# Winlogbeat 8.0.0 parsing with module

**URL:** <https://discuss.elastic.co/t/winlogbeat-8-0-0-parsing-with-module/317812>\
**Category:** Beats\
**Tags:** beats-module, winlogbeat\
**Created:** [October 31, 2022, 10:53am UTC](https://discuss.elastic.co/t/winlogbeat-8-0-0-parsing-with-module/317812 "2022-10-31T10:53:23Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![vitkon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitkon/32/97669_2.png) [@vitkon](https://discuss.elastic.co/u/vitkon)\
**Post date:** [October 31, 2022, 10:53am UTC](https://discuss.elastic.co/t/winlogbeat-8-0-0-parsing-with-module/317812/1 "2022-10-31T10:53:24Z")

</div>

Hello everyone

I have an ELK 8.0.0 series. I am testing the build of windows logs using winlogbeat 8.0.0. As I understand from the elastic documentation, the parsing of raw windows events will be by means of Security, PowerShell, Sysmon modules([Modules | Winlogbeat Reference [8.0] | Elastic](https://www.elastic.co/guide/en/beats/winlogbeat/8.0/winlogbeat-modules.html)). Based on this information, I collected a config.

```auto
winlogbeat.event_logs:
  - name: Application
    ignore_older: 72h
  - name: Security
  - name: System
  - name: ForwardedEvents
    tags: ["forwarder"]

setup.template.settings:
  index.number_of_shards: 1

max_procs: 1
keystore.path: ${path.home}/winlogbeat.keystore

output.elasticsearch:
  hosts: ["https://server1:9200", "https://server2:9200"]
  protocol: https
  index: "winlogbeat-nvs"
  username: "***"
  password: "***"
  ssl:
    enabled: true
    verification_mode: full
    supported_protocol: [TLSv1.2, TLSv1.3]
    certificate_authorities: ${path.home}/rootCA.cer

setup.ilm.enabled: false
setup.template.overwrite: true

output.elasticsearch.pipeline: winlogbeat-%{[agent.version]}-routing

setup.template.name: 'winlogbeat'
setup.template.pattern: 'winlogbeat'
setup.template.enabled: true

```

But I get incomplete parsing of logs in cabana, and almost all fields are unknown field.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/7/67631d5bdbf02343e0ae7e4129c43f961b2e4213.png)

Experts, please tell me, is this a full-fledged parsing or am I missing something?

---

<div class="post-metadata">

**Author:** ![vitkon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitkon/32/97669_2.png) [@vitkon](https://discuss.elastic.co/u/vitkon)\
**Post date:** [November 1, 2022, 6:11am UTC](https://discuss.elastic.co/t/winlogbeat-8-0-0-parsing-with-module/317812/2 "2022-11-01T06:11:44Z")

</div>

Someone can help me?

---

<div class="post-metadata">

**Author:** ![vitkon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitkon/32/97669_2.png) [@vitkon](https://discuss.elastic.co/u/vitkon)\
**Post date:** [November 2, 2022, 8:58am UTC](https://discuss.elastic.co/t/winlogbeat-8-0-0-parsing-with-module/317812/3 "2022-11-02T08:58:17Z")

</div>

Nobody faced such a problem?

---

<div class="post-metadata">

**Author:** ![vitkon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitkon/32/97669_2.png) [@vitkon](https://discuss.elastic.co/u/vitkon)\
**Post date:** [November 3, 2022, 8:25am UTC](https://discuss.elastic.co/t/winlogbeat-8-0-0-parsing-with-module/317812/4 "2022-11-03T08:25:54Z")

</div>

Studying the problem, I found in the elasticsearch.yml config that the ingest role was missing from the assigned roles. I thought that I had finally found the root of the problem, but I hurried to rejoice by specifying ingest in node.roles, the problem was not solved

My cluster consists of 3 nodes:  
1 - nodes.roles: [master, data, remoting\_cluster\_client]  
2 - nodes.roles: [master, data, remoting\_cluster\_client]  
3 - nodes.roles: [data, remoting\_cluster\_client, ml, ingest]

Added a new user with full rights cluster\_privilege and kibana - no result

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 3, 2022, 1:50pm UTC](https://discuss.elastic.co/t/winlogbeat-8-0-0-parsing-with-module/317812/5 "2022-11-03T13:50:01Z")

</div>

What specific version are you using for Winlogbeat?

Did you restarted your cluster after adding the `ingest` role?

Did you load the ingest pipelines?

Did you load the template for your index?

---

<div class="post-metadata">

**Author:** ![vitkon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitkon/32/97669_2.png) [@vitkon](https://discuss.elastic.co/u/vitkon)\
**Post date:** [November 3, 2022, 2:27pm UTC](https://discuss.elastic.co/t/winlogbeat-8-0-0-parsing-with-module/317812/6 "2022-11-03T14:27:28Z")

</div>

> [@leandrojmp](#):
>
> What specific version are you using for Winlogbeat?
> 
> Did you restarted your cluster after adding the `ingest` role?
> 
> Did you load the ingest pipelines?
> 
> Did you load the template for your index?

Hello, leandrojmp! Thanks for the answer!

I'm using winlogbeat 8.0.0  
Yes, I rebutted each node separately, as it says [here](https://www.elastic.co/guide/en/elasticsearch/reference/master/restart-cluster.html)

Yes, pipelines are loaded automatically, I see them in the kibana section of ingest pipelines

 ![pipilenes](https://us1.discourse-cdn.com/elastic/original/3X/6/9/69e9444a9c9e46b0d3d047bda48a2194e85590ca.png)

Yes, template is created automatically when creating an index. This can be seen from the winlogbeat config, which is located above

---

<div class="post-metadata">

**Author:** ![vitkon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitkon/32/97669_2.png) [@vitkon](https://discuss.elastic.co/u/vitkon)\
**Post date:** [November 4, 2022, 12:19pm UTC](https://discuss.elastic.co/t/winlogbeat-8-0-0-parsing-with-module/317812/7 "2022-11-04T12:19:02Z")

</div>

Even if I delete winlogbeat pipelines, nothing changes, the data in kibana remains in the same form. It seems that the parsing mechanism itself does not turn on...

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 4, 2022, 1:21pm UTC](https://discuss.elastic.co/t/winlogbeat-8-0-0-parsing-with-module/317812/8 "2022-11-04T13:21:58Z")

</div>

> [@vitkon](#):
>
> Even if I delete winlogbeat pipelines, nothing changes, the data in kibana remains in the same form.

You deleted the ingest pipelines and still got data in your cluster? Winlogbeat should fail if a ingest pipeline that it uses while sending data does not exists.

Have you tried sending it without changing the index name? Using the default one.

Do you have any errors in Winlogbeat logs?

> [@vitkon](#):
>
> `setup.template.pattern: 'winlogbeat'`

Also, I'm not sure this is correct, this would not match your `winlogbeat-nvs` index, try to change it to `winlogbeat-nvs`.

Can you share the template `winlogbeat` ?

---

<div class="post-metadata">

**Author:** ![vitkon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitkon/32/97669_2.png) [@vitkon](https://discuss.elastic.co/u/vitkon)\
**Post date:** [November 6, 2022, 10:51am UTC](https://discuss.elastic.co/t/winlogbeat-8-0-0-parsing-with-module/317812/9 "2022-11-06T10:51:02Z")

</div>

> You deleted the ingest pipelines and still got data in your cluster? Winlogbeat should fail if a ingest pipeline that it uses while sending data does not exists.

Yes, I am deleting pipelines, but the data is still being written to the index. at that time, no errors are recorded in the winlogbeat log

> Have you tried sending it without changing the index name? Using the default one.

yes, I tried writing to the standard index that is created after starting winlogbeat (index name: winlogbeat-8.0.0), but nothing has changed. There are no errors in the winlogbeat log either, even with debug logging mode enabled

> Can you share the template `winlogbeat` ?

Yes, I can. It's too big, I put it in my [git](https://github.com/Vitkonv/win/blob/main/win_template), please take a look

---

<div class="post-metadata">

**Author:** ![vitkon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitkon/32/97669_2.png) [@vitkon](https://discuss.elastic.co/u/vitkon)\
**Post date:** [November 10, 2022, 2:25pm UTC](https://discuss.elastic.co/t/winlogbeat-8-0-0-parsing-with-module/317812/10 "2022-11-10T14:25:49Z")

</div>

I didn't find the root of the problem, reinstalled the cluster and connected winlogbeat again, everything worked

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2022, 4:26pm UTC](https://discuss.elastic.co/t/winlogbeat-8-0-0-parsing-with-module/317812/11 "2022-12-08T16:26:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
