# Winlogbeat event.action for 4648

**URL:** <https://discuss.elastic.co/t/winlogbeat-event-action-for-4648/227919>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [April 14, 2020, 1:10pm UTC](https://discuss.elastic.co/t/winlogbeat-event-action-for-4648/227919 "2020-04-14T13:10:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [April 14, 2020, 1:10pm UTC](https://discuss.elastic.co/t/winlogbeat-event-action-for-4648/227919/1 "2020-04-14T13:10:51Z")

</div>

Hello,

Using the Winlogbeat 'security ' module I noticed event.code 4648 does not (yet) have an event.action defined:

```
var eventActionTypes = {
    "4624": "logged-in",
    "4625": "logon-failed",
    "4634": "logged-out",
    "4672": "logged-in-special",
    "4688": "created-process",
    "4689": "exited-process",

```

4624, 4625 and 4648

```
* 4624 - An account was successfully logged on.
* 4625 - An account failed to log on.
* 4648 - A logon was attempted using explicit credentials.

```

The result is that the 4648 events have 'Logon' as event.action.  
The resulting histogram for event.action for logon events ooks like this:

![image](https://us1.discourse-cdn.com/elastic/original/3X/5/e/5e106afea8788718fb54316957783129128565ee.png)

So what event.action should a 4648 get?

`special-logon-attempt` ?

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![MarianaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marianad/32/42687_2.png) [@MarianaD](https://discuss.elastic.co/u/MarianaD)\
**Post date:** [April 22, 2020, 2:19pm UTC](https://discuss.elastic.co/t/winlogbeat-event-action-for-4648/227919/2 "2020-04-22T14:19:10Z")

</div>

hi @willemdh, maybe `explicit-logon-attempt`?  
Also, feel free to add an enhancement issue/PR in the beats repo for a follow up.

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [April 23, 2020, 8:54am UTC](https://discuss.elastic.co/t/winlogbeat-event-action-for-4648/227919/3 "2020-04-23T08:54:23Z")

</div>

> [@MarianaD](#):
>
> explicit-logon-attempt

> <https://github.com/elastic/beats/issues/17926>
>
> \- Version: 7.6.1
> \- Operating System: Windows 2016 Server
> \- Discuss Forum URL:h…ttps://discuss.elastic.co/t/winlogbeat-event-action-for-4648/227919
> 
> Using the Winlogbeat 'security ' module I noticed event.code 4648 does not (yet) have an event.action defined:
> 
> \`\`\`
> var eventActionTypes = {
> "4624": "logged-in",
> "4625": "logon-failed",
> "4634": "logged-out",
> "4672": "logged-in-special",
> "4688": "created-process",
> "4689": "exited-process",
> \`\`\`
> 
> 4624, 4625 and 4648
> 
> \`\`\`
> \* 4624 - An account was successfully logged on.
> \* 4625 - An account failed to log on.
> \* 4648 - A logon was attempted using explicit credentials.
> \`\`\`
> 
> The result is that the 4648 events have 'Logon' as event.action.
> The resulting histogram for \`event.action\` for logon events ooks like this:
> 
> !\[image\](https://user-images.githubusercontent.com/6462991/80079528-b5ab4600-8550-11ea-829c-481fe7e41c00.png)
> 
> 
> event.action should be something like \`explicit-logon-attempt\`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 21, 2020, 8:54am UTC](https://discuss.elastic.co/t/winlogbeat-event-action-for-4648/227919/4 "2020-05-21T08:54:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
