762Z",
"host": "135.219.172.23",
"port": 57366,
"type": "eventlog",
"tags": [
"_grokparsefailure"
]
},
"fields": {
"@timestamp": [
1465534194762
]
},
"sort": [
1465534194762
]
WARNING :
"_index": "logstash-2016.06.10",
"_type": "eventlog",
"_id": "AVU4qG85yeP15vt6AZY4",
"_score": null,
"_source": {
"EventTime": "2016-06-10 10:23:28",
"Hostname": "KOZHIKODE.ontashindia.local",
"Keywords": -9223372036854776000,
"EventType": "WARNING",
"SeverityValue": 3,
"Severity": "WARNING",
"EventID": 1002,
"SourceName": "Microsoft-Windows-KnownFolders",
"ProviderGuid": "{8939299F-2315-4C5C-9B91-ABB86AA0627D}",
"Version": 0,
"Task": 0,
"OpcodeValue": 0,
"RecordNumber": 2049330,
"ActivityID": "{417C638D-1C28-4374-A6CA-3DC8784F39D1}",
"ProcessID": 912,
"ThreadID": 3564,
"Channel": "Microsoft-Windows-Known Folders API Service",
"Domain": "NT AUTHORITY",
"AccountName": "SYSTEM",
"UserID": "SYSTEM",
"AccountType": "User",
"Message": "Error 0x80070002 occurred while verifying known folder {B97D20BB-F46A-4C97-BA10-5E3608430854} with path 'C:\\Users\\Default\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup'.",
"Opcode": "Info",
"hrError": "0x80070002",
"FolderId": "{B97D20BB-F46A-4C97-BA10-5E3608430854}",
"Path": "C:\\Users\\Default\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
"EventReceivedTime": "2016-06-10 10:23:29",
"SourceModuleName": "eventlog",
"SourceModuleType": "im_msvistalog",
"@version": "1",
"@timestamp": "2016-06-10T04:53:30.178Z",
"host": "135.219.172.23",
"port": 57366,
"type": "eventlog",
"tags": [
"_grokparsefailure"
]
},
"fields": {
"@timestamp": [
1465534410178
]
},
"highlight": {
"SourceModuleName": [
"@kibana-highlighted-field@eventlog@/kibana-highlighted-field@"
],
"SourceModuleName.raw": [
"@kibana-highlighted-field@eventlog@/kibana-highlighted-field@"
],
"EventType": [
"@kibana-highlighted-field@WARNING@/kibana-highlighted-field@"
],
"Severity": [
"@kibana-highlighted-field@WARNING@/kibana-highlighted-field@"
],
"type.raw": [
"@kibana-highlighted-field@eventlog@/kibana-highlighted-field@"
],
"type": [
"@kibana-highlighted-field@eventlog@/kibana-highlighted-field@"
]
},
"sort": [
1465534410178
]