# Winlogbeat 7.9 not shipping logs in full ECS?

**URL:** <https://discuss.elastic.co/t/winlogbeat-7-9-not-shipping-logs-in-full-ecs/249411>\
**Category:** SIEM\
**Created:** [September 21, 2020, 6:51pm UTC](https://discuss.elastic.co/t/winlogbeat-7-9-not-shipping-logs-in-full-ecs/249411 "2020-09-21T18:51:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![AleksandrN](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@AleksandrN](https://discuss.elastic.co/u/AleksandrN)\
**Post date:** [September 21, 2020, 6:51pm UTC](https://discuss.elastic.co/t/winlogbeat-7-9-not-shipping-logs-in-full-ecs/249411/1 "2020-09-21T18:51:05Z")

</div>

Hello everyone,  
I'mtrying to fill my Elastic SIEM with data, but it seems like Winlogbeat is not shipping logs in full ECS.  
For example, authentications wiget is empty:

 ![изображение](https://us1.discourse-cdn.com/elastic/original/3X/b/5/b502a8fa4d4383277d74111375f6ae79243780e1.png)

And it is formed by such default request:

```
{
  "aggregations": {
    "eventActionGroup": {
      "terms": {
        "field": "event.outcome",
        "include": [
          "success",
          "failure"
        ],
        "order": {
          "_count": "desc"
        },
        "size": 2
      },
      "aggs": {
        "events": {
          "date_histogram": {
            "field": "@timestamp",
            "fixed_interval": "2700000ms",
            "min_doc_count": 0,
            "extended_bounds": {
              "min": 1600625803013,
              "max": 1600712203013
            }
          }
        }
      }
    }
  },
  "query": {
    "bool": {
      "filter": [
        {
          "bool": {
            "must": [],
            "filter": [
              {
                "match_all": {}
              }
            ],
            "should": [],
            "must_not": []
          }
        },
        {
          "bool": {
            "must": [
              {
                "term": {
                  "event.category": "authentication"
                }
              }
            ]
          }
        },
        {
          "range": {
            "@timestamp": {
              "gte": "2020-09-20T18:16:43.013Z",
              "lte": "2020-09-21T18:16:43.013Z",
              "format": "strict_date_optional_time"
            }
          }
        }
      ]
    }
  },
  "size": 0,
  "track_total_hits": true
}

```

I have a plenty of auth events, such 4624 and 4625 Windows in same time window with such as wiget shows, but it somehow has event.action and no event.category:

 ![изображение](https://us1.discourse-cdn.com/elastic/original/3X/d/5/d555a3dab893e53ad5615360646d7b6960d59687.png)

And it is despite event.action is more narrow than event.category, so it be very straitfrward to have a category if action is here

 ![изображение](https://us1.discourse-cdn.com/elastic/original/3X/9/5/9552c6cfa75fa92662ffa2560c9bed9f6329910e.png)

> **[Event Fields | Elastic Common Schema (ECS) Reference \[1.6\] | Elastic](https://www.elastic.co/guide/en/ecs/1.6/ecs-event.html)**

May be I miss something? If no, SIEM is not so valuable out of the box...

---

<div class="post-metadata">

**Author:** ![Lee\_Hinman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lee_hinman/32/74973_2.png) [@Lee\_Hinman](https://discuss.elastic.co/u/Lee_Hinman)\
**Post date:** [September 22, 2020, 6:18pm UTC](https://discuss.elastic.co/t/winlogbeat-7-9-not-shipping-logs-in-full-ecs/249411/2 "2020-09-22T18:18:41Z")

</div>

Hi

This is interesting. For 7.9.0 I would expect the event section to look like this for a 4624:

```auto
"event": {
      "action": "logged-in",
      "category": "authentication",
      "code": 4624,
      "kind": "event",
      "module": "security",
      "outcome": "success",
      "provider": "Microsoft-Windows-Security-Auditing",
      "type": "start"
    },

```

So the fact that you don't have `event.category` and that your `event.action` value doesn't match is odd. Is there any chance your `winlogbeat-security.js` is older and not the one that shipped with 7.9.0? `event.action = Logon` would be from an older release of Winlogbeat.

---

<div class="post-metadata">

**Author:** ![AleksandrN](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@AleksandrN](https://discuss.elastic.co/u/AleksandrN)\
**Post date:** [September 23, 2020, 10:41am UTC](https://discuss.elastic.co/t/winlogbeat-7-9-not-shipping-logs-in-full-ecs/249411/3 "2020-09-23T10:41:42Z")

</div>

Hi,  
It seems like not consistent learning gone me into troubles.  
Modules were turned off (not mentioned in config). The main problem - on the add data page for winlogbeat modules are not mentined (like any other additional settings) as required. May be it's a subject to change.

---

<div class="post-metadata">

**Author:** ![MartinL](https://avatars.discourse-cdn.com/v4/letter/m/ebca7d/32.png) [@MartinL](https://discuss.elastic.co/u/MartinL)\
**Post date:** [September 24, 2020, 11:28am UTC](https://discuss.elastic.co/t/winlogbeat-7-9-not-shipping-logs-in-full-ecs/249411/5 "2020-09-24T11:28:56Z")

</div>

Hi again, nevermind my last post. I found an answer to my issues (which was exactly the same as yours) in this post.

# [(ELK 7.9.1) Security - Hosts and Security - Network missing data](https://discuss.elastic.co/t/elk-7-9-1-security-hosts-and-security-network-missing-data/248576)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 22, 2020, 11:29am UTC](https://discuss.elastic.co/t/winlogbeat-7-9-not-shipping-logs-in-full-ecs/249411/6 "2020-10-22T11:29:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
