# "Successully published" but it didn't

**URL:** <https://discuss.elastic.co/t/successully-published-but-it-didnt/204432>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [October 21, 2019, 10:15am UTC](https://discuss.elastic.co/t/successully-published-but-it-didnt/204432 "2019-10-21T10:15:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ajawm](https://avatars.discourse-cdn.com/v4/letter/a/a9a28c/32.png) [@ajawm](https://discuss.elastic.co/u/ajawm)\
**Post date:** [October 21, 2019, 10:15am UTC](https://discuss.elastic.co/t/successully-published-but-it-didnt/204432/1 "2019-10-21T10:15:16Z")

</div>

I have setup winlogbeat according to instructions, however logs do not show up in Kibana, despite log stating "successfully published".

| 2019-10-21T11:37:59.647+0200 | WARN | elasticsearch/client.go:535 | Cannot index event publisher.Event{Content:beat.Event{Timestamp:time.Time{wall:0x946c75c, ext:63707247477, loc:(\*time.Location)(nil)}, Meta:common.MapStr(nil), Fields:common.MapStr{"agent":common.MapStr{"ephemeral\_id":"10e9afc2-1576-4643-86d2-0ef0070fcca7", "hostname":"LAPTOP-FEM9SVF4", "id":"0349223d-36a1-485d-bd95-8aa5e07a3a6c", "type":"winlogbeat", "version":"7.4.0"}, "ecs":common.MapStr{"version":"1.1.0"}, "event":common.MapStr{"action":"User Account Management", "code":0x12be, "created":common.Time{wall:0x24355bdc, ext:63707247478, loc:(\*time.Location)(nil)}, "kind":"event"}, "host":common.MapStr{"architecture":"x86\_64", "hostname":"LAPTOP-FEM9SVF4", "id":"7f1b6202-cde5-4247-b9ab-da3c0724d18b", "name":"LAPTOP-FEM9SVF4", "os":common.MapStr{"build":"18362.418", "family":"windows", "kernel":"10.0.18362.418 (WinBuild.160101.0800)", "name":"Windows 10 Pro", "platform":"windows", "version":"10.0"}}, "log":common.MapStr{"level":"information"}, "message":"A user's local group membership was enumerated.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tLAPTOP-FEM9SVF4$\n\tAccount Domain:\t\tWORKGROUP\n\tLogon ID:\t\t0x3E7\n\nUser:\n\tSecurity ID:\t\tS-1-5-21-3162102966-2696753098-2875345929-1001\n\tAccount Name:\t\tArtjoms Jakovenko\n\tAccount Domain:\t\tLAPTOP-FEM9SVF4\n\nProcess Information:\n\tProcess ID:\t\t0x2ee0\n\tProcess Name:\t\tC:\Windows\System32\LogonUI.exe", "winlog":common.MapStr{"activity\_id":"{83670da8-8403-0002-4f0e-67830384d501}", "api":"wineventlog", "channel":"Security", "computer\_name":"LAPTOP-FEM9SVF4", "event\_data":common.MapStr{"CallerProcessId":"0x2ee0", "CallerProcessName":"C:\Windows\System32\LogonUI.exe", "SubjectDomainName":"WORKGROUP", "SubjectLogonId":"0x3e7", "SubjectUserName":"LAPTOP-FEM9SVF4$", "SubjectUserSid":"S-1-5-18", "TargetDomainName":"LAPTOP-FEM9SVF4", "TargetSid":"S-1-5-21-3162102966-2696753098-2875345929-1001", "TargetUserName":"Artjoms Jakovenko"}, "event\_id":0x12be, "keywords":string{"Audit Success"}, "opcode":"Info", "process":common.MapStr{"pid":0x2fc, "thread":common.MapStr{"id":0x359c}}, "provider\_guid":"{54849625-5478-4994-a5ba-3e3b0328c30d}", "provider\_name":"Microsoft-Windows-Security-Auditing", "record\_id":0xbee7, "task":"User Account Management"}}, Private:checkpoint.EventLogState{Name:"Security", RecordNumber:0xbee7, Timestamp:time.Time{wall:0x946c75c, ext:63707247477, loc:(\*time.Location)(nil)}, Bookmark:"\r\n \r\n"}, TimeSeries:false}, Flags:0x1} (status=400): {"type":"invalid\_index\_name\_exception","reason":"Invalid index name [winLogs], must be lowercase","index\_uuid":"_na_","index":"winLogs"} |
| --- | --- | --- | --- |
| 2019-10-21T11:37:59.647+0200 | INFO | beater/eventlogger.go:76 | EventLog[Security] successfully published 1 events |

#======================= Winlogbeat specific options ===========================

winlogbeat.event\_logs:

- name: Application  
ignore\_older: 72h

- name: System

- name: Security  
processors:

- name: Microsoft-Windows-Sysmon/Operational  
processors:

#==================== Elasticsearch template settings ==========================

setup.template.name: "winlogbeat"  
setup.template.pattern: "winlogbeat-\*"

setup.template.settings:  
index.number\_of\_shards: 1

#============================== Kibana =====================================

setup.kibana:

cloud.id: "CONFIDENTIALFORQUESTION"

cloud.auth: "CONFIDENTIALFORQUESTION"

#-------------------------- Elasticsearch output ------------------------------  
output.elasticsearch:  
index: "winLogs"

#================================ Processors =====================================

processors:

- add\_host\_metadata: ~
- add\_cloud\_metadata: ~

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 21, 2019, 1:35pm UTC](https://discuss.elastic.co/t/successully-published-but-it-didnt/204432/2 "2019-10-21T13:35:14Z")

</div>

> [@ajawm](#):
>
> status=400): {"type":"invalid\_index\_name\_exception","reason":"Invalid index name [winLogs], must be lowercase","index\_uuid":" _na_ ","index":"winLogs"}

Elasticsearch requires index names to be lowercase.

I would not recommend customizing the index name if this is your first time using Winlogbeat. Give it a try first with the defaults, and then read a bit more about Elasticsearch indices, mappings, and templates. When you change the index name you will need to change the index template pattern (`setup.template.pattern`) to match the index naming scheme that you have chosen.

---

<div class="post-metadata">

**Author:** ![ajawm](https://avatars.discourse-cdn.com/v4/letter/a/a9a28c/32.png) [@ajawm](https://discuss.elastic.co/u/ajawm)\
**Post date:** [October 22, 2019, 7:00am UTC](https://discuss.elastic.co/t/successully-published-but-it-didnt/204432/3 "2019-10-22T07:00:02Z")

</div>

Thank You for response, it helped. Indeed the issue was letter capitalization.  
I did not realize the warning message contained the error description and was only trying to solve "Cannot index event publisher.Event" error.  
The end of the string is especially unlikely to be seen when you inspect logs with notepad++. Perhaps, it may help you reduce the amount of support tickets on these basic problems if the error description was moved to the start 🙂 .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 19, 2019, 7:00am UTC](https://discuss.elastic.co/t/successully-published-but-it-didnt/204432/4 "2019-11-19T07:00:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
