# Winlogbeat dashboard incomplete/missing fields

**URL:** <https://discuss.elastic.co/t/winlogbeat-dashboard-incomplete-missing-fields/256375>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [November 23, 2020, 3:22pm UTC](https://discuss.elastic.co/t/winlogbeat-dashboard-incomplete-missing-fields/256375 "2020-11-23T15:22:59Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![bohm](https://avatars.discourse-cdn.com/v4/letter/b/59ef9b/32.png) [@bohm](https://discuss.elastic.co/u/bohm)\
**Post date:** [November 23, 2020, 3:22pm UTC](https://discuss.elastic.co/t/winlogbeat-dashboard-incomplete-missing-fields/256375/1 "2020-11-23T15:22:59Z")

</div>

Hello,

Winlogbeat and ELK 7.10.0

Trying to show a college of mine that visualisation is much easier with Kibana then Splunk, I'm trying to build a use case with Active Directory security logging. But is looks like somewhere in the process I'm doing thing wrong or it is simply not working as expected.  
I'm trying to import a evtx file into an ELK stack running on a Linux server. This exported file has been copied to a Windows10 desktop in order to have it ingested via Winlogbeat.

- Import index into Elasticsearch template via:  
win10\> .\winlogbeat.exe export template --es.version 7.10.0 | Out-File -Encoding UTF8 winlogbeat.template.json  
lx\> curl -XPUT -H 'Content-Type: application/json' [http://localhost:9200/\_template/winlogbeat-7.10.0](http://localhost:9200/_template/winlogbeat-7.10.0) -d@winlogbeat.template.json

- Import the dashboards:  
win10\> .\winlogbeat.exe setup --dashboards

- import the evtx file via Logstash beats:  
win10\> .\winlogbeat.exe -e -c .\winlogbeat-evtx.yml -E EVTX\_FILE=Security.evtx

There is data to explore, but it looks like there are fields missing even though I'me sure the eventid's are present an should be processed by winlogbeat-security.js

 ![Screenshot 2020-11-23 at 16.11.12](https://us1.discourse-cdn.com/elastic/original/3X/b/9/b9ba12f4b80155b619d9df145357e3f0ec183916.png)

Any idea's?

Kind regards,  
Andre

---

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [November 23, 2020, 5:37pm UTC](https://discuss.elastic.co/t/winlogbeat-dashboard-incomplete-missing-fields/256375/2 "2020-11-23T17:37:06Z")

</div>

Hi,  
Could you check your mappings and share it here?  
Usually when you can't use aggregation on a field is because the field type isn't `keyword`.  
So check your data mapping and make sure it's using the correct template and mapping.

---

<div class="post-metadata">

**Author:** ![bohm](https://avatars.discourse-cdn.com/v4/letter/b/59ef9b/32.png) [@bohm](https://discuss.elastic.co/u/bohm)\
**Post date:** [November 23, 2020, 5:48pm UTC](https://discuss.elastic.co/t/winlogbeat-dashboard-incomplete-missing-fields/256375/3 "2020-11-23T17:48:41Z")

</div>

Hi,  
Attached is the mapping from the index winlogbeat.  
This is a fresh empty ELK single node Linux system, so how could it end up using a wrong template?  
Thanks for your time!  
Andre  
PS: not able to attach files? Post is limited by number of characters

[https://pastebin.pl/view/30d359c1](https://pastebin.pl/view/30d359c1)

---

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [November 24, 2020, 1:10pm UTC](https://discuss.elastic.co/t/winlogbeat-dashboard-incomplete-missing-fields/256375/4 "2020-11-24T13:10:26Z")

</div>

Take a look at lines 88-95. Your `event.action` main type is `text` with a `keyword` subtype.  
As you know, You can't use aggregation on `text` fields.  
Could you share your index template too? because I'm guessing your template mappings is correct and for some reason, your index isn't using your template.

---

<div class="post-metadata">

**Author:** ![bohm](https://avatars.discourse-cdn.com/v4/letter/b/59ef9b/32.png) [@bohm](https://discuss.elastic.co/u/bohm)\
**Post date:** [November 24, 2020, 1:31pm UTC](https://discuss.elastic.co/t/winlogbeat-dashboard-incomplete-missing-fields/256375/5 "2020-11-24T13:31:25Z")

</div>

Sorry, I don't know. 😉 It is a fresh installation following all the instructions found on the elastic website and that is causing problems because I missed a step or did something wrong? I did not create a dashboard or mapping or template by myself.

---

<div class="post-metadata">

**Author:** ![bohm](https://avatars.discourse-cdn.com/v4/letter/b/59ef9b/32.png) [@bohm](https://discuss.elastic.co/u/bohm)\
**Post date:** [November 24, 2020, 1:40pm UTC](https://discuss.elastic.co/t/winlogbeat-dashboard-incomplete-missing-fields/256375/6 "2020-11-24T13:40:40Z")

</div>

Oke, when having a look via Index Management I have an indice winlogbeat-2020-11-18, Looking at Index Templates I see a Legacy index template winlogbeat-7.10.0 which will be applied on index pattern winlogbeat-7.10.0-\* . So guess you are absolutely right about not using the template. Question is where to correct this.  
Should I correct this in the Logstash config?:  
output{  
elasticsearch {  
hosts =\> ["[http://127.0.0.1:9200](http://127.0.0.1:9200)"]  
index =\> "%{[@metadata][beat]}-%{+YYYY-MM-dd}"  
}

---

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [November 24, 2020, 2:43pm UTC](https://discuss.elastic.co/t/winlogbeat-dashboard-incomplete-missing-fields/256375/7 "2020-11-24T14:43:50Z")

</div>

Glad you could find the problem!

> [@bohm](#):
>
> Question is where to correct this.

You have two option:

1. Change the index pattern in your template to match the name of your indices.

2. Change your index name in Logstash/beats configurations to match your index template pattern.

I recommend the second option.

---

<div class="post-metadata">

**Author:** ![bohm](https://avatars.discourse-cdn.com/v4/letter/b/59ef9b/32.png) [@bohm](https://discuss.elastic.co/u/bohm)\
**Post date:** [November 24, 2020, 3:38pm UTC](https://discuss.elastic.co/t/winlogbeat-dashboard-incomplete-missing-fields/256375/8 "2020-11-24T15:38:46Z")

</div>

Changed Logstash.conf:  
input{  
beats{  
port =\> "5044"  
}  
}  
output{  
elasticsearch {  
hosts =\> ["[http://127.0.0.1:9200](http://127.0.0.1:9200)"]  
index =\> "%{[@metadata][beat]}-7.10.0-%{+YYYY-MM-dd}"  
# index =\> "%{[@metadata][beat]}-%{+YYYY-MM-dd}"  
}  
}

Removed al previous data and started all over again.  
Dashboards are now definitively looking beter, thanks, but still missing something :  
Could not locate that index-pattern-field (id: [winlog.logon.id](http://winlog.logon.id/))  
Trying to find out what's/why still missing, will let you know or maybe you already have a hint where to look for.

---

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [November 25, 2020, 11:10am UTC](https://discuss.elastic.co/t/winlogbeat-dashboard-incomplete-missing-fields/256375/9 "2020-11-25T11:10:10Z")

</div>

Sorry, I'm not experienced with logstash. hopefully, someone from elastic would help you.

---

<div class="post-metadata">

**Author:** ![bohm](https://avatars.discourse-cdn.com/v4/letter/b/59ef9b/32.png) [@bohm](https://discuss.elastic.co/u/bohm)\
**Post date:** [November 25, 2020, 11:25am UTC](https://discuss.elastic.co/t/winlogbeat-dashboard-incomplete-missing-fields/256375/10 "2020-11-25T11:25:01Z")

</div>

Thanks for your time and pointing out in the right direction!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 23, 2020, 1:25pm UTC](https://discuss.elastic.co/t/winlogbeat-dashboard-incomplete-missing-fields/256375/11 "2020-12-23T13:25:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
