# Problems with bad authentification logs on windows

**URL:** <https://discuss.elastic.co/t/problems-with-bad-authentification-logs-on-windows/131156>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 9, 2018, 10:16am UTC](https://discuss.elastic.co/t/problems-with-bad-authentification-logs-on-windows/131156 "2018-05-09T10:16:40Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![hash-ill](https://avatars.discourse-cdn.com/v4/letter/h/b19c9b/32.png) [@hash-ill](https://discuss.elastic.co/u/hash-ill)\
**Post date:** [May 9, 2018, 10:16am UTC](https://discuss.elastic.co/t/problems-with-bad-authentification-logs-on-windows/131156/1 "2018-05-09T10:16:41Z")

</div>

Hi everybody,  
I'm new here and i have few questions.  
First, I install ELK with X-pack and I have some problem:  
My authentifications fails does not appears on my discover menu in kibana. When I fail authentification, the log is interpreted like an "audit success" and the event id is "4624" who's match with a good authentification Id.  
I don't get why the bad authentification logs are interpreted like a good authentification.  
IDK if it's a bad interpretation on kibana or a problem in winlogbeats.  
thanks for you responses  
Ps: excuse my english i'm french

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [May 9, 2018, 10:27am UTC](https://discuss.elastic.co/t/problems-with-bad-authentification-logs-on-windows/131156/2 "2018-05-09T10:27:15Z")

</div>

Hi @hash-ill,

Could you please paste winlogbeat logs to check what's going on?

Best regards

---

<div class="post-metadata">

**Author:** ![hash-ill](https://avatars.discourse-cdn.com/v4/letter/h/b19c9b/32.png) [@hash-ill](https://discuss.elastic.co/u/hash-ill)\
**Post date:** [May 9, 2018, 12:19pm UTC](https://discuss.elastic.co/t/problems-with-bad-authentification-logs-on-windows/131156/3 "2018-05-09T12:19:04Z")

</div>

![capture%20log%20windows](https://us1.discourse-cdn.com/elastic/original/3X/8/f/8f7fb07942e9d860c66ca745b789db12fd9b9b21.PNG)

 ![logs%20kibana](https://us1.discourse-cdn.com/elastic/original/3X/b/e/bea236bf8700278a23bdeeaaa33aaebc9b106d58.PNG)

first, thanks for you response, i give your the windows log in windows and inn kibana.  
The same event but big differences in the interpretation.  
Best regards

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 9, 2018, 8:01pm UTC](https://discuss.elastic.co/t/problems-with-bad-authentification-logs-on-windows/131156/4 "2018-05-09T20:01:37Z")

</div>

Can you share the raw XML view of the event. To get the XML included in the event for debugging you need to add [include\_xml: true](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#_literal_event_logs_include_xml_literal) to your config. Then you can see the raw XML in Kibana that Windows provides to Winlogbeat. You can see some examples of the conversion [here](https://gist.github.com/andrewkroh/c88950a56e0d0b4dcee1).

From the XML, Winlogbeat uses the `RenderingInfo.Level` value for its `level` value. If that field isn't present then it falls back to using the numeric `Level` value and converts it to text based on the table defined for [event type values](https://msdn.microsoft.com/en-us/library/windows/desktop/aa363646(v=vs.85).aspx).

---

<div class="post-metadata">

**Author:** ![hash-ill](https://avatars.discourse-cdn.com/v4/letter/h/b19c9b/32.png) [@hash-ill](https://discuss.elastic.co/u/hash-ill)\
**Post date:** [May 11, 2018, 2:30pm UTC](https://discuss.elastic.co/t/problems-with-bad-authentification-logs-on-windows/131156/5 "2018-05-11T14:30:01Z")

</div>

Thanks for your respons @andrewkroh, i don't know where i find the raw xml, i change the kibana.yml file as you said and i can't use kibana after that.  
I don't undestand why just a line like this is so influent. In fact the kibana service run (so there is no syntax error on my line) but i can't access to the kibana interface on the web.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 11, 2018, 3:40pm UTC](https://discuss.elastic.co/t/problems-with-bad-authentification-logs-on-windows/131156/6 "2018-05-11T15:40:09Z")

</div>

> [@hash-ill](#):
>
> i change the kibana.yml file as you said

I never said to modify a kibana.yml. I want to you to add `include_xml: true` to your Winlogbeat configuration (the [link](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#_literal_event_logs_include_xml_literal) I gave points to the Winlogbeat documentation and shows an example of how your winlogbeat.yml should look when you use `include_xml: true`).

```auto
winlogbeat.event_logs:
  - name: Security
    include_xml: true

```

Then after adding making this change to Winlogbeat, events from the Security log will include a field named [xml](https://www.elastic.co/guide/en/beats/winlogbeat/current/exported-fields-eventlog.html#_literal_xml_literal).

---

<div class="post-metadata">

**Author:** ![hash-ill](https://avatars.discourse-cdn.com/v4/letter/h/b19c9b/32.png) [@hash-ill](https://discuss.elastic.co/u/hash-ill)\
**Post date:** [May 14, 2018, 10:13am UTC](https://discuss.elastic.co/t/problems-with-bad-authentification-logs-on-windows/131156/7 "2018-05-14T10:13:35Z")

</div>

My bad, i wasn't understood this. I test this and it works, thank you very much.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2018, 10:13am UTC](https://discuss.elastic.co/t/problems-with-bad-authentification-logs-on-windows/131156/8 "2018-06-11T10:13:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
