# Winlogbeat not capturing specific event id's in windows server 2012

**URL:** <https://discuss.elastic.co/t/winlogbeat-not-capturing-specific-event-ids-in-windows-server-2012/134540>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [June 5, 2018, 7:05am UTC](https://discuss.elastic.co/t/winlogbeat-not-capturing-specific-event-ids-in-windows-server-2012/134540 "2018-06-05T07:05:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![r.ganeshbabu](https://avatars.discourse-cdn.com/v4/letter/r/4da419/32.png) [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Post date:** [June 5, 2018, 7:05am UTC](https://discuss.elastic.co/t/winlogbeat-not-capturing-specific-event-ids-in-windows-server-2012/134540/1 "2018-06-05T07:05:36Z")

</div>

Hi All,

I have installed winlogbeat 5.6.5 version in the windows server 2012 machine and to capture only specific event id's from the machine, I have given the event id's in the winlogbeat.yml file

```
winlogbeat.event_logs:
  - name: Security
    event_id: 4612, 4625, 4648, 4672, 4673, 4719, 4720, 4723, 4738, 4740, 4742

```

But I am receiving the other event id's with respect to security log name and below is the list,  
5156, 5145, 4658, 4661, 4634, 4624, 5158 etc..

I have read this [documentation](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#_literal_event_logs_event_id_literal) and in that it mentioned like this option is only available on supporting the windows log event API.

Does the windows server 2012 operating system doesn't support this feature?

Please let me your thoughts it would be very helpful.

Thanks,  
Ganeshbabu R

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [June 5, 2018, 8:56am UTC](https://discuss.elastic.co/t/winlogbeat-not-capturing-specific-event-ids-in-windows-server-2012/134540/2 "2018-06-05T08:56:06Z")

</div>

I have tested it using Winlogbeat 5.6.9 and the configuration you provided, under Windows server 2012 and it is working as intended, with only those event\_ids being reported.

I don't see any entry in the changelog related to this, but it wouldn't hurt to upgrade to 5.6.9.

If the problem still persist, can you share a DEBUG log?

---

<div class="post-metadata">

**Author:** ![r.ganeshbabu](https://avatars.discourse-cdn.com/v4/letter/r/4da419/32.png) [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Post date:** [June 5, 2018, 7:17pm UTC](https://discuss.elastic.co/t/winlogbeat-not-capturing-specific-event-ids-in-windows-server-2012/134540/3 "2018-06-05T19:17:19Z")

</div>

Hi @adrisr

Sorry its my mistake and after your response I rechecked the event data and I found that the other event id's are older ones.

Thanks for your response.

Regards,  
Ganeshbabu R

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2018, 7:17pm UTC](https://discuss.elastic.co/t/winlogbeat-not-capturing-specific-event-ids-in-windows-server-2012/134540/4 "2018-07-03T19:17:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
