# Winlogbeat data is not parsing properly

**URL:** <https://discuss.elastic.co/t/winlogbeat-data-is-not-parsing-properly/228820>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [April 20, 2020, 9:01am UTC](https://discuss.elastic.co/t/winlogbeat-data-is-not-parsing-properly/228820 "2020-04-20T09:01:12Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![sundar\_elk](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@sundar\_elk](https://discuss.elastic.co/u/sundar_elk)\
**Post date:** [April 20, 2020, 9:01am UTC](https://discuss.elastic.co/t/winlogbeat-data-is-not-parsing-properly/228820/1 "2020-04-20T09:01:12Z")

</div>

Hi Team,

I'm using winlogbeat for pushing all windows events to elasticsearch. Parsing is not happening properly.

1. One of the examples is under “Message” there is “Properties” which when parsed in winlog.event\_data.Properties does not show up correctly

Actual message :-1

 ![message](https://us1.discourse-cdn.com/elastic/original/3X/4/5/45652056d913a14b8bd390fcc24a2fcc31a36d29.png)

parsed field :-1

 ![parsed_event](https://us1.discourse-cdn.com/elastic/original/3X/5/6/568016e52f87b617bb0f0c5aa2846be1f3828204.png)

It should come **read property** but coming some number %%7684

Is it bug?

Thanks  
Sundar

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 21, 2020, 10:42am UTC](https://discuss.elastic.co/t/winlogbeat-data-is-not-parsing-properly/228820/2 "2020-04-21T10:42:15Z")

</div>

Can you provide the raw XML from the Windows Event Viewer for this particular event. Winlogbeat does not parse the `message` field. It unmarshals the event it gets from Windows in XML and sends it as JSON.

The conversion of [%%7684](https://github.com/elastic/beats/blob/33ff75404e27c922a7926a2c7b5dafc60aabb411/x-pack/winlogbeat/module/security/config/winlogbeat-security.js#L944) to "Read Property" is possibly something that could be handled in a module, like the Security module.

---

<div class="post-metadata">

**Author:** ![sundar\_elk](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@sundar\_elk](https://discuss.elastic.co/u/sundar_elk)\
**Post date:** [April 21, 2020, 12:39pm UTC](https://discuss.elastic.co/t/winlogbeat-data-is-not-parsing-properly/228820/3 "2020-04-21T12:39:24Z")

</div>

@andrewkroh, Your right . I have checked my XML and it coming as **%%7682**. It looks like issue from our windows event. Thanks a lot for your reply. We can close this thread.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 22, 2020, 1:12am UTC](https://discuss.elastic.co/t/winlogbeat-data-is-not-parsing-properly/228820/4 "2020-04-22T01:12:44Z")

</div>

What was the event ID? It's probably something we can enrich in the Security module. Like do a conversion in the winlog.event\_data field.

---

<div class="post-metadata">

**Author:** ![sundar\_elk](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@sundar\_elk](https://discuss.elastic.co/u/sundar_elk)\
**Post date:** [April 22, 2020, 4:45am UTC](https://discuss.elastic.co/t/winlogbeat-data-is-not-parsing-properly/228820/5 "2020-04-22T04:45:27Z")

</div>

event id is 4662. Below are screenshots. Not only 4662 and other security events also.

General view :-

 ![message_4662](https://us1.discourse-cdn.com/elastic/original/3X/f/c/fc7392f96caee5bfcc3b9b2ea31a68ccc874cf0e.png)  
XML view :-  
 ![winlog_event_4662](https://us1.discourse-cdn.com/elastic/original/3X/d/f/df508d6534421dd49960ab4d1acc8f01e4cb56c5.png)

I'm not sure why properties field is different from general view and XML view. Our windows team also looking into this. will get back to you soon once i get the update from windows team.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 23, 2020, 10:23pm UTC](https://discuss.elastic.co/t/winlogbeat-data-is-not-parsing-properly/228820/6 "2020-04-23T22:23:04Z")

</div>

Event ID 4662 isn't yet handled in the Security module. The module does have a translation table for those codes. The module needs enhanced to map the fields in 4662 over to ECS.

> <https://github.com/elastic/beats/blob/86c59c09bc8fc6f6f36ff111624356b1cfec3102/x-pack/winlogbeat/module/security/config/winlogbeat-security.js#L942>

> <https://github.com/elastic/beats/issues/16334>
>
> Microsoft has a recommend list of event IDs to monitor. We want ensure we have coverage of each of these events...

---

<div class="post-metadata">

**Author:** ![sundar\_elk](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@sundar\_elk](https://discuss.elastic.co/u/sundar_elk)\
**Post date:** [April 26, 2020, 5:24am UTC](https://discuss.elastic.co/t/winlogbeat-data-is-not-parsing-properly/228820/7 "2020-04-26T05:24:59Z")

</div>

Thanks for your information, Can you please let me know how many events are completed with ECS format for all fields and what are the other event ID's are pending for ECS? if we get details we can parse the data via logstash. No need to wait for another release for this.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 7, 2020, 1:43pm UTC](https://discuss.elastic.co/t/winlogbeat-data-is-not-parsing-properly/228820/8 "2020-05-07T13:43:32Z")

</div>

This information about what event IDs are mapped in each module is contained in the documentation. Choose your Winlogbeat version in the docs. Additionally the source for each module is in Github and you can see the mapping logic.

- [https://www.elastic.co/guide/en/beats/winlogbeat/7.8/winlogbeat-module-security.html](https://www.elastic.co/guide/en/beats/winlogbeat/7.8/winlogbeat-module-security.html)
- [https://github.com/elastic/beats/blob/7.8/x-pack/winlogbeat/module/security/config/winlogbeat-security.js#L1979-L2205](https://github.com/elastic/beats/blob/7.8/x-pack/winlogbeat/module/security/config/winlogbeat-security.js#L1979-L2205)
- [https://github.com/elastic/beats/blob/7.8/x-pack/winlogbeat/module/sysmon/config/winlogbeat-sysmon.js#L1417-L1439](https://github.com/elastic/beats/blob/7.8/x-pack/winlogbeat/module/sysmon/config/winlogbeat-sysmon.js#L1417-L1439)

---

<div class="post-metadata">

**Author:** ![sundar\_elk](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@sundar\_elk](https://discuss.elastic.co/u/sundar_elk)\
**Post date:** [May 10, 2020, 7:03am UTC](https://discuss.elastic.co/t/winlogbeat-data-is-not-parsing-properly/228820/9 "2020-05-10T07:03:17Z")

</div>

thank you for detailed information.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2020, 7:10am UTC](https://discuss.elastic.co/t/winlogbeat-data-is-not-parsing-properly/228820/10 "2020-06-07T07:10:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
