# Winlogbeat not parsing AnsiString fields correctly

**URL:** <https://discuss.elastic.co/t/winlogbeat-not-parsing-ansistring-fields-correctly/378510>\
**Category:** Beats\
**Tags:** windows, winlogbeat\
**Created:** [May 25, 2025, 4:23pm UTC](https://discuss.elastic.co/t/winlogbeat-not-parsing-ansistring-fields-correctly/378510 "2025-05-25T16:23:35Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![AltairQ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/altairq/32/143328_2.png) [@AltairQ](https://discuss.elastic.co/u/AltairQ)\
**Post date:** [May 25, 2025, 4:23pm UTC](https://discuss.elastic.co/t/winlogbeat-not-parsing-ansistring-fields-correctly/378510/1 "2025-05-25T16:23:35Z")

</div>

Hello,  
I'd like to draw attention to what I believe is a bug in winlogbeat v9+ parsing logic for ETW events declared with `inType="win:AnsiString"`. Long story short, the strings are not trimmed to the null terminator.  
I made [a PR](https://github.com/elastic/beats/pull/44026) a while ago, which is still waiting for review. I would appreciate if someone could take a look -- happy to discuss further either here on under the PR.  
Thanks!

---

<div class="post-metadata">

**Author:** ![NickFritts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickfritts/32/47189_2.png) [@NickFritts](https://discuss.elastic.co/u/NickFritts)\
**Post date:** [May 27, 2025, 8:34am UTC](https://discuss.elastic.co/t/winlogbeat-not-parsing-ansistring-fields-correctly/378510/2 "2025-05-27T08:34:23Z")

</div>

Hi @AltairQ,

Thank you for reaching out. My team is the one that needs to review your PR. I'm not sure what happened as far as tracking it, but I've found it in my github queue now. I'll have someone engage with you on the PR soon though.
