# Registry Fields with Winlogbeat

**URL:** <https://discuss.elastic.co/t/registry-fields-with-winlogbeat/385082>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [February 17, 2026, 7:26pm UTC](https://discuss.elastic.co/t/registry-fields-with-winlogbeat/385082 "2026-02-17T19:26:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![TheBob](https://avatars.discourse-cdn.com/v4/letter/t/cab0a1/32.png) [@TheBob](https://discuss.elastic.co/u/TheBob)\
**Post date:** [February 17, 2026, 7:26pm UTC](https://discuss.elastic.co/t/registry-fields-with-winlogbeat/385082/1 "2026-02-17T19:26:25Z")

</div>

Running an Elastic Stack version 8 server. Trying to get Winlogbeat to send events to the server and run some detection rules alerts on them, but not getting all the expected fields configured.

E.g. one of the rules monitors registry changes and is looking for both winlog.event\_data.Details and registry.path fields, which I understand should be part of the ECS Windows mappings:

I’ve tried:

a) Enabling auditing for the registry, and get 4657 events generated in the event log and these get shipped to Logstash (also tried shipping directly to ES). They appear to get some ECS mapping (e.g. ecs.version = 8.0.0, event.code = 4657) but neither of the fields expected by the detection rule is populated.

b) Installing sysmon and shipping those events there’s a little bit of progress. The winlog.event\_data.Details is populated, but not the registry.

There’s a datastream in the stack management and it’s using a winlogbeat mapping.

I’m a bit stumped as to what we’re missing.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 17, 2026, 10:05pm UTC](https://discuss.elastic.co/t/registry-fields-with-winlogbeat/385082/2 "2026-02-17T22:05:07Z")

</div>

It sounds like you might be missing the ingest pipelines, because that is what creates the registry fields from the sysmon data, if I remember correctly. Did you install the ingest pipelines?

> **[Load ingest pipelines | Beats](https://www.elastic.co/docs/reference/beats/winlogbeat/load-ingest-pipelines)**
>
> Winlogbeat modules are implemented using Elasticsearch ingest node pipelines. The events receive their transformations within Elasticsearch. The ingest...

In your config file, at least the default one that ships with Winlogbeat, specifies the name of the ingest pipeline. You should see that if you look in winlogbeat.yml. Like [beats/x-pack/winlogbeat/winlogbeat.yml at 8de6b1fe48766cd5ae124cc031770c370f7a3dd3 · elastic/beats · GitHub](https://github.com/elastic/beats/blob/8de6b1fe48766cd5ae124cc031770c370f7a3dd3/x-pack/winlogbeat/winlogbeat.yml#L126)
