# Pulling details of an event entry with Winlogbeat

**URL:** <https://discuss.elastic.co/t/pulling-details-of-an-event-entry-with-winlogbeat/43506>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 4, 2016, 12:40pm UTC](https://discuss.elastic.co/t/pulling-details-of-an-event-entry-with-winlogbeat/43506 "2016-03-04T12:40:22Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![snbart1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/snbart1/32/8281_2.png) [@snbart1](https://discuss.elastic.co/u/snbart1)\
**Post date:** [March 4, 2016, 12:40pm UTC](https://discuss.elastic.co/t/pulling-details-of-an-event-entry-with-winlogbeat/43506/1 "2016-03-04T12:40:22Z")

</div>

Hello everybody,  
I'm new working with the ELK stack.  
Actually I realized that it seems to be impossible to get the details of events with Winlogbeat.  
Only the General (or System in XML view) section is parsed.

Did I miss any configuration setting or is this planned for future versions?

Thanks  
Sebastian

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 4, 2016, 2:20pm UTC](https://discuss.elastic.co/t/pulling-details-of-an-event-entry-with-winlogbeat/43506/2 "2016-03-04T14:20:38Z")

</div>

Hi @snbart1, the `EventData` is incorporated into the `message` string, but the raw EventData fields are not included in the event. IMO this is the most important feature to add next. Related: [https://github.com/elastic/beats/pull/689#issuecomment-172583954](https://github.com/elastic/beats/pull/689#issuecomment-172583954) and [https://github.com/elastic/beats/issues/1053](https://github.com/elastic/beats/issues/1053)

---

<div class="post-metadata">

**Author:** ![snbart1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/snbart1/32/8281_2.png) [@snbart1](https://discuss.elastic.co/u/snbart1)\
**Post date:** [March 7, 2016, 12:09pm UTC](https://discuss.elastic.co/t/pulling-details-of-an-event-entry-with-winlogbeat/43506/3 "2016-03-07T12:09:45Z")

</div>

Hi Andrew,

thanks for your quick reply.  
What's the rough timeline until seeing this implemented?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 7, 2016, 2:28pm UTC](https://discuss.elastic.co/t/pulling-details-of-an-event-entry-with-winlogbeat/43506/4 "2016-03-07T14:28:03Z")

</div>

It will probably be released in 5.1. We are about to feature freeze for [5.0](https://www.elastic.co/v5) so this isn't going to be ready for that release.

Over the weekend I experimented with getting the EventData from the Windows APIs. It seems pretty simple if I get the event as XML and parse the data. It shouldn't take too long to implement, but I'll need to do some testing to see how XML parsing impacts performance. You can subscribe to [https://github.com/elastic/beats/issues/1053](https://github.com/elastic/beats/issues/1053) if you want to follow progress on the issue. Once the feature is implemented it will be available in [development builds](https://beats-nightlies.s3.amazonaws.com/index.html?prefix=winlogbeat/) if you want to test/try it before the official release.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 21, 2016, 2:49pm UTC](https://discuss.elastic.co/t/pulling-details-of-an-event-entry-with-winlogbeat/43506/5 "2016-03-21T14:49:55Z")

</div>

Hi @snbart1, this has been implemented. See my message here: [Winlogbeat and User sessions (parsing fields from message)](https://discuss.elastic.co/t/winlogbeat-and-user-sessions-parsing-fields-from-message/43003/10)

---

<div class="post-metadata">

**Author:** ![snbart1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/snbart1/32/8281_2.png) [@snbart1](https://discuss.elastic.co/u/snbart1)\
**Post date:** [March 22, 2016, 11:44am UTC](https://discuss.elastic.co/t/pulling-details-of-an-event-entry-with-winlogbeat/43506/6 "2016-03-22T11:44:40Z")

</div>

Great to hear.  
Will give it a try for sure

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 12, 2016, 1:47pm UTC](https://discuss.elastic.co/t/pulling-details-of-an-event-entry-with-winlogbeat/43506/7 "2016-04-12T13:47:43Z")

</div>


