# Windows file server files auditing - parsing logs

**URL:** <https://discuss.elastic.co/t/windows-file-server-files-auditing-parsing-logs/371320>\
**Category:** Elasticsearch\
**Tags:** windows\
**Created:** [December 2, 2024, 2:16pm UTC](https://discuss.elastic.co/t/windows-file-server-files-auditing-parsing-logs/371320 "2024-12-02T14:16:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Adriano\_Trindade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adriano_trindade/32/139638_2.png) [@Adriano\_Trindade](https://discuss.elastic.co/u/Adriano_Trindade)\
**Post date:** [December 2, 2024, 2:16pm UTC](https://discuss.elastic.co/t/windows-file-server-files-auditing-parsing-logs/371320/1 "2024-12-02T14:16:16Z")

</div>

Hello everyone!

I've set up Windows logs for auditing a Windows file server. File access logs being generated OK. I've deployed a ELK stack in a VM. Configured Winlogbeats on Windows file server OK. Security logs are being received in Elasticsearch OK. Not using Logstash. All the info I need about files creation / modifying / delete are arriving on Elasticsearch sucessfully.

My problem is: the received logs don't discriminate user names and file names + path into specific fields. Some data is discriminated into proper fields, like agent.hostname, event.code and so on. But the filename and username are together with another info in a big string field on the logs, and I must extract these specific fields from this string data.

Once I have this data into specific fields, I can work with this data making filters and creating visualizations. Maybe using Logstash + some custom script?

Any hint on how I can customize these logs in the presented way would be welcome.

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [December 2, 2024, 3:22pm UTC](https://discuss.elastic.co/t/windows-file-server-files-auditing-parsing-logs/371320/2 "2024-12-02T15:22:16Z")

</div>

Have you looked into setting up Elastic Agent to collect Windows logs?

With the "System" integration enabled with agent, these logs are automatically pulled, parsed, and enriched.

---

<div class="post-metadata">

**Author:** ![Adriano\_Trindade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adriano_trindade/32/139638_2.png) [@Adriano\_Trindade](https://discuss.elastic.co/u/Adriano_Trindade)\
**Post date:** [December 26, 2024, 4:10pm UTC](https://discuss.elastic.co/t/windows-file-server-files-auditing-parsing-logs/371320/3 "2024-12-26T16:10:07Z")

</div>

Thanks on the insight.

I´ve had no luck with Elastic Agent, so I've setup winlogbeat instead.

But I'll give another try on Elastic Agent instead of Winlogbeat.

---

<div class="post-metadata">

**Author:** ![Adriano\_Trindade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adriano_trindade/32/139638_2.png) [@Adriano\_Trindade](https://discuss.elastic.co/u/Adriano_Trindade)\
**Post date:** [December 26, 2024, 6:18pm UTC](https://discuss.elastic.co/t/windows-file-server-files-auditing-parsing-logs/371320/4 "2024-12-26T18:18:17Z")

</div>

I've installed Elastic Agent alongside Winlogbeat.

Appears to be working, I'm getting some errors, but now I can work it out.

Thanks again!

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [December 26, 2024, 8:41pm UTC](https://discuss.elastic.co/t/windows-file-server-files-auditing-parsing-logs/371320/5 "2024-12-26T20:41:14Z")

</div>

Feel free to post about any errors you're seeing as well!
