# Reporting Windows Security Events in Kibana

**URL:** <https://discuss.elastic.co/t/reporting-windows-security-events-in-kibana/44748>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 17, 2016, 5:55pm UTC](https://discuss.elastic.co/t/reporting-windows-security-events-in-kibana/44748 "2016-03-17T17:55:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dickepa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dickepa/32/8069_2.png) [@dickepa](https://discuss.elastic.co/u/dickepa)\
**Post date:** [March 17, 2016, 5:55pm UTC](https://discuss.elastic.co/t/reporting-windows-security-events-in-kibana/44748/1 "2016-03-17T17:55:33Z")

</div>

Hi, I've been experimenting with ELK for reporting Windows security events. Whilst I'm able to get the data into logstash using Winlogbeats over TLS, I've yet to visualize the activity of users on servers.

These are the events [https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/Default.aspx](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/Default.aspx)

Using a Kibana search I can see that that the [message] field contains the field [Account Name:] however the windows event ID that shows the act of logging on and off etc. is not so clearly presented in Kibana.

Has anyone used ELK for monitoring Windows security events? If so would appreciate knowing what you do to ID the Windows Security events (user accounts).

Thank you

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [March 17, 2016, 7:17pm UTC](https://discuss.elastic.co/t/reporting-windows-security-events-in-kibana/44748/2 "2016-03-17T19:17:04Z")

</div>

I moved this post to Winlogbeat, because I think you'll get a faster answer here on the topic of the data Winlogbeat exposes.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 17, 2016, 7:30pm UTC](https://discuss.elastic.co/t/reporting-windows-security-events-in-kibana/44748/3 "2016-03-17T19:30:01Z")

</div>

Hi Paul, I have been working on an [enhancement](https://github.com/elastic/beats/pull/1153) to Winlogbeat to make data like "Account Name" available as a field within the JSON event. Also Winlogbeat will report additional data like the "Task" contained in the event. This will make Winlogbeat a much more powerful tool. This is going to be released in [v5](https://www.elastic.co/v5), but a development build is available for testing (see [#1053](https://github.com/elastic/beats/pull/1053)).

Here's a screen shot:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/3/30e3d60203864e454e0aa906d6505ff323736a74.png)

---

<div class="post-metadata">

**Author:** ![dickepa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dickepa/32/8069_2.png) [@dickepa](https://discuss.elastic.co/u/dickepa)\
**Post date:** [March 18, 2016, 9:15am UTC](https://discuss.elastic.co/t/reporting-windows-security-events-in-kibana/44748/4 "2016-03-18T09:15:45Z")

</div>

Hi Andrew, I must say that Beats rocks. Very simple to set-up and before looking at it I was trying to get my head around the Windows monitoring that your screen shot perfectly shows the functionality I'm seeking. So yes, cannot wait to get this. Thanks for the info.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 12, 2016, 1:44pm UTC](https://discuss.elastic.co/t/reporting-windows-security-events-in-kibana/44748/5 "2016-04-12T13:44:52Z")

</div>


