I've upgraded to the latest version and winlogbeat is not sending data anymore
The changes in 7.13.0
Change event.code and winlog.event_id from int to keyword.
I'm seeing a lot of these
WARN [conditions] conditions/equals.go:37 expected int but got type string in equals condition
2021-05-28T08:59:23.109+1000 INFO instance/beat.go:665 Home path: [C:\Program Files\Winlogbeat] Config path: [C:\Program Files\Winlogbeat] Data path: [C:\Program Files\Winlogbeat\data] Logs path: [C:\Program Files\Winlogbeat\logs]
2021-05-28T08:59:23.109+1000 DEBUG [beat] instance/beat.go:723 Beat metadata path: C:\Program Files\Winlogbeat\data\meta.json
2021-05-28T08:59:23.113+1000 INFO instance/beat.go:673 Beat ID: 6e3f6db3-8cb0-4044-a283-e9e4de7b8c7f
2021-05-28T08:59:23.117+1000 DEBUG [add_cloud_metadata] add_cloud_metadata/providers.go:128 add_cloud_metadata: starting to fetch metadata, timeout=3s
2021-05-28T08:59:23.118+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.118+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.118+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.119+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.119+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.119+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.119+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.119+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.119+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.119+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.119+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.119+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.119+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.120+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.120+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.120+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.120+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.120+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.120+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.120+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.120+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.120+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.120+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.120+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.120+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.120+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.120+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.120+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.120+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.126+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.127+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0]
2021-05-28T08:59:23.127+1000 DEBUG [conditions] conditions/conditions.go:98 New condition equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or e
quals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.e
vent_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0]
or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winl
og.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49c0] or equals: map[winlog.event_id:0x17e49
c0] or equals: map[winlog.event_id:0x17e49
Let me know if more info is needed
In index patterns winlogbeat-*
winlog.event_id and event.code are long not string
{
"winlogbeat-7.12.1-2021.05.27" : {
"mappings" : {
"winlog.event_id" : {
"full_name" : "winlog.event_id",
"mapping" : {
"event_id" : {
"type" : "long"
}
}
}
}
}
}
Ingesting from winlogbeat > logstash > elasticsearch
Thanks for your your help