# Winlogbeat drop\_fields not working

**URL:** <https://discuss.elastic.co/t/winlogbeat-drop-fields-not-working/275129>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [June 7, 2021, 9:58am UTC](https://discuss.elastic.co/t/winlogbeat-drop-fields-not-working/275129 "2021-06-07T09:58:10Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Billz1026](https://avatars.discourse-cdn.com/v4/letter/b/67e7ee/32.png) [@Billz1026](https://discuss.elastic.co/u/Billz1026)\
**Post date:** [June 7, 2021, 9:58am UTC](https://discuss.elastic.co/t/winlogbeat-drop-fields-not-working/275129/1 "2021-06-07T09:58:10Z")

</div>

Hi All,

I have configured Winlogbeat to drop some fields from all the events using below configuration. But it seems the "drop\_fields" process is not applying to the events since I can see those fields in the Kibana. Can someone plese tell me what went wrong with the config. (Drop\_event proceesses are working fine though)

```
- name: ForwardedEvents
 tags: [forwarded]
 processors:
  - drop_event:
      when.and:
        - equals.winlog.event_data.EnabledPrivilegeList: "-"
        - equals.winlog.event_id: 4703
  - drop_event:
      when.and:
        - equals.winlog.event_id: 4703
        - regexp.winlog.event_data.TargetUserName: ".*$"
  - drop_fields:
      fields: ["agent.id", "agent.ephemeral_id", "agent.hostname", "ecs.version", "host.id", "host.os.type", "winlog.api", "event.kind"]
      ignore_missing: true 
  - script:
      when.equals.winlog.channel: Security
      lang: javascript
      id: security
      file: ${path.home}/module/security/config/winlogbeat-security.js
  - script:
      when.equals.winlog.channel: Microsoft-Windows-Sysmon/Operational
      lang: javascript
      id: sysmon
      file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js
  - script:
      when.equals.winlog.channel: Windows PowerShell
      lang: javascript
      id: powershell
      file: ${path.home}/module/powershell/config/winlogbeat-powershell.js
  - script:
      when.equals.winlog.channel: Microsoft-Windows-PowerShell/Operational
      lang: javascript
      id: powershell
      file: ${path.home}/module/powershell/config/winlogbeat-powershell.js 

```

BR,  
Someunguy1026

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [June 7, 2021, 10:42am UTC](https://discuss.elastic.co/t/winlogbeat-drop-fields-not-working/275129/2 "2021-06-07T10:42:27Z")

</div>

Could you please temporarly comment out all processors from your configuration (both global and local) and run Winlogbeat in debug mode (`winlogbeat -e -d "*"`) and share its output?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 7, 2021, 11:30am UTC](https://discuss.elastic.co/t/winlogbeat-drop-fields-not-working/275129/3 "2021-06-07T11:30:41Z")

</div>

> [@Billz1026](#):
>
> `equals.winlog.event_id: 4703`

I think `winlog.event_id` is a string in the event so your data type in the condition needs to match. Add some quotes around the value like `equals.winlog.event_id: "123"`

In `regexp.winlog.event_data.TargetUserName: ".*$"`, this regex matches everything. I think you want `'\$$'` to match things that end in `$`.

---

<div class="post-metadata">

**Author:** ![Billz1026](https://avatars.discourse-cdn.com/v4/letter/b/67e7ee/32.png) [@Billz1026](https://discuss.elastic.co/u/Billz1026)\
**Post date:** [June 7, 2021, 4:32pm UTC](https://discuss.elastic.co/t/winlogbeat-drop-fields-not-working/275129/4 "2021-06-07T16:32:39Z")

</div>

Hi Andrewkroh.

Thanks for the advice and suggested regex worked fine.  
But my main problem is with "drop\_fields" process. It does not drop required fields mentioned in the process.

BR,  
Someunguy1026

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 7, 2021, 5:42pm UTC](https://discuss.elastic.co/t/winlogbeat-drop-fields-not-working/275129/5 "2021-06-07T17:42:20Z")

</div>

I think the issue with `drop_fields` is the order in which they applied. `agent`, `ecs`, and `host` are all added after this group of processors is run. And `event.kind` is added by the script processors. The `winlog.api` should be working since that is added as soon as the event is produced.

So I think if you move this to the global [processors](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-general-options.html#_processors) list then it will work (as opposed to the the event log specific processors).

---

<div class="post-metadata">

**Author:** ![Billz1026](https://avatars.discourse-cdn.com/v4/letter/b/67e7ee/32.png) [@Billz1026](https://discuss.elastic.co/u/Billz1026)\
**Post date:** [June 7, 2021, 6:20pm UTC](https://discuss.elastic.co/t/winlogbeat-drop-fields-not-working/275129/6 "2021-06-07T18:20:48Z")

</div>

Hi Andrew,

Yes, moving to global processors solved the issue.

As you mentioned, some fields cannot be deleted using local processors. Once I utilized the global processors, i could drop all the fields i wanted.

Thank you.

BR,  
Someunguy1026

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2021, 8:21pm UTC](https://discuss.elastic.co/t/winlogbeat-drop-fields-not-working/275129/7 "2021-07-05T20:21:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
