# Missing event\_data fields in Winlogbeat 1.x

**URL:** <https://discuss.elastic.co/t/missing-event-data-fields-in-winlogbeat-1-x/62511>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [October 7, 2016, 5:15pm UTC](https://discuss.elastic.co/t/missing-event-data-fields-in-winlogbeat-1-x/62511 "2016-10-07T17:15:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gmourani](https://avatars.discourse-cdn.com/v4/letter/g/a6a055/32.png) [@gmourani](https://discuss.elastic.co/u/gmourani)\
**Post date:** [October 7, 2016, 5:15pm UTC](https://discuss.elastic.co/t/missing-event-data-fields-in-winlogbeat-1-x/62511/1 "2016-10-07T17:15:13Z")

</div>

Hello,

winlogbeat 1.3 is installed and successful send event log directly to elastic on port 9200. Index is created in Kibana and I can see fields related to winlogbeat except all the "event\_data fields.\*" !

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 7, 2016, 5:27pm UTC](https://discuss.elastic.co/t/missing-event-data-fields-in-winlogbeat-1-x/62511/2 "2016-10-07T17:27:05Z")

</div>

> [@gmourani](#):
>
> I can see fields related to winlogbeat except all the "event\_data fields.\*" !

Those fields are not present in Winlogbeat 1.x. That data/feature was added in Winlogbeat 5.x.

---

<div class="post-metadata">

**Author:** ![gmourani](https://avatars.discourse-cdn.com/v4/letter/g/a6a055/32.png) [@gmourani](https://discuss.elastic.co/u/gmourani)\
**Post date:** [October 7, 2016, 5:47pm UTC](https://discuss.elastic.co/t/missing-event-data-fields-in-winlogbeat-1-x/62511/3 "2016-10-07T17:47:11Z")

</div>

Does Winlogbeat 5.x is compatible with Elasticsearch 2.3.x ?  
If yes, can I upgrade from Winlogbeat 1.3 to 5.x ?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 7, 2016, 5:51pm UTC](https://discuss.elastic.co/t/missing-event-data-fields-in-winlogbeat-1-x/62511/4 "2016-10-07T17:51:46Z")

</div>

> [@gmourani](#):
>
> Does Winlogbeat 5.x is compatible with Elasticsearch 2.3.x ?

Yes, we include an index template that is compatible with ES 2.x.

> [@gmourani](#):
>
> If yes, can I upgrade from Winlogbeat 1.3 to 5.x ?

There are some minor changes in the configuration files. I recommend you see the upgrade guide. There will be some minor config file changes and you will need to install and updated index template.

[https://www.elastic.co/guide/en/beats/libbeat/5.0/\_upgrading\_from\_1\_x\_to\_5\_x.html](https://www.elastic.co/guide/en/beats/libbeat/5.0/_upgrading_from_1_x_to_5_x.html)

---

<div class="post-metadata">

**Author:** ![gmourani](https://avatars.discourse-cdn.com/v4/letter/g/a6a055/32.png) [@gmourani](https://discuss.elastic.co/u/gmourani)\
**Post date:** [October 12, 2016, 1:40pm UTC](https://discuss.elastic.co/t/missing-event-data-fields-in-winlogbeat-1-x/62511/5 "2016-10-12T13:40:38Z")

</div>

Thanks again for your great support,

Just to let you know that it's working now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 2, 2016, 1:40pm UTC](https://discuss.elastic.co/t/missing-event-data-fields-in-winlogbeat-1-x/62511/6 "2016-11-02T13:40:42Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
