# Winlogbeat user.name is missing in event 4634 (Logoff Event) - ECS Missing Correlation

**URL:** <https://discuss.elastic.co/t/winlogbeat-user-name-is-missing-in-event-4634-logoff-event-ecs-missing-correlation/189363>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [July 8, 2019, 2:18pm UTC](https://discuss.elastic.co/t/winlogbeat-user-name-is-missing-in-event-4634-logoff-event-ecs-missing-correlation/189363 "2019-07-08T14:18:06Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [July 8, 2019, 2:18pm UTC](https://discuss.elastic.co/t/winlogbeat-user-name-is-missing-in-event-4634-logoff-event-ecs-missing-correlation/189363/1 "2019-07-08T14:18:06Z")

</div>

Hi,  
I'm analizing windows event logs comming from a winlogbeat 7.2.  
When looking in the logoff event (id 4634) I see that the field user.name does not exists  
The field winlog.event\_data.TargetUserName has the proper username (I've checked correlating LogonID from events 4624 and 4634).

As far as I can see, all security events are treated by the processor:

- name: Security  
processors:
  - script:  
lang: javascript  
id: security  
file: ${path.home}/module/security/config/winlogbeat-security.js

Looking into C:\Program Files\winlogbeat\module\security\config\winlogbeat-security.js I found that the winlog.event\_data.TargetUserName is copied to user.name.. so I don't understand why user.name does not exists  
(below the example)

Thank you very much in advance  
Regards  
Ana

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/8/d8cb1aa3ad60196026ee01c0830829edd822bd12.png)

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 8, 2019, 2:45pm UTC](https://discuss.elastic.co/t/winlogbeat-user-name-is-missing-in-event-4634-logoff-event-ecs-missing-correlation/189363/2 "2019-07-08T14:45:19Z")

</div>

Thanks for testing out the new module.

4624 should have `user.name`, but 4634 isn't being handled by the module yet so it won't populate the fields. I wanted to get the module in place ASAP and continue to expand the events that it handles. In order to add new events we need to check what fields are in the event\_data and then ensure that we have the appropriate mappings in place.

You'll see in the module that three event IDs [are handled](https://github.com/elastic/beats/blob/d21cf680bc8b7e923ea257a2050cacebec81763d/x-pack/winlogbeat/module/security/config/winlogbeat-security.js#L64-L71). These are listed in the [docs too](https://www.elastic.co/guide/en/beats/winlogbeat/7.2/winlogbeat-module-security.html).

If you wanted to contribute to the module you can submit a pull request with the enhanced winlogbeat-security.js file and preferably an .evtx file for a test case.

I think what it would want to start with is

```auto
diff --git a/x-pack/winlogbeat/module/security/config/winlogbeat-security.js b/x-pack/winlogbeat/module/security/config/winlogbeat-security.js
index b598c686a..9ab1cc44c 100644
--- a/x-pack/winlogbeat/module/security/config/winlogbeat-security.js
+++ b/x-pack/winlogbeat/module/security/config/winlogbeat-security.js
@@ -60,6 +60,10 @@ var security = (function () {
         .Add(setProcessNameUsingExe)
         .Build();
 
+ var logout = new processor.Chain()
+ .Add(convertAuthentication)
+ .Build();
+
     return {
         // 4624 - An account was successfully logged on.
         4624: logonSuccess.Run,
@@ -67,6 +71,9 @@ var security = (function () {
         // 4625 - An account failed to log on.
         4625: logonFailed.Run,
 
+ // 4634 - An account was logged off.
+ 4634: logout.Run,
+
         // 4648 - A logon was attempted using explicit credentials.
         4648: logonSuccess.Run,

```

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [July 8, 2019, 3:28pm UTC](https://discuss.elastic.co/t/winlogbeat-user-name-is-missing-in-event-4634-logoff-event-ecs-missing-correlation/189363/3 "2019-07-08T15:28:36Z")

</div>

Hi Andrew  
Thank you for you reply . I'll be testing winlogbeat in depth for the next two weeks; so If I can be of any help I'll be glad.  
Regarding to the event 4634, not all the fields mapped in the convertAuthentication are present.  
For example, nor winlog.event\_data.IpAddress neither winlog.event\_data.IpPort exist

![image](https://us1.discourse-cdn.com/elastic/original/3X/9/b/9b04eb6c35f832bf8fe5f235844bb23fc0de6c01.png)

Should be all the fields present?  
Analizing the event 4624 I realize that winlog.event\_data.ProcessName is not present but the conversion is taking place anyway.  
If you confirm me that the convertAuthentication does not need all the fields, I'll submit the pull request with the .evtx file.  
Thank you very much  
Regards  
Ana

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 8, 2019, 3:41pm UTC](https://discuss.elastic.co/t/winlogbeat-user-name-is-missing-in-event-4634-logoff-event-ecs-missing-correlation/189363/4 "2019-07-08T15:41:40Z")

</div>

Because the `convert` processor is configured with `ignore_missing` it will continue to work even if those fields are not present. What's important to check is that the fields that are present have the same meaning w.r.t. the target field (which it appears they do).

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [July 9, 2019, 7:12am UTC](https://discuss.elastic.co/t/winlogbeat-user-name-is-missing-in-event-4634-logoff-event-ecs-missing-correlation/189363/5 "2019-07-09T07:12:19Z")

</div>

Hi Andrew, I've checked that the field is correct correlating event 4624 and 4634 by LoginID.  
I'll submit a pull request. Also i'm working with event 4672 (Special Logon) in which we have a similar situation.  
How do I send the .evtx in order to test?  
Thank you  
Regards  
Anna

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [July 9, 2019, 8:06am UTC](https://discuss.elastic.co/t/winlogbeat-user-name-is-missing-in-event-4634-logoff-event-ecs-missing-correlation/189363/7 "2019-07-09T08:06:28Z")

</div>

Hi Andrew,  
Last question. When proccesing event 4624 user.name is populated from winlog.event\_data.TargetUserName but when at events in the index that field does not exists.  
Is that field removed before indexng into ES?  
Thank you  
Regards  
Ana

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [July 9, 2019, 11:03am UTC](https://discuss.elastic.co/t/winlogbeat-user-name-is-missing-in-event-4634-logoff-event-ecs-missing-correlation/189363/8 "2019-07-09T11:03:23Z")

</div>

Should I fork the repo [https://github.com/elastic/beats](https://github.com/elastic/beats), clone it, make the modifications and then submit a pull request with base=master?

Thank you  
Ana

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 10, 2019, 1:28am UTC](https://discuss.elastic.co/t/winlogbeat-user-name-is-missing-in-event-4634-logoff-event-ecs-missing-correlation/189363/9 "2019-07-10T01:28:44Z")

</div>

Yep, fork, git clone, git add, git commit, and then open a PR from the website. Checkout the [contributing guide](https://github.com/elastic/beats/blob/master/CONTRIBUTING.md) for a few more details.

Regarding providing an .evtx, from the Event Viewer you can filter the view to just the events you need for testing then save them to an .evtx file. Once you have the .evtx file you can add it to [x-pack/winlogbeat/module/security/test/testdata](https://github.com/elastic/beats/tree/master/x-pack/winlogbeat/module/security/test/testdata). If you have Go setup and are on Windows you can run `go test . -update` from module/security/test directory and it will generate a `.golden.json` file based on the events in the newly added .evtx file. We commit that to the repo then if there's ever a change that causes the generated events to not match those in the .golden.json file then the tests will fail. But if you just add the .evtx file and open a PR I can take care of generating the new golden file.

> [@Anabella\_Cristaldi](#):
>
> When proccesing event 4624 user.name is populated from winlog.event\_data.TargetUserName but when at events in the index that field does not exists.

Are you referring to the `winlog.event_data.TargetUserName` field? If so, yes, the `convert` processor is configured in `rename` mode (as opposed to copy) so TargetUserName will no longer exist after the processor runs.

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [July 15, 2019, 7:14am UTC](https://discuss.elastic.co/t/winlogbeat-user-name-is-missing-in-event-4634-logoff-event-ecs-missing-correlation/189363/12 "2019-07-15T07:14:50Z")

</div>

Hi Andrew,  
It is done.

> <https://github.com/elastic/beats/pull/12906>

I wasn`t able to generate de .golden.json file (I got this go error (security\_windows\_test.go:10:2: cannot find package "[github.com/elastic/beats/x-p](http://github.com/elastic/beats/x-p)  
ack/winlogbeat/module") but I did put the .evtx with the test data.

Regards  
Ana

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 18, 2019, 4:06pm UTC](https://discuss.elastic.co/t/winlogbeat-user-name-is-missing-in-event-4634-logoff-event-ecs-missing-correlation/189363/13 "2019-07-18T16:06:47Z")

</div>

For anyone following along this [change](https://github.com/elastic/beats/pull/12906) has been merged into Winlogbeat. The Security module will handle logout events 4634 and 4647.

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [August 6, 2019, 7:27am UTC](https://discuss.elastic.co/t/winlogbeat-user-name-is-missing-in-event-4634-logoff-event-ecs-missing-correlation/189363/14 "2019-08-06T07:27:33Z")

</div>

Hi Andrew,  
Are the changes available in version 7.3? Documentation does not mention events 4634 and 4647  
Regards  
Ana

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 3, 2019, 7:27am UTC](https://discuss.elastic.co/t/winlogbeat-user-name-is-missing-in-event-4634-logoff-event-ecs-missing-correlation/189363/15 "2019-09-03T07:27:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
