IMPORTANT: No additional bug fixes or documentation updates will be released for this version. For the latest information, see the current release documentation.
« Sysmon Module Beat fields »
Elastic Docs ›Winlogbeat Reference [8.18]

Exported fields

A newer version is available. Check out the latest documentation.

Exported fields

This document describes the fields that are exported by Winlogbeat. They are grouped in the following categories:

  • Beat fields
  • Cloud provider metadata fields
  • Docker fields
  • ECS fields
  • Legacy Winlogbeat alias fields
  • Host fields
  • Jolokia Discovery autodiscover provider fields
  • Kubernetes fields
  • PowerShell module fields
  • Process fields
  • Security module fields
  • Sysmon module fields
  • Winlogbeat fields
« Sysmon Module Beat fields »

Most Popular

Video

Get Started with Elasticsearch

Video

Intro to Kibana

Video

ELK for Logs & Metrics