# Winlogbeat 7.5.2 no data in discovery?

**URL:** <https://discuss.elastic.co/t/winlogbeat-7-5-2-no-data-in-discovery/218177>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [February 6, 2020, 1:03pm UTC](https://discuss.elastic.co/t/winlogbeat-7-5-2-no-data-in-discovery/218177 "2020-02-06T13:03:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![MarcusCaepio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcuscaepio/32/32458_2.png) [@MarcusCaepio](https://discuss.elastic.co/u/MarcusCaepio)\
**Post date:** [February 6, 2020, 1:03pm UTC](https://discuss.elastic.co/t/winlogbeat-7-5-2-no-data-in-discovery/218177/1 "2020-02-06T13:03:37Z")

</div>

Hi All,  
I just set up winlogbeat on a domain controller to check for failed AD logins.  
I am wondering, that I have really many documents in my discovery, but all of them are "empty". On the other side, in SIEM I can see the data. Is this normal? And if yes, how can I avoid it? Many emtpy documents in discovery are not really usefull imho 🙂

My winlogbeat config:  
I have my own ILM and already imported the template manually, so this is disabled. I am also wondering, that there seems to be no ingest pipelines, which can be imported.

```
winlogbeat.event_logs:
  #- name: Application
  # ignore_older: 72h

  #- name: System

  - name: Security
    ignore_older: 48h
    processors:
      - script:
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js

  #- name: Microsoft-Windows-Sysmon/Operational
  # processors:
  # - script:
  # lang: javascript
  # id: sysmon
  # file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js

#-------------------------- Elasticsearch output -------------------------------
output.elasticsearch:
  hosts: ["hot1:9200","hot2:9200"]
  compression_level: 9
  username: "beats"
  password: "xxx"
  worker: 2

setup.dashboards.enabled: false
setup.template.enabled: false
setup.ilm.enabled: false
logging.to_files: true
monitoring.enabled: true

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/1/41fe714c48a9ed676ee218e9ab01805cba1f9689.png)

Cheers,  
Marcus

---

<div class="post-metadata">

**Author:** ![MarcusCaepio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcuscaepio/32/32458_2.png) [@MarcusCaepio](https://discuss.elastic.co/u/MarcusCaepio)\
**Post date:** [February 6, 2020, 2:03pm UTC](https://discuss.elastic.co/t/winlogbeat-7-5-2-no-data-in-discovery/218177/2 "2020-02-06T14:03:47Z")

</div>

I fixed it. Seems there was a problem with the template. Now the fields are shown

---

<div class="post-metadata">

**Author:** ![Havoccultist](https://avatars.discourse-cdn.com/v4/letter/h/ed8c4c/32.png) [@Havoccultist](https://discuss.elastic.co/u/Havoccultist)\
**Post date:** [February 7, 2020, 9:53am UTC](https://discuss.elastic.co/t/winlogbeat-7-5-2-no-data-in-discovery/218177/3 "2020-02-07T09:53:39Z")

</div>

I think I am also facing this issue. Did you get any proper solution?

[telldunkin](https://www.telldunkin.vip/)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2020, 9:53am UTC](https://discuss.elastic.co/t/winlogbeat-7-5-2-no-data-in-discovery/218177/4 "2020-03-06T09:53:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
