# Winlogbeat event.type has 0 records

**URL:** <https://discuss.elastic.co/t/winlogbeat-event-type-has-0-records/220920>\
**Category:** Beats\
**Created:** [February 25, 2020, 8:59pm UTC](https://discuss.elastic.co/t/winlogbeat-event-type-has-0-records/220920 "2020-02-25T20:59:02Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![SeekAndDestroy](https://avatars.discourse-cdn.com/v4/letter/s/2acd7d/32.png) [@SeekAndDestroy](https://discuss.elastic.co/u/SeekAndDestroy)\
**Post date:** [February 25, 2020, 8:59pm UTC](https://discuss.elastic.co/t/winlogbeat-event-type-has-0-records/220920/1 "2020-02-25T20:59:02Z")

</div>

I'm trying to get familiar with the SIEM. When I look at "Authentications" in the Hosts section, it is empty. If I look at the request, it appears to be looking for event.type:

"aggregations": {  
"eventActionGroup": {  
"terms": {  
"field": "event.type",  
"include": [  
"authentication\_success",  
"authentication\_failure"  
],

However, I have 0 records containing that field when I search my Winlogbeat indices for event.type in the Discover tab.

I just recently upgraded Winlogbeats from 7.3.0 to 7.6.0. When I look at the mappings for 7.6.0, the field is defined (It is also defined in previous 7.3.0 indices as well).

Am I missing something? Is there something else I need to do to get this field logged other than the default mappings used in Winlogbeat? For example, logging specifically required events...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2020, 10:59pm UTC](https://discuss.elastic.co/t/winlogbeat-event-type-has-0-records/220920/2 "2020-03-24T22:59:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
