We save the windows XP event log to elasticsearch by winlogbeat.
But we find there is no field of event_data.Binary in elasticsearch.
For win7 system we can get a field:"event_data.Binary XXXXXXXXXXXXXX".
Is there any config issue?
here is the XP event log:
The Bytes data can not show on kinana: