I cleaned up everything one more time.
Ran command winlogbeat setup from the endpoint (no errors):
Went to check winlogbeat-*
in Kibana/Saved Objects
Pulled out Winlogbeat mapping data from Dev Console
Winlogbeat index is also empty
ndjson file
{"attributes":{"fieldFormatMap":"{\"client.bytes\":{\"id\":\"bytes\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"client.nat.port\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"client.port\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"destination.bytes\":{\"id\":\"bytes\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"destination.nat.port\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"destination.port\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"event.duration\":{\"id\":\"duration\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"},\"inputFormat\":\"nanoseconds\",\"outputFormat\":\"asMilliseconds\",\"outputPrecision\":1}},\"event.sequence\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"event.severity\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"http.request.body.bytes\":{\"id\":\"bytes\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"http.request.bytes\":{\"id\":\"bytes\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"http.response.body.bytes\":{\"id\":\"bytes\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"http.response.bytes\":{\"id\":\"bytes\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"http.response.status_code\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"log.syslog.facility.code\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"log.syslog.priority\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"network.bytes\":{\"id\":\"bytes\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"package.size\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"process.parent.pgid\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"process.parent.pid\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"process.parent.ppid\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"process.parent.thread.id\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"process.pgid\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"process.pid\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"process.ppid\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"process.thread.id\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"server.bytes\":{\"id\":\"bytes\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"server.nat.port\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"server.port\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"source.bytes\":{\"id\":\"bytes\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"source.nat.port\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"source.port\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}},\"url.port\":{\"id\":\"string\",\"params\":{\"parsedUrl\":{\"origin\":\"https://192.168.1.190:5601\",\"pathname\":\"/app/dashboards\",\"basePath\":\"\"}}}}","fields":"[{\"name\":\"_id\",\"type\":\"string\",\"count\":0,\"scripted\":false,\"searchable\":false,\"aggregatable\":false,\"readFromDocValues\":false},{\"name\":\"_index\",\"type\":\"string\",\"count\":0,\"scripted\":false,\"searchable\":false,\"aggregatable\":false,\"readFromDocValues\":false},{\"name\":\"_score\",\"type\":\"number\",\"count\":0,\"scripted\":false,\"searchable\":false,\"aggregatable\":false,\"readFromDocValues\":false},{\"name\":\"_source\",\"type\":\"_source\",\"count\":0,\"scripted\":false,\"searchable\":false,\"aggregatable\":false,\"readFromDocValues\":false},{\"name\":\"_type\",\"type\":\"string\",\"count\":0,\"scripted\":false,\"searchable\":false,\"aggregatable\":false,\"readFromDocValues\":false}]","timeFieldName":"@timestamp","title":"winlogbeat-*"},"id":"winlogbeat-*","migrationVersion":{"index-pattern":"7.6.0"},"references":[],"type":"index-pattern","updated_at":"2020-11-24T14:52:35.546Z","version":"WzQ3MDU0MjEsNTld"}
{"exportedCount":1,"missingRefCount":0,"missingReferences":[]}
So this seems to be the issue. Winlogbeat is not experiencing a wrong mapping, but instead is not mapping at all. Setup
command is failing?