We've reorganized our documentation navigation structure to align directly with your operational workflows. See the release notes and the walkthrough video for more information.
Stay organized with collections
Save and categorize content based on your preferences.
Change log for ELASTIC_WINLOGBEAT
Date
Changes
2022-04-27
Enhancement-Added new field mapping.
mapped StartAddress to target.labels
2022-04-13
Enhancement
-Mapped ReferrerUrl, HostUrl from additional to security_result.rule_labels.
-Mapped CallTrace field to security_result.detection_fields.
Handled the below errors:
"winlog.keywords.0" not found in state data
"security_result" not found in state data
"winlog.record_id": field not set
"_event.provider": field not set
"powershell.file.script_block_id": field not set
"winlog.opcode": field not set
"_event.action": field not set
"auth_mechanism" must not be empty
"winlog.process.pid": field not set
"winlog.event_data.TargetUserName": field not set
"agent.type": field not set
"host.name": field not set
"agent.version": field not set
2022-03-25
Enhancement
- Added check for event_type where event.code is either 11, 12, or 13.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-08-11 UTC."],[],[]]