# Winlogbeat New ECS Fields and security module questions

**URL:** <https://discuss.elastic.co/t/winlogbeat-new-ecs-fields-and-security-module-questions/190479>\
**Category:** Beats\
**Tags:** ecs-elastic-common-schema, winlogbeat\
**Created:** [July 15, 2019, 9:41am UTC](https://discuss.elastic.co/t/winlogbeat-new-ecs-fields-and-security-module-questions/190479 "2019-07-15T09:41:45Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [August 8, 2019, 3:58pm UTC](https://discuss.elastic.co/t/winlogbeat-new-ecs-fields-and-security-module-questions/190479/6 "2019-08-08T15:58:12Z")

</div>

Hi Andrew,  
I have been reading the modifications in the winlogbeat-security.js and I have a comment when populating the logon.id

```
var addLogonIds = function(evt) {
    var id = evt.Get("winlog.event_data.SubjectLogonId");
    if (id) {
        evt.AppendTo("winlog.logon.id", id);
    }
    id = evt.Get("winlog.event_data.TargetLogonId");
    if (id) {
        evt.AppendTo("winlog.logon.id", id);
    }
};

```

There are events, like 4624 that has both winlog.event\_data.SubjectLogonId and winlog.event\_data.TargetLogonId.  
In this case as winlog.event\_data.TargetLogonId is the last one assigned to winlog.logon.id so it has the proper information; but I do not know if there are others events in which this approach may not work

Regards  
Ana

---

_[View the full topic](https://discuss.elastic.co/t/winlogbeat-new-ecs-fields-and-security-module-questions/190479)._
