# Not Logging Account Lockout (4740)

**URL:** <https://discuss.elastic.co/t/not-logging-account-lockout-4740/138023>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [June 29, 2018, 6:28pm UTC](https://discuss.elastic.co/t/not-logging-account-lockout-4740/138023 "2018-06-29T18:28:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Innove](https://avatars.discourse-cdn.com/v4/letter/i/ce73a5/32.png) [@Innove](https://discuss.elastic.co/u/Innove)\
**Post date:** [June 29, 2018, 6:28pm UTC](https://discuss.elastic.co/t/not-logging-account-lockout-4740/138023/1 "2018-06-29T18:28:45Z")

</div>

I have winlogbeat installed on a few desktops and our primary domain controller with all of them pointing to a SecurityOnion server with ELK. If I clear event logs (1102) for example, the event quickly shows up in my Kibana dashboard. Account lockouts though (4740) on the domain or local user accounts do not show up at all, even though they are in my event viewer. Looking at logs in debug mode, I not see an entry in it for the event.

**This is my configuration:**  
winlogbeat.event\_logs:

- name: Application
- name: Security
- name: System

**I have also tried explicitly setting the event with this config:**  
winlogbeat.event\_logs:

- name: Application
- name: Security  
event\_id: 4740
- name: System

This returns no events.

Any ideas? I am new to ELK and winlogbeat, so it may be something very obvious that I am missing. Any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [June 29, 2018, 8:06pm UTC](https://discuss.elastic.co/t/not-logging-account-lockout-4740/138023/2 "2018-06-29T20:06:43Z")

</div>

Hello @Innove,

Can you add the windows version that you are running, I am asking that because the EventID might be different depending on the Window release?

Also can you try the following:

- Remove registry file in `data/`
- Restart again.

I am asking for a clear because maybe the lockout event is old end the saved pointer is after that that event.

---

<div class="post-metadata">

**Author:** ![Innove](https://avatars.discourse-cdn.com/v4/letter/i/ce73a5/32.png) [@Innove](https://discuss.elastic.co/u/Innove)\
**Post date:** [July 2, 2018, 1:46pm UTC](https://discuss.elastic.co/t/not-logging-account-lockout-4740/138023/3 "2018-07-02T13:46:15Z")

</div>

@pierhugues ,

Thank you for the reply. There are two computers that I cannot get the event on: Windows Server 2016 and Windows 10 Pro. I have removed the registry file and rebooted, but I am getting the same problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 30, 2018, 1:46pm UTC](https://discuss.elastic.co/t/not-logging-account-lockout-4740/138023/4 "2018-07-30T13:46:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
