# Winlogbeat not all events are parsed

**URL:** <https://discuss.elastic.co/t/winlogbeat-not-all-events-are-parsed/173707>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 25, 2019, 9:40am UTC](https://discuss.elastic.co/t/winlogbeat-not-all-events-are-parsed/173707 "2019-03-25T09:40:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kalinichenk](https://avatars.discourse-cdn.com/v4/letter/k/48db29/32.png) [@kalinichenk](https://discuss.elastic.co/u/kalinichenk)\
**Post date:** [March 25, 2019, 9:40am UTC](https://discuss.elastic.co/t/winlogbeat-not-all-events-are-parsed/173707/1 "2019-03-25T09:40:30Z")

</div>

Hello!  
I have ELK stack 6.6.2 and some beats installed.  
The problem is that some fields from Winlogbeat are not parsed.  
For example event\_id 4663 "Message" field contains:

Access Request Information:  
Accesses: ReadData (or ListDirectory)  
Access Mask: 0x1

"Access Mask" field was parsed, Accesses field was not.

I don't apply any filters to winlogbeat events in Logstash.  
How can I get parsed "Accesses" field?

Available fields, filtered by "access":  
event\_data.AccessList  
event\_data.AccessList.keyword  
event\_data.AccessMask  
event\_data.AccessMask.keyword

Winlogbeat config:

```
tags: ["winlogbeat"]
winlogbeat.event_logs:
  - name: Application
  - name: Security
  - name: System
output.logstash:
  hosts: ["logstash1:5044"]
logging.level: error

```

Logstash config:

```
input {
 beats {
    host => "192.168.1.10"
    port => 5044
    client_inactivity_timeout => 600
 }
}

output {
    if "winlogbeat" in [tags] {
        elasticsearch {
                hosts => ["192.168.1.10:9200"]
                index => "winlogbeat-eventlog-%{+YYYY.MM.dd}"
        }
    } 
}

```

Thank a lot

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [March 29, 2019, 2:50pm UTC](https://discuss.elastic.co/t/winlogbeat-not-all-events-are-parsed/173707/2 "2019-03-29T14:50:21Z")

</div>

Hi,

The information about "accesses" comes encoded into the `event_data.AccessList` field. Currently Winlogbeat does not decode this field.

In your case, you have:

> event\_data.AccessList: "%%416"

Which means

 ![25](https://us1.discourse-cdn.com/elastic/original/3X/f/1/f10d3ac1f83a2535e2ce8017774e586f9d6cff03.png)

You can see the mappings from access code to permission here:

> **[4663(S) An attempt was made to access an object. - Windows Security](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4663)**
>
> Describes security event 4663(S) An attempt was made to access an object.

I've created an enhancement request to make this mapping automatically from Winlogbeat:

> <https://github.com/elastic/beats/issues/11539>
>
> Some auditing messages (\[4663\](https://docs.microsoft.com/en-us/windows/security…/threat-protection/auditing/event-4663) for example) contain a list of permissions (a.k.a AccessList).
> 
> This is list encoded as a list of numeric identifiers ("%%4416") and we would like to have them mapped to their textual representation ("ReadData (or ListDirectory) ") as Event Viewer does.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2019, 2:50pm UTC](https://discuss.elastic.co/t/winlogbeat-not-all-events-are-parsed/173707/3 "2019-04-26T14:50:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
