# Windows event classification mapping - is there a source for this?

**URL:** <https://discuss.elastic.co/t/windows-event-classification-mapping-is-there-a-source-for-this/299248>\
**Category:** Logstash\
**Created:** [March 9, 2022, 5:10pm UTC](https://discuss.elastic.co/t/windows-event-classification-mapping-is-there-a-source-for-this/299248 "2022-03-09T17:10:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mistrhanky](https://avatars.discourse-cdn.com/v4/letter/m/13edae/32.png) [@mistrhanky](https://discuss.elastic.co/u/mistrhanky)\
**Post date:** [March 9, 2022, 5:10pm UTC](https://discuss.elastic.co/t/windows-event-classification-mapping-is-there-a-source-for-this/299248/1 "2022-03-09T17:10:27Z")

</div>

I am writing(re-writing) a logstash parser for windows and I want to ensure that all of my events get categorized as closely as possible to the ECS definitions. The mappings I am directly referring to are event.type, event.category, and event. kind. I handle event.outcome already, and for most logs, I think event.kind = 'event' will probably be correct.

What I am looking for though is for each event.code(i.e. event 4625,4770,etc) is there a mapping anywhere that anyone has done to map the type and category fields? It is a ton of work to build this mapping from scratch and if you want to be in sync with the same fields others are using for future supportability, it all needs to categorized similiarly. Does anyone know of a resource to find a mapping for this?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 9, 2022, 5:22pm UTC](https://discuss.elastic.co/t/windows-event-classification-mapping-is-there-a-source-for-this/299248/2 "2022-03-09T17:22:29Z")

</div>

You could look at how the winlogbeat module categorize some events with its ingest pipeline.

For example to the event `4770`, it will do [this](https://github.com/elastic/beats/blob/35607336925218ce586c0f3d67e64099b5a36d98/x-pack/winlogbeat/module/security/ingest/security.yml#L580-L585):

```auto
        "4770":
          category:
            - authentication
          type:
            - start
          action: kerberos-service-ticket-renewed

```

Those are the `event.category`, `event.type` and `event.action` fields

---

<div class="post-metadata">

**Author:** ![mistrhanky](https://avatars.discourse-cdn.com/v4/letter/m/13edae/32.png) [@mistrhanky](https://discuss.elastic.co/u/mistrhanky)\
**Post date:** [March 9, 2022, 5:35pm UTC](https://discuss.elastic.co/t/windows-event-classification-mapping-is-there-a-source-for-this/299248/3 "2022-03-09T17:35:09Z")

</div>

Thanks for the quick reply. Kicking myself for not looking at that sooner!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2022, 5:36pm UTC](https://discuss.elastic.co/t/windows-event-classification-mapping-is-there-a-source-for-this/299248/4 "2022-04-06T17:36:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
