# Winlogbeat processor for powershell module

**URL:** <https://discuss.elastic.co/t/winlogbeat-processor-for-powershell-module/249390>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [September 21, 2020, 3:53pm UTC](https://discuss.elastic.co/t/winlogbeat-processor-for-powershell-module/249390 "2020-09-21T15:53:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![v.n](https://avatars.discourse-cdn.com/v4/letter/v/5daacb/32.png) [@v.n](https://discuss.elastic.co/u/v.n)\
**Post date:** [September 21, 2020, 3:53pm UTC](https://discuss.elastic.co/t/winlogbeat-processor-for-powershell-module/249390/1 "2020-09-21T15:53:27Z")

</div>

This [page](https://www.elastic.co/guide/en/beats/winlogbeat/master/winlogbeat-modules.html) shows how to enable modules for security and sysmon but nothing for powershell.

> winlogbeat.event\_logs:
> 
> - name: ForwardedEvents  
> tags: [forwarded]  
> processors:
> - script:  
> when.equals.winlog.channel: Security  
> lang: javascript  
> id: security  
> file: ${path.home}/module/security/config/winlogbeat-security.js
> - script:  
> when.equals.winlog.channel: Microsoft-Windows-Sysmon/Operational  
> lang: javascript  
> id: sysmon  
> file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js

If you want to enable powershell you need to do it like shown [here](https://www.elastic.co/guide/en/beats/winlogbeat/master/winlogbeat-module-powershell.html)

> winlogbeat.event\_logs:
> 
> - name: Windows PowerShell  
> event\_id: 400, 403, 600, 800  
> processors:
> 
> - name: Microsoft-Windows-PowerShell/Operational  
> event\_id: 4103, 4104, 4105, 4106  
> processors:

Is it possible to enable powershell module according to the first type? For example somehow

> processors:  
> - script:  
> when.equals.winlog.channel: Windows PowerShell and when.equals.event\_id: 400, 403, 600, 800

How to include multiple conditions into processor script?

---

<div class="post-metadata">

**Author:** ![v.n](https://avatars.discourse-cdn.com/v4/letter/v/5daacb/32.png) [@v.n](https://discuss.elastic.co/u/v.n)\
**Post date:** [September 22, 2020, 3:26pm UTC](https://discuss.elastic.co/t/winlogbeat-processor-for-powershell-module/249390/2 "2020-09-22T15:26:23Z")

</div>

I found the solution myself.

```auto
 - script:
     when.equals.winlog.channel: Security
     lang: javascript
     id: security
     file: ${path.home}/module/security/config/winlogbeat-security.js
  - script:
     when.equals.winlog.channel: Microsoft-Windows-Sysmon/Operational
     lang: javascript
     id: sysmon
     file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js
  - script:
     and:
      equals.winlog.channel: Windows PowerShell
      or:
       equals.event_id: 400
       equals.event_id: 403
       equals.event_id: 600
       equals.event_id: 800
     lang: javascript
     id: powershell
     file: ${path.home}/module/powershell/config/winlogbeat-powershell.js     
  - script:
     and:
      equals.winlog.channel: Microsoft-Windows-PowerShell/Operational
      or:
       equals.event_id: 4103
       equals.event_id: 4104
       equals.event_id: 4105
       equals.event_id: 4106
     lang: javascript
     id: powershell-operational
     file: ${path.home}/module/powershell/config/winlogbeat-powershell.js 

```

---

<div class="post-metadata">

**Author:** ![Pedro\_77](https://avatars.discourse-cdn.com/v4/letter/p/278dde/32.png) [@Pedro\_77](https://discuss.elastic.co/u/Pedro_77)\
**Post date:** [September 22, 2020, 8:03pm UTC](https://discuss.elastic.co/t/winlogbeat-processor-for-powershell-module/249390/3 "2020-09-22T20:03:18Z")

</div>

Hello

I have similar topic, with winlogbeat 7.9 I'm trying to get fields which are "nested" in message field:  
for example:  
` "message": "Endpoint: xxxyy211\nEndpoint IP: 10.1.1.x\nDomain: Agents\\xxx\\update\\\nDate/Time: 22.09.2020 13:43:16\nDetailed information:`

All other "normal" fields can index without problem. There is some special option to start process such kind of fields as seperate fields?

thanks for help  
Pedro

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 20, 2020, 10:03pm UTC](https://discuss.elastic.co/t/winlogbeat-processor-for-powershell-module/249390/4 "2020-10-20T22:03:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
