Skip to content

Latest commit

 

History

History
31 lines (24 loc) · 728 Bytes

docs.asciidoc

File metadata and controls

31 lines (24 loc) · 728 Bytes

Security Module

beta[]

The security module processes event log records from the Security log.

The module has transformations for the following event IDs:

  • 4624 - An account was successfully logged on.

  • 4625 - An account failed to log on.

  • 4634 - An account was logged off.

  • 4647 - User initiated logoff (interactive logon types).

  • 4648 - A logon was attempted using explicit credentials.

More event IDs will be added.

Configuration

winlogbeat.event_logs:
  - name: Security
    processors:
      - script:
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js