# \#winlogbeat

**URL:** https://discuss.elastic.co/tag/winlogbeat/57.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [Winlogbeat 9.4.3 parsing fields wrong unless include\_xml is supplied](https://discuss.elastic.co/t/winlogbeat-9-4-3-parsing-fields-wrong-unless-include-xml-is-supplied/388680)

<div class="topic-metadata">

**Author:** [@tt-ah](https://discuss.elastic.co/u/tt-ah)\
**Replies:** 2\
**Last updated:** [August 6, 2026, 1:50pm UTC](https://discuss.elastic.co/t/winlogbeat-9-4-3-parsing-fields-wrong-unless-include-xml-is-supplied/388680 "2026-08-06T13:50:15Z")

</div>

Hello everyone! I noticed at least one field being processed incorrectly after updating our Elasticsearch and Winlogbeats to 9.4.3 (from 8.x.x). I do not have other findings yet, but I doubt this is the only case. Appl…

---

## [BUG: xml\_query endlessly repeats same record in Winlogbeat 9.2.7+, 9.3](https://discuss.elastic.co/t/bug-xml-query-endlessly-repeats-same-record-in-winlogbeat-9-2-7-9-3/386112)

<div class="topic-metadata">

**Author:** [@lh317](https://discuss.elastic.co/u/lh317)\
**Replies:** 1\
**Last updated:** [April 30, 2026, 3:45pm UTC](https://discuss.elastic.co/t/bug-xml-query-endlessly-repeats-same-record-in-winlogbeat-9-2-7-9-3/386112 "2026-04-30T15:45:02Z")

</div>

I've run into an issue with newer versions of Winlogbeat that attempt to perform gap detection against the Windows channels. First, create any XML query that results in gaps in the record IDs (this should hopefully work…

---

## [Winlogbeat supports for TPM Windows certificates store](https://discuss.elastic.co/t/winlogbeat-supports-for-tpm-windows-certificates-store/386098)

<div class="topic-metadata">

**Author:** [@MiguelN](https://discuss.elastic.co/u/MiguelN)\
**Replies:** 0\
**Last updated:** [April 29, 2026, 2:57pm UTC](https://discuss.elastic.co/t/winlogbeat-supports-for-tpm-windows-certificates-store/386098 "2026-04-29T14:57:01Z")

</div>

I want to deploy per-device client certificates to Windows workstations via Intune SCEP, with the private key generated and bound to the TPM (Microsoft Platform Crypto Provider, non-exportable). Winlogbeat would then use…

---

## [Winlogbeat - Mismatched event.action for event.code](https://discuss.elastic.co/t/winlogbeat-mismatched-event-action-for-event-code/385735)

<div class="topic-metadata">

**Author:** [@coldmint](https://discuss.elastic.co/u/coldmint)\
**Replies:** 1\
**Last updated:** [April 2, 2026, 7:35am UTC](https://discuss.elastic.co/t/winlogbeat-mismatched-event-action-for-event-code/385735 "2026-04-02T07:35:31Z")

</div>

Hello, We’re running a clean install of Winlogbeat with a pretty barebones configuration, but unfortunately we’re noticing logged events transfer with incorrect event.action values for the respective event.code(Such as …

---

## [It looks like winlogbeat (8.19.10) is showing noisy warn logs again](https://discuss.elastic.co/t/it-looks-like-winlogbeat-8-19-10-is-showing-noisy-warn-logs-again/385125)

<div class="topic-metadata">

**Author:** [@Alyssa\_Nunez](https://discuss.elastic.co/u/Alyssa_Nunez)\
**Replies:** 4\
**Last updated:** [March 5, 2026, 2:19pm UTC](https://discuss.elastic.co/t/it-looks-like-winlogbeat-8-19-10-is-showing-noisy-warn-logs-again/385125 "2026-03-05T14:19:59Z")

</div>

Hi, I was going over some logs for an incident and noticed that a lot of logs we’re seeing are similar to the ones report here: Channel not found would be suppressed ( \[Winlogbeat\] Suppress excessive channel not found w…

---

## [Winlogbeat Kafka output not reading SSL certs with "wrong" line ends](https://discuss.elastic.co/t/winlogbeat-kafka-output-not-reading-ssl-certs-with-wrong-line-ends/385257)

<div class="topic-metadata">

**Author:** [@ciranor](https://discuss.elastic.co/u/ciranor)\
**Replies:** 3\
**Last updated:** [February 27, 2026, 10:41am UTC](https://discuss.elastic.co/t/winlogbeat-kafka-output-not-reading-ssl-certs-with-wrong-line-ends/385257 "2026-02-27T10:41:24Z")

</div>

I’m setting up Winlogbeat to output to Kafka with SSL certificates used to authenticate. The certificates will be generated, rotated and supplied automatically by another system. But when trying to configure it, winlogbe…

---

## [Agent (Winlogbeat) stop sending data](https://discuss.elastic.co/t/agent-winlogbeat-stop-sending-data/384988)

<div class="topic-metadata">

**Author:** [@Andex](https://discuss.elastic.co/u/Andex)\
**Replies:** 5\
**Last updated:** [February 23, 2026, 8:21pm UTC](https://discuss.elastic.co/t/agent-winlogbeat-stop-sending-data/384988 "2026-02-23T20:21:41Z")

</div>

Hi, i’m facing with a problem for some winlogbeat agents. Randomly the agent stop sending data to the cluster. When i restart the service It starts writing data from where it stopped and then after a few hours it stops a…

---

## [Registry Fields with Winlogbeat](https://discuss.elastic.co/t/registry-fields-with-winlogbeat/385082)

<div class="topic-metadata">

**Author:** [@TheBob](https://discuss.elastic.co/u/TheBob)\
**Replies:** 1\
**Last updated:** [February 17, 2026, 10:05pm UTC](https://discuss.elastic.co/t/registry-fields-with-winlogbeat/385082 "2026-02-17T22:05:07Z")

</div>

Running an Elastic Stack version 8 server. Trying to get Winlogbeat to send events to the server and run some detection rules alerts on them, but not getting all the expected fields configured. E.g. one of the rules mon…

---

## [Winlogbeat 9.2.1 Fails to Ingest Specific Windows Application Event (Winlogon Event ID 6000)](https://discuss.elastic.co/t/winlogbeat-9-2-1-fails-to-ingest-specific-windows-application-event-winlogon-event-id-6000/383593)

<div class="topic-metadata">

**Author:** [@banksmt](https://discuss.elastic.co/u/banksmt)\
**Replies:** 1\
**Last updated:** [November 22, 2025, 8:37am UTC](https://discuss.elastic.co/t/winlogbeat-9-2-1-fails-to-ingest-specific-windows-application-event-winlogon-event-id-6000/383593 "2025-11-22T08:37:15Z")

</div>

We are experiencing an issue where Winlogbeat successfully ingests all Windows log channels (Application/System/Security/Sysmon) except for one very specific event type: Microsoft-Windows-Winlogon — Event ID 6000 ("The …

---

## [Integrating fortigate firewall to elastic](https://discuss.elastic.co/t/integrating-fortigate-firewall-to-elastic/382949)

<div class="topic-metadata">

**Author:** [@phumlani](https://discuss.elastic.co/u/phumlani)\
**Replies:** 2\
**Last updated:** [October 28, 2025, 8:49pm UTC](https://discuss.elastic.co/t/integrating-fortigate-firewall-to-elastic/382949 "2025-10-28T20:49:52Z")

</div>

I am required to pull logs from the firewall(fortigate), and Office365. I have registered the application on microsoft AZURE for office365 and assigned permissions(Office365 management API(ActivityFeed.Read, ActivityFeed…

---

## [Add 'process.args\_count' to Windows Security ingest pipeline](https://discuss.elastic.co/t/add-process-args-count-to-windows-security-ingest-pipeline/382903)

<div class="topic-metadata">

**Author:** [@elkn00b](https://discuss.elastic.co/u/elkn00b)\
**Replies:** 1\
**Last updated:** [October 28, 2025, 12:26am UTC](https://discuss.elastic.co/t/add-process-args-count-to-windows-security-ingest-pipeline/382903 "2025-10-28T00:26:45Z")

</div>

Hello All, We’ve had this fix in place for a while, but I noticed when checking open issues that an enhancement request existed to add process.args\_count to the Elastic Agent integrations. I’ve reviewed the code for bo…

---

## [Winlogbeat 9.1.3 - agent logs floodinig with warnings](https://discuss.elastic.co/t/winlogbeat-9-1-3-agent-logs-floodinig-with-warnings/381577)

<div class="topic-metadata">

**Author:** [@novaksam](https://discuss.elastic.co/u/novaksam)\
**Replies:** 1\
**Last updated:** [September 4, 2025, 9:43am UTC](https://discuss.elastic.co/t/winlogbeat-9-1-3-agent-logs-floodinig-with-warnings/381577 "2025-09-04T09:43:29Z")

</div>

I recently upgraded my setup from 8.18.2 to 9.0.4, and upgraded my Winlogbeats to 9.1.3. Since doing that upgrade, the logs for my winlogbeat agents are being flooded with logs like {"log.level":"warn","@timestamp":"202…

---

## [ESA-2025-12 Detail Questions](https://discuss.elastic.co/t/esa-2025-12-detail-questions/381320)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 1\
**Last updated:** [August 28, 2025, 9:49am UTC](https://discuss.elastic.co/t/esa-2025-12-detail-questions/381320 "2025-08-28T09:49:40Z")

</div>

Per Beats (Windows Installer) 8.18.6, 8.19.3, 9.0.6, & 9.1.0 Security Update (ESA-2025-12) , Affected Configurations: The issue only affects Beats when installed through the install-service script for Windows. Example w…

---

## [Winlogbeat isn't dropping event](https://discuss.elastic.co/t/winlogbeat-isnt-dropping-event/380975)

<div class="topic-metadata">

**Author:** [@Paulo\_Isaias](https://discuss.elastic.co/u/Paulo_Isaias)\
**Replies:** 7\
**Last updated:** [August 19, 2025, 1:19pm UTC](https://discuss.elastic.co/t/winlogbeat-isnt-dropping-event/380975 "2025-08-19T13:19:09Z")

</div>

Hey guys, cheers, i really need help to drop some events at my active directory, it’s eating my disk space, xD, I have issue with filtering system logons which occur in events 4624 and 4634, i only want to filter real lo…

---

## [Elastic agent Windows integration issue](https://discuss.elastic.co/t/elastic-agent-windows-integration-issue/380771)

<div class="topic-metadata">

**Author:** [@f4n-1nh1b1t10n](https://discuss.elastic.co/u/f4n-1nh1b1t10n)\
**Replies:** 2\
**Last updated:** [August 11, 2025, 4:07pm UTC](https://discuss.elastic.co/t/elastic-agent-windows-integration-issue/380771 "2025-08-11T16:07:53Z")

</div>

Hello, first post here. Short description of the current environment: kibana and elasticsearch on 1 host (virtualized in a vbox) standalone elastic agent on another host (a windows laptop) with Windows (v3.1.0) & sys…

---

## [Winlogbeat Agent shut down unexpectedly and is not starting](https://discuss.elastic.co/t/winlogbeat-agent-shut-down-unexpectedly-and-is-not-starting/379903)

<div class="topic-metadata">

**Author:** [@DBuchukuri](https://discuss.elastic.co/u/DBuchukuri)\
**Replies:** 3\
**Last updated:** [July 8, 2025, 1:52pm UTC](https://discuss.elastic.co/t/winlogbeat-agent-shut-down-unexpectedly-and-is-not-starting/379903 "2025-07-08T13:52:27Z")

</div>

Hello, Winlogbeat Agent unexpectedly got shut down on one of the servers and now i cannot start it. when i start it in foreground it works normally but once i try to start it normally it does not show any output. If i st…

---

## [Winlogbeat not parsing AnsiString fields correctly](https://discuss.elastic.co/t/winlogbeat-not-parsing-ansistring-fields-correctly/378510)

<div class="topic-metadata">

**Author:** [@AltairQ](https://discuss.elastic.co/u/AltairQ)\
**Replies:** 1\
**Last updated:** [May 27, 2025, 8:34am UTC](https://discuss.elastic.co/t/winlogbeat-not-parsing-ansistring-fields-correctly/378510 "2025-05-27T08:34:23Z")

</div>

Hello, I'd like to draw attention to what I believe is a bug in winlogbeat v9+ parsing logic for ETW events declared with inType="win:AnsiString". Long story short, the strings are not trimmed to the null terminator. I…

---

## [Winlogbeat was mistakenly killed by 360 antivirus software, how to solve it](https://discuss.elastic.co/t/winlogbeat-was-mistakenly-killed-by-360-antivirus-software-how-to-solve-it/376156)

<div class="topic-metadata">

**Author:** [@shaohuan](https://discuss.elastic.co/u/shaohuan)\
**Replies:** 9\
**Last updated:** [April 2, 2025, 9:55am UTC](https://discuss.elastic.co/t/winlogbeat-was-mistakenly-killed-by-360-antivirus-software-how-to-solve-it/376156 "2025-04-02T09:55:29Z")

</div>

When the program is running, it is always mistakenly killed by 360 antivirus software

---

## [Winlogbeat freezes](https://discuss.elastic.co/t/winlogbeat-freezes/372270)

<div class="topic-metadata">

**Author:** [@RBR](https://discuss.elastic.co/u/RBR)\
**Replies:** 5\
**Last updated:** [March 24, 2025, 4:19pm UTC](https://discuss.elastic.co/t/winlogbeat-freezes/372270 "2025-03-24T16:19:44Z")

</div>

Hello everyone, I recently came across the topic of Elastic Search, following the motto: "Can you take a look at this" We have been having an issue since November where the transmission on our Active Directory Domain Co…

---

## [Probleme winlogbeats](https://discuss.elastic.co/t/probleme-winlogbeats/375524)

<div class="topic-metadata">

**Author:** [@team\_simsim](https://discuss.elastic.co/u/team_simsim)\
**Replies:** 7\
**Last updated:** [March 9, 2025, 5:12pm UTC](https://discuss.elastic.co/t/probleme-winlogbeats/375524 "2025-03-09T17:12:21Z")

</div>

hello my winlogbeats clients don't want to come up when I start the service there is this error Exiting: failed to sanitize the YAML pipeline file: security/ingest/security.yml: key 'false' is not string but bool than…

---

## [Windows Server 2025 Support](https://discuss.elastic.co/t/windows-server-2025-support/371325)

<div class="topic-metadata">

**Author:** [@oed-brosentd](https://discuss.elastic.co/u/oed-brosentd)\
**Replies:** 3\
**Last updated:** [March 6, 2025, 8:25am UTC](https://discuss.elastic.co/t/windows-server-2025-support/371325 "2025-03-06T08:25:41Z")

</div>

Hi there, we're currently evaluating the use of Winlog/Filebeat on Microsofts latest Major Release Windows Server 2025. As it's not yet in the Support Matrix: Is there any information on when Elastic will officially sup…

---

## [ILM problem](https://discuss.elastic.co/t/ilm-problem/373646)

<div class="topic-metadata">

**Author:** [@Mehran\_Noorani](https://discuss.elastic.co/u/Mehran_Noorani)\
**Replies:** 12\
**Last updated:** [January 26, 2025, 1:06am UTC](https://discuss.elastic.co/t/ilm-problem/373646 "2025-01-26T01:06:30Z")

</div>

hello all . I'm using ELK 8.17.1 and have ILM configured with a Hot phase. my problem is : my policy : name = policy\_ipas age = 2min size = 5mb and my indexes : also index2 : No logs are thrown inside it. ===…

---

## [Custom fields.yml not loaded](https://discuss.elastic.co/t/custom-fields-yml-not-loaded/371583)

<div class="topic-metadata">

**Author:** [@Benjamin\_Gathmann](https://discuss.elastic.co/u/Benjamin_Gathmann)\
**Replies:** 2\
**Last updated:** [December 6, 2024, 2:54pm UTC](https://discuss.elastic.co/t/custom-fields-yml-not-loaded/371583 "2024-12-06T14:54:23Z")

</div>

I have changed the mapping of a field in fields.yml and saved it as fields-patched.yml in C:\\Program Files\\Winlogbeat\\. In winlogbeat.yml, I have set this: setup.template.fields: "${path.config}/fields-patched.yml" I …

---

## [License Concerns About Winlogbeat](https://discuss.elastic.co/t/license-concerns-about-winlogbeat/370921)

<div class="topic-metadata">

**Author:** [@chhu0830](https://discuss.elastic.co/u/chhu0830)\
**Replies:** 3\
**Last updated:** [November 25, 2024, 3:18am UTC](https://discuss.elastic.co/t/license-concerns-about-winlogbeat/370921 "2024-11-25T03:18:01Z")

</div>

We have some concerns regarding the licensing of the elastic/beats project. From what we understand, winlogbeat is licensed under Apache-2.0. However, one of its dependencies, github.com/elastic/elastic-agent-client/v7/…

---

## [Windows Event pipelines - beats vs agent](https://discuss.elastic.co/t/windows-event-pipelines-beats-vs-agent/370420)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 2\
**Last updated:** [November 14, 2024, 5:37pm UTC](https://discuss.elastic.co/t/windows-event-pipelines-beats-vs-agent/370420 "2024-11-14T17:37:44Z")

</div>

When a new version of winlogbeat is setup, it loads 5 pipelines with some having a lot of processors (44-93). Looking at the logs-winlog pipelines for the agents, there are only the stubs for the optional @custom pipeli…

---

## [Forward Archived .evtx files](https://discuss.elastic.co/t/forward-archived-evtx-files/368650)

<div class="topic-metadata">

**Author:** [@turboz](https://discuss.elastic.co/u/turboz)\
**Replies:** 6\
**Last updated:** [October 24, 2024, 6:31pm UTC](https://discuss.elastic.co/t/forward-archived-evtx-files/368650 "2024-10-24T18:31:12Z")

</div>

I'm trying to use this winlogbeat config suggested by elastic to forward archived events, however I'm having issues. It paritially works I do receive events into Elastic however, randomly it will stop sending events and…

---

## [Winlogbeat is not sending logs to new version of Apache Kafka with KRaft](https://discuss.elastic.co/t/winlogbeat-is-not-sending-logs-to-new-version-of-apache-kafka-with-kraft/368812)

<div class="topic-metadata">

**Author:** [@IamYipi](https://discuss.elastic.co/u/IamYipi)\
**Replies:** 2\
**Last updated:** [October 21, 2024, 7:43am UTC](https://discuss.elastic.co/t/winlogbeat-is-not-sending-logs-to-new-version-of-apache-kafka-with-kraft/368812 "2024-10-21T07:43:35Z")

</div>

Hi everyone, I'm having a problem with Apache Kafka, related with the configuration of the output format. The arquitecture I created is with docker containers, where Apache Kafka is one and the windows host (virtualize…

---

## [Impact of not upgrading to 7.17 first](https://discuss.elastic.co/t/impact-of-not-upgrading-to-7-17-first/366630)

<div class="topic-metadata">

**Author:** [@mang0wifi](https://discuss.elastic.co/u/mang0wifi)\
**Replies:** 0\
**Last updated:** [September 16, 2024, 3:21pm UTC](https://discuss.elastic.co/t/impact-of-not-upgrading-to-7-17-first/366630 "2024-09-16T15:21:33Z")

</div>

Please can anyone explain the impact of not upgrading to 7.17 for auditbeat and winlogbeat? I am trying to troubleshoot an ELK stack and the previous team have upgraded from 7.10 straight to 8.12 (even though all the do…

---

## [Configure Winlogbeat to use Logstash and setup kibana dashboards at once](https://discuss.elastic.co/t/configure-winlogbeat-to-use-logstash-and-setup-kibana-dashboards-at-once/366357)

<div class="topic-metadata">

**Author:** [@akabigsmokee](https://discuss.elastic.co/u/akabigsmokee)\
**Replies:** 6\
**Last updated:** [September 11, 2024, 9:24pm UTC](https://discuss.elastic.co/t/configure-winlogbeat-to-use-logstash-and-setup-kibana-dashboards-at-once/366357 "2024-09-11T21:24:16Z")

</div>

Hello everyone, Can you help me with an issue I'm facing? Is it possible to configure Winlogbeat to send output to Logstash while still loading the patterns and dashboards for Kibana? Below is a screenshot showing the e…

---

## [Is there is a Version 8 32bit client for x86 windows 10 systems?](https://discuss.elastic.co/t/is-there-is-a-version-8-32bit-client-for-x86-windows-10-systems/366086)

<div class="topic-metadata">

**Author:** [@Joerg\_Kraemer](https://discuss.elastic.co/u/Joerg_Kraemer)\
**Replies:** 0\
**Last updated:** [September 5, 2024, 8:56am UTC](https://discuss.elastic.co/t/is-there-is-a-version-8-32bit-client-for-x86-windows-10-systems/366086 "2024-09-05T08:56:25Z")

</div>

Hello, is there is a Version 8 32bit client for x86 windows 10 systems? Or is it just not wanted that it works? We have a 8.14 Server and all x64 windows systems are conneted, but no way that I found that will get my …

[Next page](https://discuss.elastic.co/tag/winlogbeat/57.md?match_all_tags=true&page=1&tags%5B%5D=winlogbeat)
