# Winlogbeat - no winlog.logon.id

**URL:** <https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [June 10, 2020, 2:29pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524 "2020-06-10T14:29:17Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![mgotechlock](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Post date:** [June 10, 2020, 2:29pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/1 "2020-06-10T14:29:18Z")

</div>

The winlogbeat 7.7.1 dashboards reference winlog.logon.id.These two threads also mention it and imply it should be in versions \> 7.4.  
[https://discuss.elastic.co/search?q=winlog.logon.id](https://discuss.elastic.co/search?q=winlog.logon.id)  
However, I am running 7.6.2 and 7.7.1 and am not seeing that field in any log, across 100's of machines. My config is pretty basic, basically this:

```
winlogbeat.event_logs: 
  - name: Application 
    ignore_older: 72h 
  
  - name: System 
  
  - name: Security 
    processors: 
      - script: 
          lang: javascript 
          id: security 
          file: ${path.home}/module/security/config/winlogbeat-security.js 
  
  - name: Microsoft-Windows-Sysmon/Operational 
    processors: 
      - script: 
          lang: javascript 
          id: sysmon 
          file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js 
  
#==================== Elasticsearch template settings ==========================  
  
setup.template.settings: 
  index.number_of_shards: 1 
  
#================================ Outputs =====================================  
  
#----------------------------- Logstash output -------------------------------- 
output.logstash: 
  # The Logstash hosts 
  hosts: ["localhost:5044"] 
  
#================================ Processors ===================================== 
  
# Configure processors to enhance or manipulate events generated by the beat. 
  
processors: 
  - add_host_metadata: ~ 
  - add_cloud_metadata: ~ 
  - add_docker_metadata: ~ 

```

So where is winlog.logon.id? Is that field currently populated by winlogbeat or not? If so, where is the discrepancy?

---

<div class="post-metadata">

**Author:** ![mgotechlock](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Post date:** [June 10, 2020, 2:51pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/2 "2020-06-10T14:51:07Z")

</div>

I think I now understand how the ${path.home}/module/security/config/winlogbeat-security.js integration works. I think I still have an issue though. Event code 4634, says it is covered by winlogbeat-security.js, but those events are not showing a winlog.logon.id but are showing things like user.name so I believe they are being processed.  
The convert looks like {from: "winlog.event\_data.TargetLogonId", to: "winlog.logon.id"},  
and I have values in kibana for winlog.event.\_data.TargetLogonId, so it seems like I should have winlog.logon.id as well (or instead), but I dont.

---

<div class="post-metadata">

**Author:** ![minorsatellite](https://avatars.discourse-cdn.com/v4/letter/m/f05b48/32.png) [@minorsatellite](https://discuss.elastic.co/u/minorsatellite)\
**Post date:** [July 1, 2020, 8:37pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/3 "2020-07-01T20:37:17Z")

</div>

Did you ever find a solution for this issue? Prebuilt visualizations using the Security Module error out for me with the following error: " [Could not locate that index-pattern-field (id: winlog.login.id)]" Its very frustrating to say the least.

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [July 11, 2020, 10:38pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/4 "2020-07-11T22:38:47Z")

</div>

I've now stumbled over this discuss entry here.  
So I did a short test with versions 7.7.0, 7.7.1 and 7.8.0 started as a service or started from command line with outputs directly to elasticsearch and through logstash.  
In every case I've seen values.  
Let's first check if entries are existing which should filter out path `winlog.logon`:

```auto
GET winlogbeat-*/_search?filter_path=hits.hits._source.winlog.logon,hits.total.value
{
  "query": {
    "match_phrase": {
      "event.code": "4634"
    }
  }
}

```

I checked Windows 10. What exact OS are you using?

Do you maybe use WEC (Windows Event Collector)?  
So my question is if you can give a bit more metadata around this topic.

And finally I can see the events in the Dashboard as well `[Winlogbeat] Overview`.

---

<div class="post-metadata">

**Author:** ![minorsatellite](https://avatars.discourse-cdn.com/v4/letter/m/f05b48/32.png) [@minorsatellite](https://discuss.elastic.co/u/minorsatellite)\
**Post date:** [July 12, 2020, 12:21am UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/5 "2020-07-12T00:21:56Z")

</div>

> [@Andre\_Letterer](#):
>
> ```auto
> GET winlogbeat-*/_search?filter_path=hits.hits._source.winlog.logon,hits.total.value
> {
> "query": {
> "match_phrase": {
> "event.code": "4634"
> }
> }
> }
> 
> ```

Hello Andre-

My pipeline is the same as yours, I believe: Winlogbeat--\>Filebeat--\>Logstash

When I run the same query as yours I get back a very different result:

```
{
   "hits" : {
      "total" : {
         "value" : 0
        }
    }
}

```

I am running Server 2016. Output from Winlogbeat Overview Dashboard looks good (see attached). I have not explicitly configured Windows Event Collector and if its functional its using default settings. According to the Services MMC WEC it is active and running.

I have also observed that events that should show up in certain visualizations are not. For instance, if I create and then delete a user, those actions do not show up in the appropriate visualizations.

 ![Screen Shot 2020-07-11 at 5.13.26 PM](https://us1.discourse-cdn.com/elastic/original/3X/6/2/62a217caf8bf09a287ee833b555c3d43702c2610.png)

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [July 12, 2020, 1:24pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/6 "2020-07-12T13:24:01Z")

</div>

Ok, the event type id 4634 we were talking about was logging off messages of a particular user

> **[4634(S) An account was logged off. (Windows 10) - Windows security](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4634)**
>
> Describes security event 4634(S) An account was logged off.

  
and like you can see this one is documented to be  
[https://www.elastic.co/guide/en/beats/winlogbeat/master/winlogbeat-module-security.html](https://www.elastic.co/guide/en/beats/winlogbeat/master/winlogbeat-module-security.html)

Now Deleting a certain user should be events 4720 and 4726 which at least should come up:

> **[4720(S) A user account was created. (Windows 10) - Windows security](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4720)**
>
> Describes security event 4720(S) A user account was created.

> **[4726(S) A user account was deleted. (Windows 10) - Windows security](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4726)**
>
> Describes security event 4726(S) A user account was deleted.

But I would like to come back to your architectural answer. I understand we are talking about a server where you host winlogbeat is not the one you are interested in to see the events, as you are talking about WEC.

If I understand you correctly you have at least 2 computers in place:

```auto
unknown server or workstation with configured WEF (Windows Event Forwarder)
-->
Windows Server 2016 with configured WEC (Windows Event Collector) and hosting Winlogbeat
events are in services.msc in Folder ForwardedEvents
-->
Logstash
-->
Elasticsearch

```

This is how I understand your architecture. When you are in ForwardedEvents in services.msc on your WEC Windows2016 Server can you filter for events 4720, 4726 or 4634?

---

<div class="post-metadata">

**Author:** ![minorsatellite](https://avatars.discourse-cdn.com/v4/letter/m/f05b48/32.png) [@minorsatellite](https://discuss.elastic.co/u/minorsatellite)\
**Post date:** [July 13, 2020, 11:09pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/7 "2020-07-13T23:09:17Z")

</div>

Hello Andre, confirmed, neither creating or deleting user accounts were appearing. It's entirely possible that I have my environment setup incorrectly since I am new to ES. I am going to revert to the simplest config possible and ship everything from Beats directly to ES (and leave out Logstash) and see if I can get it to behave more predictably. Currently Filebeat is processing output for the Filebeat System module, Fortinet and Winlogbeat and all is being written to a single index. Is that even a recommended approach?

---

<div class="post-metadata">

**Author:** ![mgotechlock](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Post date:** [July 16, 2020, 7:28pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/8 "2020-07-16T19:28:48Z")

</div>

I just checked again. We only use winlogbeat, no WEC. I see event.code:4634 with no corresponding winlog.login.id for

- Windows Server 2008 R2 Standard
- Windows 10 Pro (10.0.18362.900 (WinBuild.160101.0800)) / 10.0.18362.778 (WinBuild.160101.0800), 10.0.18362.904 (WinBuild.160101.0800),
- Windows Server 2019 Standard
- Windows Server 2012 Standard

Are you saying you see winlog.login.id fields?

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [July 16, 2020, 9:31pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/9 "2020-07-16T21:31:51Z")

</div>

@minorsatellite  
I wouldn't feed winlogbeat data into filebeat indices.  
[https://www.elastic.co/guide/en/beats/winlogbeat/current/elasticsearch-output.html#index-option-es](https://www.elastic.co/guide/en/beats/winlogbeat/current/elasticsearch-output.html#index-option-es)  
default for `index` are winlogbeat indices `winlogbeat-%{[agent.version]}-%{+yyyy.MM.dd}` so I assume you went away from default index which means, if you output to filebeat, there are existing ingest pipelines that match this particular index and I have never tested what happens in this case. Would you mind doing what you said going back to the default output elasticsearch settings?

What do you get if you feed into winlogbeat indices and check after some time if you then find data?  
`GET winlogbeat-*/_search?size=2000&filter_path=hits.hits._source.winlog.logon,hits.total.value`

@mgotechlock  
Yes I am seeing these fields in logon section:  
`GET winlogbeat-*/_search?size=2000&filter_path=hits.hits._source.winlog.logon,hits.total.value`  
Do you see the id field for other resultsets?  
Please keep in mind that these fields have the name `winlog.logon` not `login`, because in last comment you mentioned login.id, but it's logon.id  
[https://www.elastic.co/guide/en/beats/winlogbeat/current/exported-fields-security.html](https://www.elastic.co/guide/en/beats/winlogbeat/current/exported-fields-security.html)  
Here the example resultset:

```auto
{
  "hits" : {
    "total" : {
      "value" : 10000
    },
    "hits" : [
      {
        "_source" : {
          "winlog" : {
            "logon" : {
              "id" : "0x3e7",
              "type" : "Service"
            }
          }
        }
      },
      {
        "_source" : {
          "winlog" : {
            "logon" : {
              "id" : "0x3e7"
            }
          }
        }
      },
      {
        "_source" : {
          "winlog" : {
            "logon" : {
              "id" : "0x3e7",
              "type" : "Service"
            }
          }
        }
      },
      {
        "_source" : {
          "winlog" : {
            "logon" : {
              "id" : "0x3e7"
            }
          }
        }
      },
      {
        "_source" : {
          "winlog" : {
            "logon" : {
              "id" : "0x3e7",
              "type" : "Service"
            }
          }
        }
      },
      {
        "_source" : {
          "winlog" : {
            "logon" : {
              "id" : "0x3e7"
            }
          }
        }
      },
      {
        "_source" : {
          "winlog" : {
            "logon" : {
              "id" : "0x3e7",
              "type" : "Service"
            }
          }
        }
      },
...

```

---

<div class="post-metadata">

**Author:** ![mgotechlock](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Post date:** [July 17, 2020, 1:22pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/10 "2020-07-17T13:22:50Z")

</div>

So my issue is not an issue after all. Turns out, unbeknownst to me, someone filtered out some events so they never make it to Elastic and Kibana cant see them.

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [July 17, 2020, 8:59pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/11 "2020-07-17T20:59:05Z")

</div>

Ok so issue of @mgotechlock is solved I assume.

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [July 17, 2020, 8:59pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/12 "2020-07-17T20:59:45Z")

</div>

@minorsatellite  
What about you? Any news here?

---

<div class="post-metadata">

**Author:** ![minorsatellite](https://avatars.discourse-cdn.com/v4/letter/m/f05b48/32.png) [@minorsatellite](https://discuss.elastic.co/u/minorsatellite)\
**Post date:** [July 17, 2020, 9:12pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/13 "2020-07-17T21:12:16Z")

</div>

I reached out to you on Slack Channel to say that the situation is as before, still receiving the error:  
`Could not locate that index-pattern-field (id: [winlog.logon.id](http://winlog.logon.id/))`

---

<div class="post-metadata">

**Author:** ![minorsatellite](https://avatars.discourse-cdn.com/v4/letter/m/f05b48/32.png) [@minorsatellite](https://discuss.elastic.co/u/minorsatellite)\
**Post date:** [July 17, 2020, 11:13pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/14 "2020-07-17T23:13:10Z")

</div>

I am actually outputting to a separate Winlogbeat index, if that is what you are asking.

```
GET winlogbeat-*/_search?size=2000&filter_path=hits.hits._source.winlog.logon,hits.total.value

{
  "hits" : {
    "total" : {
      "value" : 10000
    }
  }
}

```

Here is the Logstash pipeline I am using:

```
input {
        beats {
                port => 5044
        }
}
filter {
        if [type] == "syslog" {
                grok {
                        match => { "message" => "%{SYSLOGLINE}" }
                }
                date {
                        match => ["timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
                }
        }
}
output {

        if [event][module] == "fortinet" {
                elasticsearch {
                #ssl => true
                #ssl_certificate_verification => true
                #cacert => ["elastic\ca.crt"]
                hosts => ["10.101.10.25:9200"]
                #user => "${ES_USR}"
                #password => "${ES_PWD}"
                manage_template => false
                ilm_rollover_alias => "filebeat-7.8.0-fortinet"
                ilm_policy => "filebeat-fortinet"
                ilm_pattern => "{now/d}-000001"
                pipeline => "%{[@metadata][pipeline]}"
        }

        # stdout {
        # codec => json
        # }
        }
        else {
                elasticsearch {
                hosts => ["10.101.10.25:9200"]
                #user => some_user
                #password => some_password
                manage_template => false
                index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
                }
            }

}

```

In the winlogbeat-security.js file, there are numerous field renaming (conversion) actions taking place, in the form of:

{from: "winlog.event\_data.SubjectLogonId", to: "winlog.logon.id"},

Are these correct, and if so, what should be happening? Are any modifications required here to remedy the errors?

---

<div class="post-metadata">

**Author:** ![minorsatellite](https://avatars.discourse-cdn.com/v4/letter/m/f05b48/32.png) [@minorsatellite](https://discuss.elastic.co/u/minorsatellite)\
**Post date:** [July 18, 2020, 6:01pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/15 "2020-07-18T18:01:36Z")

</div>

unknown server or workstation with configured WEF (Windows Event Forwarder)  
--\>  
Windows Server 2016 with configured WEC (Windows Event Collector) and hosting Winlogbeat  
events are in services.msc in Folder ForwardedEvents  
--\>  
Logstash  
--\>  
Elasticsearch

Not exactly, I have 2 Winlogbeat servers are shipping their logs to a single node ES cluster, outputting first to Filebeat, then Logstash, then to ES. Again, I aim not too sure about WEC configuration, and WEF is configured in my YAML file.

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [July 18, 2020, 7:30pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/16 "2020-07-18T19:30:08Z")

</div>

I think the main question is if your `winlogbeat.yml` is configured to care about the ForwardedEvents Folder In Event Log and the underlying js fields:

It should be something like this

```auto
....

 - name: Security
    processors:
      - script:
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js

  - name: Microsoft-Windows-Sysmon/Operational
    processors:
      - script:
          lang: javascript
          id: sysmon
          file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js

###beginning###
  - name: ForwardedEvents
    tags: [forwarded]
    processors:
      - script:
          when.equals.winlog.channel: Security
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js
      - script:
          when.equals.winlog.channel: Microsoft-Windows-Sysmon/Operational
          lang: javascript
          id: sysmon
          file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js
 ###end###

```

Let me know how it goes.

---

<div class="post-metadata">

**Author:** ![minorsatellite](https://avatars.discourse-cdn.com/v4/letter/m/f05b48/32.png) [@minorsatellite](https://discuss.elastic.co/u/minorsatellite)\
**Post date:** [July 20, 2020, 12:32am UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/17 "2020-07-20T00:32:05Z")

</div>

Actually, the main question is why is winlog.login.id field missing from my index pattern 🙂

Comparing my YAML file to your code snippet, they look exactly the same.

---

<div class="post-metadata">

**Author:** ![minorsatellite](https://avatars.discourse-cdn.com/v4/letter/m/f05b48/32.png) [@minorsatellite](https://discuss.elastic.co/u/minorsatellite)\
**Post date:** [July 20, 2020, 9:55pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/18 "2020-07-20T21:55:15Z")

</div>

Guess this is turning out to be a bug with the WLB code.

> <https://github.com/elastic/beats/pull/15236/commits/d0b005b7c4131cd881424d9a0373bfdef578417c#r457018303>

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [July 21, 2020, 8:38am UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/19 "2020-07-21T08:38:25Z")

</div>

Ok, great find. But the question that is still open for me is, do you have only an issue with the field missing in the dashboard or do you have the situation as well that you don’t have any content in `winlog.logon.id` field?

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [July 21, 2020, 11:37pm UTC](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524/20 "2020-07-21T23:37:55Z")

</div>

Ok,  
@minorsatellite  
if I understand correctly and looking to slack it seems that everything is working for you now?

[Next page](https://discuss.elastic.co/t/winlogbeat-no-winlog-logon-id/236524.md?page=2)
