# Winlogbeat output kafka, but not same fields as Elastic output

**URL:** <https://discuss.elastic.co/t/winlogbeat-output-kafka-but-not-same-fields-as-elastic-output/304226>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 9, 2022, 9:00am UTC](https://discuss.elastic.co/t/winlogbeat-output-kafka-but-not-same-fields-as-elastic-output/304226 "2022-05-09T09:00:50Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![CemG](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@CemG](https://discuss.elastic.co/u/CemG)\
**Post date:** [May 9, 2022, 9:00am UTC](https://discuss.elastic.co/t/winlogbeat-output-kafka-but-not-same-fields-as-elastic-output/304226/1 "2022-05-09T09:00:50Z")

</div>

Hello,

I get Windows logs with Winlogbeat, and I output them to **Kafka**.  
The issue is that when I use Winlogbeat dashboard in Elasticsearch, there are missing fields, and I would like to use them.  
And when I use **Elasticsearch output** , it works great.  
I don't want to use Elastic as output, because I have to use Kafka as Broker.  
When I check the log's JSON in Kafka, I see that a lot of fields are missing when I do Kafka output, and with the Elastic Output, the module add those missing fields.  
Is it a way to add those fields with kafka output ?

Thanks a lot,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2022, 11:01am UTC](https://discuss.elastic.co/t/winlogbeat-output-kafka-but-not-same-fields-as-elastic-output/304226/2 "2022-06-06T11:01:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
