Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

document why field names under event_data may be unnamed (named param1, param2, etc) #2192

Closed
dedemorton opened this issue Aug 8, 2016 · 1 comment
Assignees
Labels

Comments

@dedemorton
Copy link
Contributor

For Windows platforms prior to Windows Vista, the parameters in event log messages were unnamed
Therefore, for those platforms, the output fields that appear under event_data are named param1, param2, param3, param4, etc.

See https://discuss.elastic.co/t/windows-2003-winlogbeat-x32-alpha4/57386/2

Clarification about this needs to be added here: https://www.elastic.co/guide/en/beats/winlogbeat/master/exported-fields-eventlog.html#_event_data

And perhaps an FAQ topic should also be added.

@dedemorton dedemorton added the docs label Aug 8, 2016
@dedemorton dedemorton self-assigned this Aug 8, 2016
@dedemorton
Copy link
Contributor Author

Closing in favor of tracking this issue in #2482

@dedemorton dedemorton mentioned this issue Sep 7, 2016
50 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant