# Winlogbeat 8.5 and Windows 11 22H2

**URL:** <https://discuss.elastic.co/t/winlogbeat-8-5-and-windows-11-22h2/318676>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [November 10, 2022, 5:16pm UTC](https://discuss.elastic.co/t/winlogbeat-8-5-and-windows-11-22h2/318676 "2022-11-10T17:16:05Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![logs4drew](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/logs4drew/32/113350_2.png) [@logs4drew](https://discuss.elastic.co/u/logs4drew)\
**Post date:** [November 10, 2022, 5:16pm UTC](https://discuss.elastic.co/t/winlogbeat-8-5-and-windows-11-22h2/318676/1 "2022-11-10T17:16:05Z")

</div>

Greetings! It appears that variables (e.g. %1, %2) in windows events shipped via winlogbeat do not have these variables replaced with their real values.

Example:

```auto
Credential Manager credentials were read.

Subject:
	Security ID: %1
	Account Name: %2
	Account Domain: %3
	Logon ID: %4
	Read Operation: %8

This event occurs when a user performs a read operation on stored credentials in Credential Manager.

```

I verified i'm using the latest publicly available winlogbeat version (8.5) but still encounter this issue. I also tried searching on this forum and around the internet but can't find any acknowledgment that this issue exists.

Any ideas?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 10, 2022, 8:06pm UTC](https://discuss.elastic.co/t/winlogbeat-8-5-and-windows-11-22h2/318676/2 "2022-11-10T20:06:00Z")

</div>

Please share the winlogbeat.yml configuration you are using.

To debug this event, add [`include_xml: true`](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#_event_logs_include_xml) into the configuration for the event log that's producing this document. After that change, share the JSON document from Elasticsearch that has this issues so that we can see the full event with the raw XML stored in `event.original`.

---

<div class="post-metadata">

**Author:** ![logs4drew](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/logs4drew/32/113350_2.png) [@logs4drew](https://discuss.elastic.co/u/logs4drew)\
**Post date:** [November 14, 2022, 11:33pm UTC](https://discuss.elastic.co/t/winlogbeat-8-5-and-windows-11-22h2/318676/3 "2022-11-14T23:33:25Z")

</div>

winlogbeat config:

```yaml
fields_under_root: true

output.logstash:
   hosts: ["redacted:5044"]
path:
  data: .\data
  logs: .\logs
winlogbeat:
  event_logs:
   - name: Application
     ignore_older: 1h
   - name: System
     ignore_older: 1h
   - name: Security
     ignore_older: 1h
   - name: Setup
     ignore_older: 1h

```

Sample JSON document:

```json
{
    "winlogbeat_event_created": "2022-11-14T23:26:53.533Z",
    "winlogbeat_agent_id": "19ecbfde-93bb-42ca-99d7-1aae1aba63b2",
    "winlogbeat_winlog_opcode": "Info",
    "winlogbeat_ecs_version": "8.0.0",
    "winlogbeat_event_code": "7040",
    "source": "unknown",
    "winlogbeat_winlog_user_identifier": "S-1-5-21-63776543-3909903815-3855965128-1001",
    "winlogbeat_winlog_user_type": "User",
    "winlogbeat_winlog_event_data_param4": "BITS",
    "winlogbeat_winlog_event_data_param3": "demand start",
    "winlogbeat_event_original": "<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='Service Control Manager' Guid='{555908d1-a6d7-4695-8e1e-26931d2012f4}' EventSourceName='Service Control Manager'/><EventID Qualifiers='16384'>7040</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8080000000000000</Keywords><TimeCreated SystemTime='2022-11-14T23:25:46.7729215Z'/><EventRecordID>4749</EventRecordID><Correlation/><Execution ProcessID='1456' ThreadID='27768'/><Channel>System</Channel><Computer>DESKTOP-OIU9K0J</Computer><Security UserID='S-1-5-21-63776543-3909903815-3855965128-1001'/></System><EventData><Data Name='param1'>Background Intelligent Transfer Service</Data><Data Name='param2'>auto start</Data><Data Name='param3'>demand start</Data><Data Name='param4'>BITS</Data></EventData><RenderingInfo Culture='en-US'><Message>The start type of the %1 service was changed from %2 to %3.</Message><Level>Information</Level><Provider>Microsoft-Windows-Service Control Manager</Provider><Keywords><Keyword>Classic</Keyword></Keywords></RenderingInfo></Event>",
    "winlogbeat_event_action": "None",
    "streams": [
    "000000000000000000000001"
    ],
    "winlogbeat_@timestamp": "2022-11-14T23:25:46.772Z",
    "winlogbeat_agent_version": "8.5.0",
    "winlogbeat_agent_ephemeral_id": "33e854ff-2ffd-4c75-a3c2-f675cfebdb32",
    "winlogbeat_@metadata_version": "8.5.0",
    "winlogbeat_winlog_record_id": 4749,
    "winlogbeat_log_level": "information",
    "winlogbeat_@metadata_type": "_doc",
    "winlogbeat_@metadata_beat": "winlogbeat",
    "winlogbeat_event_provider": "Service Control Manager",
    "beats_type": "winlogbeat",
    "winlogbeat_winlog_user_domain": "DESKTOP-OIU9K0J",
    "winlogbeat_agent_name": "DESKTOP-OIU9K0J",
    "winlogbeat_winlog_event_id": "7040",
    "timestamp": "2022-11-14T23:25:46.772Z",
    "winlogbeat_winlog_task": "None",
    "winlogbeat_host_name": "DESKTOP-OIU9K0J",
    "winlogbeat_winlog_user_name": "geek4",
    "winlogbeat_winlog_channel": "System",
    "winlogbeat_winlog_computer_name": "DESKTOP-OIU9K0J",
    "winlogbeat_event_kind": "event",
    "winlogbeat_winlog_event_data_param2": "auto start",
    "winlogbeat_winlog_event_data_param1": "Background Intelligent Transfer Service",
    "winlogbeat_winlog_process_thread_id": 27768,
    "winlogbeat_winlog_api": "wineventlog",
    "message": "The start type of the %1 service was changed from %2 to %3.",
    "winlogbeat_winlog_provider_guid": "{555908d1-a6d7-4695-8e1e-26931d2012f4}",
    "winlogbeat_agent_type": "winlogbeat",
    "winlogbeat_winlog_provider_name": "Service Control Manager",
    "winlogbeat_winlog_process_pid": 1456,
    "winlogbeat_winlog_keywords": [
    "Classic"
    ]
}

```

For comparison, here is the original event in windows event viewer:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/2/32e4cbcf29f1c7920963c89e29fee8d2fbd74f24.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/c/8c953a7e37f5ac2167f591bea7ffacaa0411b0de.png)

---

<div class="post-metadata">

**Author:** ![logs4drew](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/logs4drew/32/113350_2.png) [@logs4drew](https://discuss.elastic.co/u/logs4drew)\
**Post date:** [November 23, 2022, 4:41pm UTC](https://discuss.elastic.co/t/winlogbeat-8-5-and-windows-11-22h2/318676/4 "2022-11-23T16:41:50Z")

</div>

Any update on this?

---

<div class="post-metadata">

**Author:** ![hugalafutro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hugalafutro/32/113939_2.png) [@hugalafutro](https://discuss.elastic.co/u/hugalafutro)\
**Post date:** [November 29, 2022, 1:49pm UTC](https://discuss.elastic.co/t/winlogbeat-8-5-and-windows-11-22h2/318676/5 "2022-11-29T13:49:06Z")

</div>

I am also seeing this after machines started updating to win 11 22h2, I originally reported this as an Graylog Sidecar issue at [Windows sidecar sends variables instead of data from one host. · Issue #449 · Graylog2/collector-sidecar · GitHub](https://github.com/Graylog2/collector-sidecar/issues/449)

With latest winlogbeat 8.5.2 this is an example of data I get: [PrivateBin](https://o.o5.ddns.net/8x90h)

---

<div class="post-metadata">

**Author:** ![logs4drew](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/logs4drew/32/113350_2.png) [@logs4drew](https://discuss.elastic.co/u/logs4drew)\
**Post date:** [November 29, 2022, 5:34pm UTC](https://discuss.elastic.co/t/winlogbeat-8-5-and-windows-11-22h2/318676/6 "2022-11-29T17:34:56Z")

</div>

This does appear to be an issue with Winlogbeat (although possibly caused by a change in Windows 11).

---

<div class="post-metadata">

**Author:** ![hugalafutro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hugalafutro/32/113939_2.png) [@hugalafutro](https://discuss.elastic.co/u/hugalafutro)\
**Post date:** [November 29, 2022, 5:55pm UTC](https://discuss.elastic.co/t/winlogbeat-8-5-and-windows-11-22h2/318676/7 "2022-11-29T17:55:10Z")

</div>

Most definitely related to Win11 updating to 22H2. I had 2 installs running years old winlogbeat, one of them updated to 22H2, later on I noticed this issue, but didn't make the connection. Even later I was digging more into this as I was updating the 2nd machine to 22H2 and immediately after first boot of 22H2 the issue presented itself.

---

<div class="post-metadata">

**Author:** ![logs4drew](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/logs4drew/32/113350_2.png) [@logs4drew](https://discuss.elastic.co/u/logs4drew)\
**Post date:** [December 6, 2022, 8:58pm UTC](https://discuss.elastic.co/t/winlogbeat-8-5-and-windows-11-22h2/318676/8 "2022-12-06T20:58:41Z")

</div>

I've posted an issue here [Winlogbeat sending winevt with '%' variables and not the replacement values · Issue #33966 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/33966)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2023, 10:59pm UTC](https://discuss.elastic.co/t/winlogbeat-8-5-and-windows-11-22h2/318676/9 "2023-01-03T22:59:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
