# Winlogbeat does not properly handle CN's with comma(s) in name

**URL:** <https://discuss.elastic.co/t/winlogbeat-does-not-properly-handle-cns-with-comma-s-in-name/264362>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [February 15, 2021, 9:15pm UTC](https://discuss.elastic.co/t/winlogbeat-does-not-properly-handle-cns-with-comma-s-in-name/264362 "2021-02-15T21:15:10Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [February 15, 2021, 9:15pm UTC](https://discuss.elastic.co/t/winlogbeat-does-not-properly-handle-cns-with-comma-s-in-name/264362/1 "2021-02-15T21:15:10Z")

</div>

Hi All,

I was looking at some Winlogbeat events, and I noticed that it doesn't seem to be properly handling CN's with comma(s) in them.

Example (backslashes present to show escapes):

Have a user like so: `Admin\\, user`

For the related.users field I would expect to see:

```auto
"related": {
    "user": [
      "Admin\\, user"
    ]
  }

```

Instead what I see is:

```auto
"related": {
    "user": [
      "user",
      "Admin\\"
    ]
  }

```

I'm using Winlogbeat 7.10.0 currently, but didn't see any patch notes from the later releases regarding this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 15, 2021, 11:15pm UTC](https://discuss.elastic.co/t/winlogbeat-does-not-properly-handle-cns-with-comma-s-in-name/264362/2 "2021-03-15T23:15:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
