---
title: "box.win_winlogbeat"
canonical: "https://docs.devo.com/space/latest/367493206/box.win_winlogbeat"
format: markdown
---
> Macro (toc)

## Introduction

The tags beginning with `box.win_winlogbeat` identify events generated by [Winlogbeat](https://www.elastic.co/downloads/beats/winlogbeat).

## Valid tags and data tables 

The full tag must have at least 2 levels. The first two are fixed as** **`box.win_winlogbeat`. The third level identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

| **Product / Service** | **Tags** | **Data tables** |
| --- | --- | --- |
| Winlogbeat | - `box.win_winlogbeat.application`
- `box.win_winlogbeat.sysmon`
- `box.win_winlogbeat.security`
- `box.win_winlogbeat.applocker` | `box.win_winlogbeat` |
| `box.win_winlogbeat.adpwprotect` | `box.win_winlogbeat.adpwprotect` |
| `box.win_winlogbeat.application` | `box.win_winlogbeat.application` |
| `box.win_winlogbeat.applocker` | `box.win_winlogbeat.applocker` |
| `box.win_winlogbeat.authentication` | `box.win_winlogbeat.authentication` |
| `box.win_winlogbeat.bits-client` | `box.win_winlogbeat.bitsClient` |
| `box.win_winlogbeat.codeintegrity` | `box.win_winlogbeat.codeintegrity` |
| `box.win_winlogbeat.deviceguard` | `box.win_winlogbeat.deviceguard` |
| `box.win_winlogbeat.dns` | `box.win_winlogbeat.dns` |
| `box.win_winlogbeat.forwarding` | `box.win_winlogbeat.forwarding` |
| `box.win_winlogbeat.kernel-pnp` | `box.win_winlogbeat.kernelPnp` |
| `box.win_winlogbeat.ntlm` | `box.win_winlogbeat.ntlm` |
| `box.win_winlogbeat.oalerts` | `box.win_winlogbeat.oalerts` |
| `box.win_winlogbeat.powershell` | `box.win_winlogbeat.powershell` |
| `box.win_winlogbeat.security` | `box.win_winlogbeat.security` |
| `box.win_winlogbeat.security-mitigations` | `box.win_winlogbeat.securityMitigations` |
| `box.win_winlogbeat.setup` | `box.win_winlogbeat.setup` |
| `box.win_winlogbeat.smb` | `box.win_winlogbeat.smb` |
| `box.win_winlogbeat.sysmon` | `box.win_winlogbeat.sysmon` |
| `box.win_winlogbeat.system` | `box.win_winlogbeat.system` |
| `box.win_winlogbeat.taskscheduler` | `box.win_winlogbeat.taskscheduler` |
| `box.win_winlogbeat.terminalservices` | `box.win_winlogbeat.terminalservices` |
| `box.win_winlogbeat.win32k` | `box.win_winlogbeat.win32k` |
| `box.win_winlogbeat.windows_defender` | `box.win_winlogbeat.windows_defender` |
| `box.win_winlogbeat.windows_firewall` | `box.win_winlogbeat.windows_firewall` |
| `box.win_winlogbeat.windowsupdateclient` | `box.win_winlogbeat.windowsupdateclient` |
| `box.win_winlogbeat.wmi-activity` | `box.win_winlogbeat.wmiActivity` |

For more information, read more [About Devo tags](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95126204).

## Send it

> Macro (excerpt-include)



Data should be sent using the [relay](https://docs.devo.com/space/latest/96468993/Devo+Relay).

### Example [relay rules](https://docs.devo.com/space/latest/96469377/Defining+a+relay+rule)

```
         Source message: 
            Source data:
             Source tag: 
             Target tag: box.win_winlogbeat.security
Sent without syslog tag: false
        Stop processing: false
```

## Table structure

These are the fields displayed in these tables:

> Macro (rw-ui-tabs-macro)
> 
> > Macro (rw-tab)
> 
> - [box.win_winlogbeat](#tag1)
> - [box.win_winlogbeat.adpwprotect](#tag2)
> - [box.win_winlogbeat.application](#tag3)
> - [box.win_winlogbeat.applocker](#tag4)
> - [box.win_winlogbeat.authentication](#tag5)
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat
> 
> | **Field** | **Type** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- |
> | *eventdate* | `timestamp` | * * |  |
> | *hostname* | `str` | * * |  |
> | *tableName* | `str` | *vEventSource* |  |
> | *at_timestamp* | `str` | * * |  |
> | *event__action* | `str` | * * |  |
> | *event__category* | `str` | * * |  |
> | *event__outcome* | `str` | * * |  |
> | *event__code* | `int4` | * * |  |
> | *event__created* | `str` | * * |  |
> | *event__kind* | `str` | * * |  |
> | *event__provider* | `str` | * * |  |
> | *event__type* | `str` | * * |  |
> | *event__original* | `str` | * * |  |
> | *group__domain* | `str` | * * |  |
> | *group__id* | `str` | * * |  |
> | *group__name* | `str` | * * |  |
> | *host__hostname* | `str` | * * |  |
> | *host__id* | `str` | * * |  |
> | *host__ip* | `str` | * * |  |
> | *host__ip_first* | `str` | * * |  |
> | *host__mac* | `str` | * * |  |
> | *host__name* | `str` | * * |  |
> | *host__os__name* | `str` | * * |  |
> | *log__level* | `str` | * * |  |
> | *message* | `str` | * * |  |
> | *process__command_line* | `str` | * * |  |
> | *process__name* | `str` | * * |  |
> | *process__parent__name* | `str` | * * |  |
> | *service__name* | `str` | * * |  |
> | *service__type* | `str` | * * |  |
> | *winlog__activity_id* | `str` | * * |  |
> | *winlog__channel* | `str` | * * |  |
> | *winlog__computer_name* | `str` | * * |  |
> | *winlog__event_data__UtcTime* | `timestamp` | * * |  |
> | *winlog__event_data__User* | `str` | * * |  |
> | *winlog__event_data__AppId* | `str` | * * |  |
> | *winlog__event_data__ErrorCode* | `str` | * * |  |
> | *winlog__event_data__ImagePath* | `str` | * * |  |
> | *winlog__event_data__IpAddress* | `str` | * * |  |
> | *winlog__event_data__IpPort* | `str` | * * |  |
> | *winlog__event_data__MandatoryLabel* | `str` | * * |  |
> | *winlog__event_data__ObjectName* | `str` | * * |  |
> | *winlog__event_data__ObjectServer* | `str` | * * |  |
> | *winlog__event_data__ObjectType* | `str` | * * |  |
> | *winlog__event_data__ObjectValueName* | `str` | * * |  |
> | *winlog__event_data__LogonId* | `str` | * * |  |
> | *winlog__event_data__LogonType* | `str` | * * |  |
> | *winlog__event_data__LogonGuid* | `str` | * * |  |
> | *winlog__event_data__LogonProcessName* | `str` | * * |  |
> | *winlog__event_data__ProcessId* | `str` | * * |  |
> | *winlog__event_data__ProcessName* | `str` | * * |  |
> | *winlog__event_data__ProcessGuid* | `str` | * * |  |
> | *winlog__event_data__ServiceAccount* | `str` | * * |  |
> | *winlog__event_data__ServiceFileName* | `str` | * * |  |
> | *winlog__event_data__ServiceName* | `str` | * * |  |
> | *winlog__event_data__SubjectDomainName* | `str` | * * |  |
> | *winlog__event_data__SubjectLogonId* | `str` | * * |  |
> | *winlog__event_data__SubjectUserName* | `str` | * * |  |
> | *winlog__event_data__SubjectUserSid* | `str` | * * |  |
> | *winlog__event_data__TargetDomainName* | `str` | * * |  |
> | *winlog__event_data__TargetLogonId* | `str` | * * |  |
> | *winlog__event_data__TargetUserName* | `str` | * * |  |
> | *winlog__event_data__TargetUserSid* | `str` | * * |  |
> | *winlog__event_data__TargetObject* | `str` | * * |  |
> | *winlog__event_data__TokenElevationType* | `str` | * * |  |
> | *winlog__event_data__Workstation* | `str` | * * |  |
> | *winlog__event_data__WorkstationName* | `str` | * * |  |
> | *winlog__event_data__CurrentDirectory* | `str` | * * |  |
> | *winlog__event_data__OriginalFileName* | `str` | * * |  |
> | *winlog__event_data__FileVersion* | `ip4` | * * |  |
> | *winlog__event_data__Hashes* | `str` | * * |  |
> | *winlog__event_data__IntegrityLevel* | `str` | * * |  |
> | *winlog__event_data__Description* | `str` | * * |  |
> | *winlog__event_data__QueryName* | `str` | * * |  |
> | *winlog__event_data__QueryStatus* | `str` | * * |  |
> | *winlog__event_data__QueryResults* | `str` | * * |  |
> | *winlog__event_data__ShareName* | `str` | * * |  |
> | *winlog__event_data__ShareLocalPath* | `str` | * * |  |
> | *winlog__event_data__RelativeTargetName* | `str` | * * |  |
> | *winlog__event_data__ClassId* | `str` | * * |  |
> | *winlog__event_data__ClassName* | `str` | * * |  |
> | *winlog__event_data__DeviceId* | `str` | * * |  |
> | *winlog__event_data__DeviceDescription* | `str` | * * |  |
> | *winlog__event_data__TaskName* | `str` | * * |  |
> | *winlog__event_data__TaskContent* | `str` | * * |  |
> | *winlog__event_data__TicketEncryptionType* | `str` | * * |  |
> | *winlog__event_data__TicketOptions* | `str` | * * |  |
> | *winlog__event_data__Signature* | `str` | * * |  |
> | *winlog__event_data__Initiated* | `str` | * * |  |
> | *winlog__event_data__ContextInfo* | `str` | * * |  |
> | *winlog__event_data__Payload* | `str` | * * |  |
> | *winlog__event_data__DestIp* | `str` | * * |  |
> | *winlog__event_data__DestPort* | `str` | * * |  |
> | *winlog__event_data__LayerRTID* | `str` | * * |  |
> | *winlog__event_data__AuthenticationPackageName* | `str` | * * |  |
> | *winlog__event_data__Properties* | `str` | * * |  |
> | *winlog__event_data__OperationType* | `str` | * * |  |
> | *winlog__event_data__HandleId* | `str` | * * |  |
> | *winlog__event_data__OldValueType* | `str` | * * |  |
> | *winlog__event_data__OldValue* | `str` | * * |  |
> | *winlog__event_data__NewValueType* | `str` | * * |  |
> | *winlog__event_data__NewValue* | `str` | * * |  |
> | *winlog__event_data__PrivilegeList* | `str` | * * |  |
> | *winlog__event_data__AttributeValue* | `str` | * * |  |
> | *winlog__event_data__AttributeLDAPDisplayName* | `str` | * * |  |
> | *winlog__event_data__SamAccountName* | `str` | * * |  |
> | *winlog__event_data__AccessMask* | `str` | * * |  |
> | *winlog__event_data__AccessList* | `str` | * * |  |
> | *winlog__event_data__AccessReason* | `str` | * * |  |
> | *winlog__event_data__FailureReason* | `str` | * * |  |
> | *winlog__event_data__AuditPolicyChanges* | `str` | * * |  |
> | *winlog__event_data__MemberName* | `str` | * * |  |
> | *winlog__event_data__NewProcessId* | `str` | * * |  |
> | *winlog__event_data__NewProcessName* | `str` | * * |  |
> | *winlog__event_data__CallerProcessId* | `str` | * * |  |
> | *winlog__event_data__CallerProcessName* | `str` | * * |  |
> | *winlog__event_data__ParentProcessId* | `str` | * * |  |
> | *winlog__event_data__ParentProcessGuid* | `str` | * * |  |
> | *winlog__event_data__ParentCommandLine* | `str` | * * |  |
> | *winlog__event_data__KeyLength* | `str` | * * |  |
> | *winlog__event_data__Image* | `str` | * * |  |
> | *winlog__event_data__ParentImage* | `str` | * * |  |
> | *winlog__event_data__ParentUser* | `str` | * * |  |
> | *winlog__event_data__SourceIp* | `str` | * * |  |
> | *winlog__event_data__SourceIsIpv6* | `str` | * * |  |
> | *winlog__event_data__SourcePort* | `str` | * * |  |
> | *winlog__event_data__SourcePortName* | `str` | * * |  |
> | *winlog__event_data__SourceHostname* | `str` | * * |  |
> | *winlog__event_data__DestinationIp* | `str` | * * |  |
> | *winlog__event_data__DestinationIsIpv6* | `str` | * * |  |
> | *winlog__event_data__DestinationPort* | `str` | * * |  |
> | *winlog__event_data__DestinationPortName* | `str` | * * |  |
> | *winlog__event_data__DestinationHostname* | `str` | * * |  |
> | *winlog__event_data__Protocol* | `str` | * * |  |
> | *winlog__event_data__RuleName* | `str` | * * |  |
> | *winlog__event_data__param1* | `str` | * * |  |
> | *winlog__event_data__param2* | `str` | * * |  |
> | *winlog__event_data__param3* | `str` | * * |  |
> | *winlog__event_data__param4* | `str` | * * |  |
> | *winlog__event_data__param5* | `str` | * * |  |
> | *winlog__event_data__param6* | `str` | * * |  |
> | *winlog__event_data__param7* | `str` | * * |  |
> | *winlog__event_data__param8* | `str` | * * |  |
> | *winlog__event_data__param9* | `str` | * * |  |
> | *winlog__event_data__param10* | `str` | * * |  |
> | *winlog__event_data__param11* | `str` | * * |  |
> | *winlog__event_data__param12* | `str` | * * |  |
> | *winlog__event_data__param13* | `str` | * * |  |
> | *winlog__event_data__param14* | `str` | * * |  |
> | *winlog__event_data__param15* | `str` | * * |  |
> | *winlog__event_data__param16* | `str` | * * |  |
> | *winlog__event_data__param17* | `str` | * * |  |
> | *winlog__event_data__param18* | `str` | * * |  |
> | *winlog__event_data__param19* | `str` | * * |  |
> | *winlog__event_data__param20* | `str` | * * |  |
> | *winlog__event_data__param21* | `str` | * * |  |
> | *winlog__event_data__param22* | `str` | * * |  |
> | *winlog__event_data__param23* | `str` | * * |  |
> | *winlog__event_data__Product* | `str` | * * |  |
> | *winlog__event_data__Company* | `str` | * * |  |
> | *winlog__event_id* | `int4` | * * |  |
> | *winlog__keywords* | `str` | * * |  |
> | *winlog__keywords_first* | `str` | * * |  |
> | *winlog__logon__failure__reason* | `str` | * * |  |
> | *winlog__logon__failure__status* | `str` | * * |  |
> | *winlog__logon__failure__sub_status* | `str` | * * |  |
> | *winlog__event_data__sub_status* | `str` | * * |  |
> | *winlog__logon__id* | `str` | * * |  |
> | *winlog__logon__type* | `str` | * * |  |
> | *winlog__opcode* | `str` | * * |  |
> | *winlog__process__pid* | `int4` | * * |  |
> | *winlog__process__thread__id* | `int4` | * * |  |
> | *winlog__provider_guid* | `str` | * * |  |
> | *winlog__provider_name* | `str` | * * |  |
> | *winlog__record_id* | `int8` | * * |  |
> | *winlog__task* | `str` | * * |  |
> | *winlog__user__domain* | `str` | * * |  |
> | *winlog__user__identifier* | `str` | * * |  |
> | *winlog__user__name* | `str` | * * |  |
> | *winlog__user__type* | `str` | * * |  |
> | *winlog__user_data__param1* | `str` | * * |  |
> | *winlog__user_data__param2* | `str` | * * |  |
> | *winlog__user_data__xml_name* | `str` | * * |  |
> | *winlog__user_data__PolicyName* | `str` | * * |  |
> | *winlog__user_data__PolicyNameLength* | `str` | * * |  |
> | *winlog__user_data__Fqbn* | `str` | * * |  |
> | *winlog__user_data__RuleName* | `str` | * * |  |
> | *winlog__user_data__RuleNameLength* | `str` | * * |  |
> | *winlog__user_data__FullFilePath* | `str` | * * |  |
> | *winlog__user_data__RuleSddlLength* | `str` | * * |  |
> | *winlog__user_data__FilePathLength* | `str` | * * |  |
> | *winlog__user_data__FilePath* | `str` | * * |  |
> | *winlog__user_data__RuleId* | `str` | * * |  |
> | *winlog__user_data__TargetLogonId* | `str` | * * |  |
> | *winlog__user_data__FullFilePathLength* | `str` | * * |  |
> | *winlog__user_data__TargetProcessId* | `str` | * * |  |
> | *winlog__user_data__RuleSddl* | `str` | * * |  |
> | *winlog__user_data__TargetUser* | `str` | * * |  |
> | *winlog__user_data__FileHashLength* | `str` | * * |  |
> | *winlog__user_data__FqbnLength* | `str` | * * |  |
> | *message__hostVersion* | `str` | * * |  |
> | *message__engineVersion* | `str` | * * |  |
> | *base_name* | `str` | * * |  |
> | *domain_name* | `str` | * * |  |
> | *log_name* | `str` | * * |  |
> | *logcollector* | `str` | * * |  |
> | *hostchain* | `str` | * * | **✓** |
> | *tag* | `str` | * * | **✓** |
> | *rawMessage* | `str` | * * | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.adpwprotect
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__code* | `str` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__activity_id* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__Data1* | `str` |  |
> | *winlog__event_data__Data2* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.application
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__action* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *event__original* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__activity_id* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__AppId* | `str` |  |
> | *winlog__event_data__ErrorCode* | `str` |  |
> | *winlog__event_data__param1* | `str` |  |
> | *winlog__event_data__param2* | `str` |  |
> | *winlog__event_data__param3* | `str` |  |
> | *winlog__event_data__param4* | `str` |  |
> | *winlog__event_data__param5* | `str` |  |
> | *winlog__event_data__param6* | `str` |  |
> | *winlog__event_data__param7* | `str` |  |
> | *winlog__event_data__param8* | `str` |  |
> | *winlog__event_data__param9* | `str` |  |
> | *winlog__event_data__param10* | `str` |  |
> | *winlog__event_data__param11* | `str` |  |
> | *winlog__event_data__param12* | `str` |  |
> | *winlog__event_data__param13* | `str` |  |
> | *winlog__event_data__param14* | `str` |  |
> | *winlog__event_data__param15* | `str` |  |
> | *winlog__event_data__param16* | `str` |  |
> | *winlog__event_data__param17* | `str` |  |
> | *winlog__event_data__param18* | `str` |  |
> | *winlog__event_data__param19* | `str` |  |
> | *winlog__event_data__param20* | `str` |  |
> | *winlog__event_data__param21* | `str` |  |
> | *winlog__event_data__param22* | `str` |  |
> | *winlog__event_data__param23* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *winlog__user_data__binaryData* | `str` |  |
> | *winlog__user_data__binaryDataSize* | `str` |  |
> | *winlog__user_data__param1* | `str` |  |
> | *winlog__user_data__param2* | `str` |  |
> | *winlog__user_data__xml_name* | `str` |  |
> | *base_name* | `str` |  |
> | *domain_name* | `str` |  |
> | *log_name* | `str` |  |
> | *logcollector* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.applocker
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__provider* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__kind* | `str` |  |
> | *event__created* | `str` |  |
> | *host__os__name* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__id* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__user_data__PolicyName* | `str` |  |
> | *winlog__user_data__PolicyNameLength* | `str` |  |
> | *winlog__user_data__Fqbn* | `str` |  |
> | *winlog__user_data__RuleName* | `str` |  |
> | *winlog__user_data__RuleNameLength* | `str` |  |
> | *winlog__user_data__FullFilePath* | `str` |  |
> | *winlog__user_data__RuleSddlLength* | `str` |  |
> | *winlog__user_data__FilePathLength* | `str` |  |
> | *winlog__user_data__FilePath* | `str` |  |
> | *winlog__user_data__RuleId* | `str` |  |
> | *winlog__user_data__xml_name* | `str` |  |
> | *winlog__user_data__TargetLogonId* | `str` |  |
> | *winlog__user_data__FullFilePathLength* | `str` |  |
> | *winlog__user_data__TargetProcessId* | `str` |  |
> | *winlog__user_data__RuleSddl* | `str` |  |
> | *winlog__user_data__TargetUser* | `str` |  |
> | *winlog__user_data__FileHashLength* | `str` |  |
> | *winlog__user_data__FqbnLength* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__opcode* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.authentication
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__AccountName* | `str` |  |
> | *winlog__event_data__DeviceName* | `str` |  |
> | *winlog__event_data__Status* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> > Macro (rw-tab)
> 
> - [box.win_winlogbeat.bitsClient](#tag6)
> - [box.win_winlogbeat.codeintegrity](#tag7)
> - [box.win_winlogbeat.deviceguard](#tag8)
> - [box.win_winlogbeat.dns](#tag89)
> - [box.win_winlogbeat.forwarding](#tag9)
> - [box.win_winlogbeat.kernelPnp](#tag10)
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.bitsClient
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__activity_id* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__AdditionalInfoHr* | `str` |  |
> | *winlog__event_data__ClientProcessStartKey* | `str` |  |
> | *winlog__event_data__ErrorCode* | `str` |  |
> | *winlog__event_data__Id* | `str` |  |
> | *winlog__event_data__LocalName* | `str` |  |
> | *winlog__event_data__Owner* | `str` |  |
> | *winlog__event_data__PeerContextInfo* | `str` |  |
> | *winlog__event_data__RemoteName* | `str` |  |
> | *winlog__event_data__Title* | `str` |  |
> | *winlog__event_data__User* | `str` |  |
> | *winlog__event_data__bandwidthLimit* | `str` |  |
> | *winlog__event_data__bytesTotal* | `str` |  |
> | *winlog__event_data__bytesTransferred* | `str` |  |
> | *winlog__event_data__bytesTransferredFromPeer* | `str` |  |
> | *winlog__event_data__fileCount* | `str` |  |
> | *winlog__event_data__fileLength* | `str` |  |
> | *winlog__event_data__fileTime* | `str` |  |
> | *winlog__event_data__hr* | `str` |  |
> | *winlog__event_data__ignoreBandwidthLimitsOnLan* | `str` |  |
> | *winlog__event_data__isRoaming* | `str` |  |
> | *winlog__event_data__job* | `str` |  |
> | *winlog__event_data__jobId* | `str` |  |
> | *winlog__event_data__jobName* | `str` |  |
> | *winlog__event_data__jobOwner* | `str` |  |
> | *winlog__event_data__jobTitle* | `str` |  |
> | *winlog__event_data__name* | `str` |  |
> | *winlog__event_data__number* | `str` |  |
> | *winlog__event_data__peerProtocolFlags* | `str` |  |
> | *winlog__event_data__processId* | `str` |  |
> | *winlog__event_data__processPath* | `str` |  |
> | *winlog__event_data__scheme* | `str` |  |
> | *winlog__event_data__server* | `str` |  |
> | *winlog__event_data__string2* | `str` |  |
> | *winlog__event_data__string* | `str` |  |
> | *winlog__event_data__transferId* | `str` |  |
> | *winlog__event_data__url* | `str` |  |
> | *winlog__event_data__user* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.codeintegrity
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__activity_id* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__FileNameBuffer* | `str` |  |
> | *winlog__event_data__FileNameLength* | `str` |  |
> | *winlog__event_data__ProcessNameBuffer* | `str` |  |
> | *winlog__event_data__ProcessNameLength* | `str` |  |
> | *winlog__event_data__RequestedSigningLevel* | `str` |  |
> | *winlog__event_data__SecureRequired* | `str` |  |
> | *winlog__event_data__Status* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.deviceguard
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.dns
> 
> | **Field** | **Type** | **Field transformation** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  |  |  |
> | *hostname* | `str` |  |  |  |
> | *at_timestamp* | `str` |  |  |  |
> | *event__kind* | `str` |  |  |  |
> | *event__provider* | `str` |  |  |  |
> | *event__action* | `str` |  |  |  |
> | *event__created* | `str` |  |  |  |
> | *event__code* | `str` |  |  |  |
> | *log__level* | `str` |  |  |  |
> | *message* | `str` |  |  |  |
> | *agent__ephemeral_id* | `str` |  |  |  |
> | *host__name* | `str` |  |  |  |
> | *winlog__channel* | `str` |  |  |  |
> | *winlog__user__type* | `str` |  |  |  |
> | *winlog__user__identifier* | `str` |  |  |  |
> | *winlog__user__domain* | `str` |  |  |  |
> | *winlog__user__name* | `str` |  |  |  |
> | *winlog__keywords* | `str` | ```
> join(winlog__keywords_array, ',')
> ``` | *winlog__keywords_array* |  |
> | *winlog__task* | `str` |  |  |  |
> | *winlog__computer_name* | `str` |  |  |  |
> | *winlog__event_data__param1* | `str` |  |  |  |
> | *winlog__event_data__Binary* | `str` |  |  |  |
> | *winlog__provider_name* | `str` |  |  |  |
> | *winlog__api* | `str` |  |  |  |
> | *winlog__process__pid* | `int4` |  |  |  |
> | *winlog__process__thread__id* | `int4` |  |  |  |
> | *winlog__provider_guid* | `str` |  |  |  |
> | *winlog__event_id* | `int4` |  |  |  |
> | *winlog__record_id* | `int8` |  |  |  |
> | *winlog__opcode* | `str` |  |  |  |
> | *hostchain* | `str` |  |  | **✓** |
> | *tag* | `str` |  |  | **✓** |
> | *rawMessage* | `str` |  |  | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.forwarding
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__activity_id* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__ErrorCode* | `str` |  |
> | *winlog__event_data__ErrorMessage* | `str` |  |
> | *winlog__event_data__Id* | `str` |  |
> | *winlog__event_data__Query* | `str` |  |
> | *winlog__event_data__Status* | `str` |  |
> | *winlog__event_data__SubscriptionManagerAddress* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.kernelPnp
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__ClassGuid* | `str` |  |
> | *winlog__event_data__DeviceInstanceId* | `str` |  |
> | *winlog__event_data__DeviceUpdated* | `str` |  |
> | *winlog__event_data__DriverDate* | `str` |  |
> | *winlog__event_data__DriverInbox* | `str` |  |
> | *winlog__event_data__DriverName* | `str` |  |
> | *winlog__event_data__DriverProvider* | `str` |  |
> | *winlog__event_data__DriverRank* | `str` |  |
> | *winlog__event_data__DriverSection* | `str` |  |
> | *winlog__event_data__DriverVersion* | `str` |  |
> | *winlog__event_data__MatchingDeviceId* | `str` |  |
> | *winlog__event_data__ParentDeviceInstanceId* | `str` |  |
> | *winlog__event_data__Problem* | `str` |  |
> | *winlog__event_data__ServiceName* | `str` |  |
> | *winlog__event_data__Status* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> > Macro (rw-tab)
> 
> - [box.win_winlogbeat.ntlm](#tag11)
> - [box.win_winlogbeat.oalerts](#tag12)
> - [box.win_winlogbeat.powershell](#tag13)
> - [box.win_winlogbeat.security](#tag14)
> - [box.win_winlogbeat.securityMitigations](#tag15)
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.ntlm
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__action* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__activity_id* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__CallerPID* | `str` |  |
> | *winlog__event_data__ClientDomainName* | `str` |  |
> | *winlog__event_data__ClientLUID* | `str` |  |
> | *winlog__event_data__ClientUserName* | `str` |  |
> | *winlog__event_data__DomainName* | `str` |  |
> | *winlog__event_data__MechanismOID* | `str` |  |
> | *winlog__event_data__ProcessName* | `str` |  |
> | *winlog__event_data__TargetName* | `str` |  |
> | *winlog__event_data__UserName* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.oalerts
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__param1* | `str` |  |
> | *winlog__event_data__param2* | `str` |  |
> | *winlog__event_data__param3* | `str` |  |
> | *winlog__event_data__param4* | `str` |  |
> | *winlog__event_data__param5* | `str` |  |
> | *winlog__event_data__param6* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.powershell
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__action* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__activity_id* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__ContextInfo* | `str` |  |
> | *winlog__event_data__FileName* | `str` |  |
> | *winlog__event_data__InstanceId* | `str` |  |
> | *winlog__event_data__MaxRunspaces* | `str` |  |
> | *winlog__event_data__MessageNumber* | `str` |  |
> | *winlog__event_data__MessageTotal* | `str` |  |
> | *winlog__event_data__MinRunspaces* | `str` |  |
> | *winlog__event_data__Path* | `str` |  |
> | *winlog__event_data__Payload* | `str` |  |
> | *winlog__event_data__ScriptBlockId* | `str` |  |
> | *winlog__event_data__ScriptBlockText* | `str` |  |
> | *winlog__event_data__param1* | `str` |  |
> | *winlog__event_data__param2* | `str` |  |
> | *winlog__event_data__param3* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *message__hostVersion* | `str` |  |
> | *message__engineVersion* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.security
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__action* | `str` |  |
> | *event__category* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__module* | `str` |  |
> | *event__outcome* | `str` |  |
> | *event__provider* | `str` |  |
> | *event__type* | `str` |  |
> | *event__original* | `str` |  |
> | *group__domain* | `str` |  |
> | *group__id* | `str` |  |
> | *group__name* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *process__args* | `str` |  |
> | *process__command_line* | `str` |  |
> | *process__executable* | `str` |  |
> | *process__name* | `str` |  |
> | *process__parent__executable* | `str` |  |
> | *process__parent__name* | `str` |  |
> | *process__pid* | `int4` |  |
> | *related__user* | `str` |  |
> | *service__name* | `str` |  |
> | *service__type* | `str` |  |
> | *source__domain* | `str` |  |
> | *source__ip* | `ip4` |  |
> | *source__port* | `int4` |  |
> | *user__domain* | `str` |  |
> | *user__id* | `str` |  |
> | *user__name* | `str` |  |
> | *winlog__activity_id* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__AccessList* | `str` |  |
> | *winlog__event_data__AccessMask* | `str` |  |
> | *winlog__event_data__AccessMaskDescription* | `str` |  |
> | *winlog__event_data__AccessReason* | `str` |  |
> | *winlog__event_data__Action* | `str` |  |
> | *winlog__event_data__Active* | `str` |  |
> | *winlog__event_data__ActiveProfile* | `str` |  |
> | *winlog__event_data__AdditionalInfo2* | `str` |  |
> | *winlog__event_data__AdditionalInfo* | `str` |  |
> | *winlog__event_data__AdvancedOptions* | `str` |  |
> | *winlog__event_data__AlgorithmName* | `str` |  |
> | *winlog__event_data__ApplicationPath* | `str` |  |
> | *winlog__event_data__AuditPolicyChanges* | `str` |  |
> | *winlog__event_data__AuditSourceName* | `str` |  |
> | *winlog__event_data__AuthenticationPackageName* | `str` |  |
> | *winlog__event_data__CallerProcessId* | `str` |  |
> | *winlog__event_data__CallerProcessName* | `str` |  |
> | *winlog__event_data__CallingProcessCreateTime* | `str` |  |
> | *winlog__event_data__CallingProcessId* | `str` |  |
> | *winlog__event_data__CallingProcessProtection* | `str` |  |
> | *winlog__event_data__CallingProcessSectionSignatureLevel* | `str` |  |
> | *winlog__event_data__CallingProcessSignatureLevel* | `str` |  |
> | *winlog__event_data__CallingProcessStartKey* | `str` |  |
> | *winlog__event_data__CallingThreadCreateTime* | `str` |  |
> | *winlog__event_data__CallingThreadId* | `str` |  |
> | *winlog__event_data__CalloutKey* | `str` |  |
> | *winlog__event_data__CalloutName* | `str` |  |
> | *winlog__event_data__CategoryId* | `str` |  |
> | *winlog__event_data__ChangeType* | `str` |  |
> | *winlog__event_data__ChildCommandLine* | `str` |  |
> | *winlog__event_data__ChildCommandLineLength* | `str` |  |
> | *winlog__event_data__ChildImagePathName* | `str` |  |
> | *winlog__event_data__ChildImagePathNameLength* | `str` |  |
> | *winlog__event_data__ClassId* | `str` |  |
> | *winlog__event_data__ClassName* | `str` |  |
> | *winlog__event_data__ClientProcessId* | `str` |  |
> | *winlog__event_data__ClientProcessStartKey* | `str` |  |
> | *winlog__event_data__CommandLine* | `str` |  |
> | *winlog__event_data__CompatibleIds* | `str` |  |
> | *winlog__event_data__Conditions* | `str` |  |
> | *winlog__event_data__ConfigAccessPolicy* | `str` |  |
> | *winlog__event_data__DeviceDescription* | `str` |  |
> | *winlog__event_data__DeviceId* | `str` |  |
> | *winlog__event_data__Direction* | `str` |  |
> | *winlog__event_data__DisableIntegrityChecks* | `str` |  |
> | *winlog__event_data__EAPErrorCode* | `str` |  |
> | *winlog__event_data__EAPReasonCode* | `str` |  |
> | *winlog__event_data__EdgeTraversal* | `str` |  |
> | *winlog__event_data__ElevatedToken* | `str` |  |
> | *winlog__event_data__EmbeddedContext* | `str` |  |
> | *winlog__event_data__ErrorCode* | `str` |  |
> | *winlog__event_data__EventCountTotal* | `str` |  |
> | *winlog__event_data__EventIdx* | `str` |  |
> | *winlog__event_data__EventSourceId* | `str` |  |
> | *winlog__event_data__FQDN* | `str` |  |
> | *winlog__event_data__FailureReason* | `str` |  |
> | *winlog__event_data__FilterId* | `str` |  |
> | *winlog__event_data__FilterKey* | `str` |  |
> | *winlog__event_data__FilterName* | `str` |  |
> | *winlog__event_data__FilterType* | `str` |  |
> | *winlog__event_data__Flags* | `str` |  |
> | *winlog__event_data__FlightSigning* | `str` |  |
> | *winlog__event_data__GroupMembership* | `str` |  |
> | *winlog__event_data__GroupPolicyApplied* | `str` |  |
> | *winlog__event_data__HandleId* | `str` |  |
> | *winlog__event_data__HardwareIds* | `str` |  |
> | *winlog__event_data__HypervisorDebug* | `str` |  |
> | *winlog__event_data__HypervisorLaunchType* | `str` |  |
> | *winlog__event_data__HypervisorLoadOptions* | `str` |  |
> | *winlog__event_data__Identity* | `str` |  |
> | *winlog__event_data__ImageName* | `str` |  |
> | *winlog__event_data__ImageNameLength* | `str` |  |
> | *winlog__event_data__ImpersonationLevel* | `str` |  |
> | *winlog__event_data__InterfaceName* | `str` |  |
> | *winlog__event_data__IntfGuid* | `str` |  |
> | *winlog__event_data__IpAddress* | `ip4` |  |
> | *winlog__event_data__IpPort* | `str` |  |
> | *winlog__event_data__KernelDebug* | `str` |  |
> | *winlog__event_data__KeyFilePath* | `str` |  |
> | *winlog__event_data__KeyLength* | `str` |  |
> | *winlog__event_data__KeyName* | `str` |  |
> | *winlog__event_data__KeyType* | `str` |  |
> | *winlog__event_data__LayerId* | `str` |  |
> | *winlog__event_data__LayerKey* | `str` |  |
> | *winlog__event_data__LayerName* | `str` |  |
> | *winlog__event_data__LmPackageName* | `str` |  |
> | *winlog__event_data__LoadOptions* | `str` |  |
> | *winlog__event_data__LocalAddresses* | `str` |  |
> | *winlog__event_data__LocalMac* | `str` |  |
> | *winlog__event_data__LocalOnlyMapped* | `str` |  |
> | *winlog__event_data__LocalPorts* | `str` |  |
> | *winlog__event_data__LocationInformation* | `str` |  |
> | *winlog__event_data__LogDroppedPacketsEnabled* | `str` |  |
> | *winlog__event_data__LogSuccessfulConnectionsEnabled* | `str` |  |
> | *winlog__event_data__LogonGuid* | `str` |  |
> | *winlog__event_data__LogonProcessName* | `str` |  |
> | *winlog__event_data__LogonType* | `str` |  |
> | *winlog__event_data__LooseSourceMapped* | `str` |  |
> | *winlog__event_data__MandatoryLabel* | `str` |  |
> | *winlog__event_data__MemberName* | `str` |  |
> | *winlog__event_data__ModifyingApplication* | `str` |  |
> | *winlog__event_data__ModifyingUser* | `str` |  |
> | *winlog__event_data__MulticastFlowsEnabled* | `str` |  |
> | *winlog__event_data__NewProcessId* | `str` |  |
> | *winlog__event_data__NewProcessName* | `str` |  |
> | *winlog__event_data__NewSd* | `str` |  |
> | *winlog__event_data__NewState* | `str` |  |
> | *winlog__event_data__NewTime* | `str` |  |
> | *winlog__event_data__NewValue* | `str` |  |
> | *winlog__event_data__NewValueType* | `str` |  |
> | *winlog__event_data__NotificationPackageName* | `str` |  |
> | *winlog__event_data__ObjectName* | `str` |  |
> | *winlog__event_data__ObjectServer* | `str` |  |
> | *winlog__event_data__ObjectType* | `str` |  |
> | *winlog__event_data__ObjectValueName* | `str` |  |
> | *winlog__event_data__OldSd* | `str` |  |
> | *winlog__event_data__OldValue* | `str` |  |
> | *winlog__event_data__OldValueType* | `str` |  |
> | *winlog__event_data__Operation* | `str` |  |
> | *winlog__event_data__OperationMode* | `str` |  |
> | *winlog__event_data__OperationType* | `str` |  |
> | *winlog__event_data__Origin* | `str` |  |
> | *winlog__event_data__PackageName* | `str` |  |
> | *winlog__event_data__ParentProcessId* | `str` |  |
> | *winlog__event_data__ParentProcessName* | `str` |  |
> | *winlog__event_data__PeerMac* | `str` |  |
> | *winlog__event_data__PreAuthType* | `str` |  |
> | *winlog__event_data__PreviousTime* | `str` |  |
> | *winlog__event_data__PrivilegeList* | `str` |  |
> | *winlog__event_data__ProcessCommandLine* | `str` |  |
> | *winlog__event_data__ProcessCommandLineLength* | `str` |  |
> | *winlog__event_data__ProcessCreateTime* | `str` |  |
> | *winlog__event_data__ProcessId* | `str` |  |
> | *winlog__event_data__ProcessName* | `str` |  |
> | *winlog__event_data__ProcessPath* | `str` |  |
> | *winlog__event_data__ProcessPathLength* | `str` |  |
> | *winlog__event_data__ProcessProtection* | `str` |  |
> | *winlog__event_data__ProcessSectionSignatureLevel* | `str` |  |
> | *winlog__event_data__ProcessSignatureLevel* | `str` |  |
> | *winlog__event_data__ProcessStartKey* | `str` |  |
> | *winlog__event_data__Profile* | `str` |  |
> | *winlog__event_data__ProfileChanged* | `str` |  |
> | *winlog__event_data__ProfileUsed* | `str` |  |
> | *winlog__event_data__Profiles* | `str` |  |
> | *winlog__event_data__Properties* | `str` |  |
> | *winlog__event_data__Protocol* | `str` |  |
> | *winlog__event_data__ProviderKey* | `str` |  |
> | *winlog__event_data__ProviderName* | `str` |  |
> | *winlog__event_data__PuaCount* | `str` |  |
> | *winlog__event_data__PuaPolicyId* | `str` |  |
> | *winlog__event_data__ReasonCode* | `str` |  |
> | *winlog__event_data__ReasonForRejection* | `str` |  |
> | *winlog__event_data__ReasonText* | `str` |  |
> | *winlog__event_data__RelativeTargetName* | `str` |  |
> | *winlog__event_data__RemoteAddresses* | `str` |  |
> | *winlog__event_data__RemoteAdminEnabled* | `str` |  |
> | *winlog__event_data__RemoteEventLogging* | `str` |  |
> | *winlog__event_data__RemotePorts* | `str` |  |
> | *winlog__event_data__RequiredSignatureLevel* | `str` |  |
> | *winlog__event_data__ResourceManager* | `str` |  |
> | *winlog__event_data__RestrictedAdminMode* | `str` |  |
> | *winlog__event_data__ReturnCode* | `str` |  |
> | *winlog__event_data__RpcCallClientLocality* | `str` |  |
> | *winlog__event_data__RuleAttr* | `str` |  |
> | *winlog__event_data__RuleId* | `str` |  |
> | *winlog__event_data__RuleName* | `str` |  |
> | *winlog__event_data__RuleStatus* | `str` |  |
> | *winlog__event_data__SSID* | `str` |  |
> | *winlog__event_data__SchemaVersion* | `str` |  |
> | *winlog__event_data__SecurityOptions* | `str` |  |
> | *winlog__event_data__SecurityPackageName* | `str` |  |
> | *winlog__event_data__ServiceAccount* | `str` |  |
> | *winlog__event_data__ServiceFileName* | `str` |  |
> | *winlog__event_data__ServiceName* | `str` |  |
> | *winlog__event_data__ServiceSid* | `str` |  |
> | *winlog__event_data__ServiceStartType* | `str` |  |
> | *winlog__event_data__ServiceType* | `str` |  |
> | *winlog__event_data__ShareLocalPath* | `str` |  |
> | *winlog__event_data__ShareName* | `str` |  |
> | *winlog__event_data__SignatureLevel* | `str` |  |
> | *winlog__event_data__Status* | `str` |  |
> | *winlog__event_data__SubStatus* | `str` |  |
> | *winlog__event_data__SubcategoryGuid* | `str` |  |
> | *winlog__event_data__SubcategoryId* | `str` |  |
> | *winlog__event_data__SubjectDomainName* | `str` |  |
> | *winlog__event_data__SubjectLogonId* | `str` |  |
> | *winlog__event_data__SubjectUserName* | `str` |  |
> | *winlog__event_data__SubjectUserSid* | `str` |  |
> | *winlog__event_data__TargetDomainName* | `str` |  |
> | *winlog__event_data__TargetInfo* | `str` |  |
> | *winlog__event_data__TargetLinkedLogonId* | `str` |  |
> | *winlog__event_data__TargetLogonGuid* | `str` |  |
> | *winlog__event_data__TargetLogonId* | `str` |  |
> | *winlog__event_data__TargetOutboundDomainName* | `str` |  |
> | *winlog__event_data__TargetOutboundUserName* | `str` |  |
> | *winlog__event_data__TargetServerName* | `str` |  |
> | *winlog__event_data__TargetSid* | `str` |  |
> | *winlog__event_data__TargetThreadCreateTime* | `str` |  |
> | *winlog__event_data__TargetThreadId* | `str` |  |
> | *winlog__event_data__TargetUserName* | `str` |  |
> | *winlog__event_data__TargetUserSid* | `str` |  |
> | *winlog__event_data__TaskContent* | `str` |  |
> | *winlog__event_data__TaskContentNew* | `str` |  |
> | *winlog__event_data__TaskName* | `str` |  |
> | *winlog__event_data__TestSigning* | `str` |  |
> | *winlog__event_data__TicketEncryptionType* | `str` |  |
> | *winlog__event_data__TicketOptions* | `str` |  |
> | *winlog__event_data__TokenElevationType* | `str` |  |
> | *winlog__event_data__TransactionId* | `str` |  |
> | *winlog__event_data__TransmittedServices* | `str` |  |
> | *winlog__event_data__UserName* | `str` |  |
> | *winlog__event_data__UserSid* | `str` |  |
> | *winlog__event_data__VendorIds* | `str` |  |
> | *winlog__event_data__VirtualAccount* | `str` |  |
> | *winlog__event_data__VsmLaunchType* | `str` |  |
> | *winlog__event_data__Weight* | `str` |  |
> | *winlog__event_data__Workstation* | `str` |  |
> | *winlog__event_data__WorkstationName* | `str` |  |
> | *winlog__event_data__param1* | `str` |  |
> | *winlog__event_data__DestIp* | `str` |  |
> | *winlog__event_data__DestPort* | `str` |  |
> | *winlog__event_data__LayerRTID* | `str` |  |
> | *winlog__event_data__AttributeValue* | `str` |  |
> | *winlog__event_data__AttributeLDAPDisplayName* | `str` |  |
> | *winlog__event_data__SamAccountName* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__logon__failure__reason* | `str` |  |
> | *winlog__logon__failure__status* | `str` |  |
> | *winlog__logon__failure__sub_status* | `str` |  |
> | *winlog__logon__id* | `str` |  |
> | *winlog__logon__type* | `str` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *base_name* | `str` |  |
> | *domain_name* | `str` |  |
> | *log_name* | `str` |  |
> | *logcollector* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.securityMitigations
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__CallingProcessCreateTime* | `str` |  |
> | *winlog__event_data__CallingProcessId* | `str` |  |
> | *winlog__event_data__CallingProcessProtection* | `str` |  |
> | *winlog__event_data__CallingProcessSectionSignatureLevel* | `str` |  |
> | *winlog__event_data__CallingProcessSignatureLevel* | `str` |  |
> | *winlog__event_data__CallingProcessStartKey* | `str` |  |
> | *winlog__event_data__CallingThreadCreateTime* | `str` |  |
> | *winlog__event_data__CallingThreadId* | `str` |  |
> | *winlog__event_data__ChildCommandLine* | `str` |  |
> | *winlog__event_data__ChildCommandLineLength* | `str` |  |
> | *winlog__event_data__ChildImagePathName* | `str` |  |
> | *winlog__event_data__ChildImagePathNameLength* | `str` |  |
> | *winlog__event_data__ImageName* | `str` |  |
> | *winlog__event_data__ImageNameLength* | `str` |  |
> | *winlog__event_data__ProcessCommandLine* | `str` |  |
> | *winlog__event_data__ProcessCommandLineLength* | `str` |  |
> | *winlog__event_data__ProcessCreateTime* | `str` |  |
> | *winlog__event_data__ProcessId* | `str` |  |
> | *winlog__event_data__ProcessPath* | `str` |  |
> | *winlog__event_data__ProcessPathLength* | `str` |  |
> | *winlog__event_data__ProcessProtection* | `str` |  |
> | *winlog__event_data__ProcessSectionSignatureLevel* | `str` |  |
> | *winlog__event_data__ProcessSignatureLevel* | `str` |  |
> | *winlog__event_data__ProcessStartKey* | `str` |  |
> | *winlog__event_data__RequiredSignatureLevel* | `str` |  |
> | *winlog__event_data__SignatureLevel* | `str` |  |
> | *winlog__event_data__TargetThreadCreateTime* | `str` |  |
> | *winlog__event_data__TargetThreadId* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> > Macro (rw-tab)
> 
> - [box.win_winlogbeat.setup](#tag16)
> - [box.win_winlogbeat.smb](#tag17)
> - [box.win_winlogbeat.sysmon](#tag18)
> - [box.win_winlogbeat.system](#tag19)
> - [box.win_winlogbeat.taskscheduler](#tag20)
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.setup
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *winlog__user_data__Client* | `str` |  |
> | *winlog__user_data__ErrorCode* | `str` |  |
> | *winlog__user_data__IntendedPackageState* | `str` |  |
> | *winlog__user_data__PackageIdentifier* | `str` |  |
> | *winlog__user_data__xml_name* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.smb
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *log__level* | `str` |  |
> | *agent__ephemeral_id* | `str` |  |
> | *agent__name* | `str` |  |
> | *agent__type* | `str` |  |
> | *agent__id* | `str` |  |
> | *agent__hostname* | `str` |  |
> | *agent__version* | `str` |  |
> | *event__created* | `timestamp` |  |
> | *event__kind* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__provider* | `str` |  |
> | *ecs__version* | `str` |  |
> | *at_timestamp* | `timestamp` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__id* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__architecture* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__os__platform* | `str` |  |
> | *host__os__name* | `str` |  |
> | *host__os__build* | `str` |  |
> | *host__os__type* | `str` |  |
> | *host__os__version* | `str` |  |
> | *host__os__family* | `str` |  |
> | *host__os__kernel* | `str` |  |
> | *fields__log_type* | `str` |  |
> | *fields__winlogbeatymlversion* | `timestamp` |  |
> | *tags* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__task* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__api* | `str` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__event_data__RegValue* | `str` |  |
> | *winlog__event_data__RegName* | `str` |  |
> | *winlog__event_data__Status* | `str` |  |
> | *winlog__event_data__ServerName* | `str` |  |
> | *winlog__event_data__Reason* | `str` |  |
> | *winlog__event_data__ServerNameLength* | `str` |  |
> | *message* | `str` |  |
> | *at_version* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.sysmon
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *event__action* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *event__original* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__CommandLine* | `str` |  |
> | *winlog__event_data__Company* | `str` |  |
> | *winlog__event_data__CreationUtcTime* | `str` |  |
> | *winlog__event_data__CurrentDirectory* | `str` |  |
> | *winlog__event_data__Description* | `str` |  |
> | *winlog__event_data__Details* | `str` |  |
> | *winlog__event_data__EventType* | `str` |  |
> | *winlog__event_data__FileVersion* | `ip4` |  |
> | *winlog__event_data__Image* | `str` |  |
> | *winlog__event_data__IntegrityLevel* | `str` |  |
> | *winlog__event_data__LogonGuid* | `str` |  |
> | *winlog__event_data__LogonId* | `str` |  |
> | *winlog__event_data__OriginalFileName* | `str` |  |
> | *winlog__event_data__ParentCommandLine* | `str` |  |
> | *winlog__event_data__ParentImage* | `str` |  |
> | *winlog__event_data__ParentProcessGuid* | `str` |  |
> | *winlog__event_data__ParentProcessId* | `str` |  |
> | *winlog__event_data__ProcessGuid* | `str` |  |
> | *winlog__event_data__ProcessId* | `str` |  |
> | *winlog__event_data__Product* | `str` |  |
> | *winlog__event_data__QueryName* | `str` |  |
> | *winlog__event_data__QueryResults* | `str` |  |
> | *winlog__event_data__QueryStatus* | `str` |  |
> | *winlog__event_data__RuleName* | `str` |  |
> | *winlog__event_data__SchemaVersion* | `str` |  |
> | *winlog__event_data__State* | `str` |  |
> | *winlog__event_data__TargetFilename* | `str` |  |
> | *winlog__event_data__TargetObject* | `str` |  |
> | *winlog__event_data__TerminalSessionId* | `str` |  |
> | *winlog__event_data__User* | `str` |  |
> | *winlog__event_data__UtcTime* | `str` |  |
> | *winlog__event_data__Version* | `str` |  |
> | *winlog__event_data__Signature* | `str` |  |
> | *winlog__event_data__Initiated* | `str` |  |
> | *winlog__event_data__ParentUser* | `str` |  |
> | *winlog__event_data__SourceIp* | `str` |  |
> | *winlog__event_data__SourceIsIpv6* | `str` |  |
> | *winlog__event_data__SourcePort* | `str` |  |
> | *winlog__event_data__SourcePortName* | `str` |  |
> | *winlog__event_data__SourceHostname* | `str` |  |
> | *winlog__event_data__DestinationIp* | `str` |  |
> | *winlog__event_data__DestinationIsIpv6* | `str` |  |
> | *winlog__event_data__DestinationPort* | `str` |  |
> | *winlog__event_data__DestinationPortName* | `str` |  |
> | *winlog__event_data__DestinationHostname* | `str` |  |
> | *winlog__event_data__Protocol* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *tags* | `str` |  |
> | *base_name* | `str` |  |
> | *domain_name* | `str` |  |
> | *log_name* | `str` |  |
> | *logcollector* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *at_version* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.system
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__action* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *event__original* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__activity_id* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__AccountName* | `str` |  |
> | *winlog__event_data__AdapterName* | `str` |  |
> | *winlog__event_data__AdapterSuffixName* | `str` |  |
> | *winlog__event_data__BitlockerUserInputTime* | `str` |  |
> | *winlog__event_data__BootAppStatus* | `str` |  |
> | *winlog__event_data__BootMenuPolicy* | `str` |  |
> | *winlog__event_data__BootMode* | `str` |  |
> | *winlog__event_data__BugcheckCode* | `str` |  |
> | *winlog__event_data__BugcheckInfoFromEFI* | `str` |  |
> | *winlog__event_data__BugcheckParameter1* | `str` |  |
> | *winlog__event_data__BugcheckParameter2* | `str` |  |
> | *winlog__event_data__BugcheckParameter3* | `str` |  |
> | *winlog__event_data__BugcheckParameter4* | `str` |  |
> | *winlog__event_data__BuildVersion* | `str` |  |
> | *winlog__event_data__Caption* | `str` |  |
> | *winlog__event_data__Checkpoint* | `str` |  |
> | *winlog__event_data__CheckpointStatus* | `str` |  |
> | *winlog__event_data__ConnectedStandbyInProgress* | `str` |  |
> | *winlog__event_data__CorruptionActionState* | `str` |  |
> | *winlog__event_data__CsEntryScenarioInstanceId* | `str` |  |
> | *winlog__event_data__CsEntryScenarioInstanceIdV2* | `str` |  |
> | *winlog__event_data__DCName* | `str` |  |
> | *winlog__event_data__Default_SD_String_* | `str` |  |
> | *winlog__event_data__DeviceName* | `str` |  |
> | *winlog__event_data__DeviceNameLength* | `str` |  |
> | *winlog__event_data__DeviceTime* | `str` |  |
> | *winlog__event_data__DeviceVersionMajor* | `str` |  |
> | *winlog__event_data__DeviceVersionMinor* | `str` |  |
> | *winlog__event_data__DirtyPages* | `str` |  |
> | *winlog__event_data__DnsServerList* | `str` |  |
> | *winlog__event_data__DriveName* | `str` |  |
> | *winlog__event_data__DriverName* | `str` |  |
> | *winlog__event_data__DriverNameLength* | `str` |  |
> | *winlog__event_data__EnableDisableReason* | `str` |  |
> | *winlog__event_data__EntryCount* | `str` |  |
> | *winlog__event_data__Error* | `str` |  |
> | *winlog__event_data__ErrorCode* | `str` |  |
> | *winlog__event_data__ErrorDescription* | `str` |  |
> | *winlog__event_data__ErrorState* | `str` |  |
> | *winlog__event_data__ExtraInfoLength* | `str` |  |
> | *winlog__event_data__ExtraInfoString* | `str` |  |
> | *winlog__event_data__FailureName* | `str` |  |
> | *winlog__event_data__FailureNameLength* | `str` |  |
> | *winlog__event_data__FilePath* | `str` |  |
> | *winlog__event_data__FilterID* | `str` |  |
> | *winlog__event_data__FinalStatus* | `str` |  |
> | *winlog__event_data__GPOCNName* | `str` |  |
> | *winlog__event_data__Group* | `str` |  |
> | *winlog__event_data__HiveName* | `str` |  |
> | *winlog__event_data__HiveNameLength* | `str` |  |
> | *winlog__event_data__HostName* | `str` |  |
> | *winlog__event_data__IdleImplementation* | `str` |  |
> | *winlog__event_data__IdleStateCount* | `str` |  |
> | *winlog__event_data__ImagePath* | `str` |  |
> | *winlog__event_data__Ipaddress* | `ip4` |  |
> | *winlog__event_data__KeysUpdated* | `str` |  |
> | *winlog__event_data__LastBootGood* | `str` |  |
> | *winlog__event_data__LastShutdownGood* | `str` |  |
> | *winlog__event_data__LongPowerButtonPressDetected* | `str` |  |
> | *winlog__event_data__MajorVersion* | `str` |  |
> | *winlog__event_data__MaximumPerformancePercent* | `str` |  |
> | *winlog__event_data__Message* | `str` |  |
> | *winlog__event_data__MinimumPasswordLength* | `str` |  |
> | *winlog__event_data__MinimumPasswordLengthAudit* | `str` |  |
> | *winlog__event_data__MinimumPerformancePercent* | `str` |  |
> | *winlog__event_data__MinimumThrottlePercent* | `str` |  |
> | *winlog__event_data__MinorVersion* | `str` |  |
> | *winlog__event_data__NTSTATUS* | `str` |  |
> | *winlog__event_data__NewTime* | `str` |  |
> | *winlog__event_data__NominalFrequency* | `str` |  |
> | *winlog__event_data__Number* | `str` |  |
> | *winlog__event_data__OldTime* | `str` |  |
> | *winlog__event_data__PerformanceImplementation* | `str` |  |
> | *winlog__event_data__PowerButtonTimestamp* | `str` |  |
> | *winlog__event_data__ProcessingMode* | `str` |  |
> | *winlog__event_data__ProcessingTimeInMilliseconds* | `str` |  |
> | *winlog__event_data__QfeVersion* | `str` |  |
> | *winlog__event_data__Reason* | `str` |  |
> | *winlog__event_data__Sent_UpdateServer* | `str` |  |
> | *winlog__event_data__ServiceName* | `str` |  |
> | *winlog__event_data__ServiceType* | `str` |  |
> | *winlog__event_data__ServiceVersion* | `str` |  |
> | *winlog__event_data__ShutdownActionType* | `str` |  |
> | *winlog__event_data__ShutdownEventCode* | `str` |  |
> | *winlog__event_data__ShutdownReason* | `str` |  |
> | *winlog__event_data__SleepInProgress* | `str` |  |
> | *winlog__event_data__SourceFileID* | `str` |  |
> | *winlog__event_data__SourceLine* | `str` |  |
> | *winlog__event_data__SourceTag* | `str` |  |
> | *winlog__event_data__StartTime* | `str` |  |
> | *winlog__event_data__StartType* | `str` |  |
> | *winlog__event_data__State* | `str` |  |
> | *winlog__event_data__Status* | `str` |  |
> | *winlog__event_data__StopTime* | `str` |  |
> | *winlog__event_data__SupportInfo1* | `str` |  |
> | *winlog__event_data__SupportInfo2* | `str` |  |
> | *winlog__event_data__SystemSleepTransitionsToOn* | `str` |  |
> | *winlog__event_data__TSId* | `str` |  |
> | *winlog__event_data__TimeSource* | `str` |  |
> | *winlog__event_data__Type* | `str` |  |
> | *winlog__event_data__UserSid* | `str` |  |
> | *winlog__event_data__Version* | `str` |  |
> | *winlog__event_data__VolumeId* | `str` |  |
> | *winlog__event_data__VolumeName* | `str` |  |
> | *winlog__event_data__VsmPolicy* | `str` |  |
> | *winlog__event_data__param1* | `str` |  |
> | *winlog__event_data__param2* | `str` |  |
> | *winlog__event_data__param3* | `str` |  |
> | *winlog__event_data__param4* | `str` |  |
> | *winlog__event_data__param5* | `str` |  |
> | *winlog__event_data__param6* | `str` |  |
> | *winlog__event_data__param7* | `str` |  |
> | *winlog__event_data__param8* | `str` |  |
> | *winlog__event_data__param9* | `str` |  |
> | *winlog__event_data__param10* | `str` |  |
> | *winlog__event_data__param11* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *winlog__user_data__AddServiceStatus* | `str` |  |
> | *winlog__user_data__DeviceInstanceID* | `str` |  |
> | *winlog__user_data__DriverFileName* | `str` |  |
> | *winlog__user_data__PrimaryService* | `str` |  |
> | *winlog__user_data__ServiceName* | `str` |  |
> | *winlog__user_data__UpdateService* | `str` |  |
> | *winlog__user_data__xml_name* | `str` |  |
> | *base_name* | `str` |  |
> | *domain_name* | `str` |  |
> | *log_name* | `str` |  |
> | *logcollector* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.taskscheduler
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__action* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__activity_id* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__ActionName* | `str` |  |
> | *winlog__event_data__EnginePID* | `str` |  |
> | *winlog__event_data__Path* | `str` |  |
> | *winlog__event_data__Priority* | `str` |  |
> | *winlog__event_data__ProcessID* | `str` |  |
> | *winlog__event_data__ResultCode* | `str` |  |
> | *winlog__event_data__TaskInstanceId* | `str` |  |
> | *winlog__event_data__TaskName* | `str` |  |
> | *winlog__event_data__UserContext* | `str` |  |
> | *winlog__event_data__UserName* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> > Macro (rw-tab)
> 
> - [box.win_winlogbeat.terminalservices](#tag21)
> - [box.win_winlogbeat.win32k](#tag22)
> - [box.win_winlogbeat.windows_defender](#tag23)
> - [box.win_winlogbeat.windows_firewall](#tag24)
> - [box.win_winlogbeat.windowsupdateclient](#tag25)
> - [box.win_winlogbeat.wmiActivity](#tag26)
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.terminalservices
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__activity_id* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__Param1* | `str` |  |
> | *winlog__event_data__Param2* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.win32k
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__activity_id* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__Blocked* | `str` |  |
> | *winlog__event_data__FontSourcePath* | `str` |  |
> | *winlog__event_data__SourceProcessName* | `str` |  |
> | *winlog__event_data__SourceType* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.windows_defender
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__activity_id* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__Action_ID* | `str` |  |
> | *winlog__event_data__Action_Name* | `str` |  |
> | *winlog__event_data__Additional_Actions_ID* | `str` |  |
> | *winlog__event_data__Additional_Actions_String* | `str` |  |
> | *winlog__event_data__Category_ID* | `str` |  |
> | *winlog__event_data__Category_Name* | `str` |  |
> | *winlog__event_data__Detection_ID* | `str` |  |
> | *winlog__event_data__Detection_Time* | `str` |  |
> | *winlog__event_data__Detection_User* | `str` |  |
> | *winlog__event_data__Engine_Version* | `str` |  |
> | *winlog__event_data__Error_Code* | `str` |  |
> | *winlog__event_data__Error_Description* | `str` |  |
> | *winlog__event_data__Execution_ID* | `str` |  |
> | *winlog__event_data__Execution_Name* | `str` |  |
> | *winlog__event_data__FWLink* | `str` |  |
> | *winlog__event_data__New_Value* | `str` |  |
> | *winlog__event_data__Old_Value* | `str` |  |
> | *winlog__event_data__Origin_ID* | `str` |  |
> | *winlog__event_data__Origin_Name* | `str` |  |
> | *winlog__event_data__Path* | `str` |  |
> | *winlog__event_data__Post_Clean_Status* | `str` |  |
> | *winlog__event_data__Pre_Execution_Status* | `str` |  |
> | *winlog__event_data__Process_Name* | `str` |  |
> | *winlog__event_data__Product_Name* | `str` |  |
> | *winlog__event_data__Product_Version* | `str` |  |
> | *winlog__event_data__Remediation_User* | `str` |  |
> | *winlog__event_data__Security_intelligence_Version* | `str` |  |
> | *winlog__event_data__Severity_ID* | `str` |  |
> | *winlog__event_data__Severity_Name* | `str` |  |
> | *winlog__event_data__Source_ID* | `str` |  |
> | *winlog__event_data__Source_Name* | `str` |  |
> | *winlog__event_data__State* | `str` |  |
> | *winlog__event_data__Status_Code* | `str` |  |
> | *winlog__event_data__Threat_ID* | `str` |  |
> | *winlog__event_data__Threat_Name* | `str` |  |
> | *winlog__event_data__Type_ID* | `str` |  |
> | *winlog__event_data__Type_Name* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.windows_firewall
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__activity_id* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__Action* | `str` |  |
> | *winlog__event_data__Active* | `str` |  |
> | *winlog__event_data__ApplicationPath* | `str` |  |
> | *winlog__event_data__Direction* | `str` |  |
> | *winlog__event_data__EdgeTraversal* | `str` |  |
> | *winlog__event_data__EmbeddedContext* | `str` |  |
> | *winlog__event_data__Flags* | `str` |  |
> | *winlog__event_data__LocalAddresses* | `str` |  |
> | *winlog__event_data__LocalOnlyMapped* | `str` |  |
> | *winlog__event_data__LocalPorts* | `str` |  |
> | *winlog__event_data__LooseSourceMapped* | `str` |  |
> | *winlog__event_data__ModifyingApplication* | `str` |  |
> | *winlog__event_data__ModifyingUser* | `str` |  |
> | *winlog__event_data__Origin* | `str` |  |
> | *winlog__event_data__Profiles* | `str` |  |
> | *winlog__event_data__Protocol* | `str` |  |
> | *winlog__event_data__RemoteAddresses* | `str` |  |
> | *winlog__event_data__RemotePorts* | `str` |  |
> | *winlog__event_data__RuleId* | `str` |  |
> | *winlog__event_data__RuleName* | `str` |  |
> | *winlog__event_data__RuleStatus* | `str` |  |
> | *winlog__event_data__SchemaVersion* | `str` |  |
> | *winlog__event_data__SecurityOptions* | `str` |  |
> | *winlog__event_data__ServiceName* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.windowsupdateclient
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__action* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__activity_id* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_data__errorCode* | `str` |  |
> | *winlog__event_data__serviceGuid* | `str` |  |
> | *winlog__event_data__updateGuid* | `str` |  |
> | *winlog__event_data__updateRevisionNumber* | `str` |  |
> | *winlog__event_data__updateTitle* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> box.win_winlogbeat.wmiActivity
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *at_timestamp* | `str` |  |
> | *event__code* | `int4` |  |
> | *event__created* | `str` |  |
> | *event__kind* | `str` |  |
> | *event__provider* | `str` |  |
> | *host__hostname* | `str` |  |
> | *host__id* | `str` |  |
> | *host__ip* | `str` |  |
> | *host__mac* | `str` |  |
> | *host__name* | `str` |  |
> | *host__os__name* | `str` |  |
> | *log__level* | `str` |  |
> | *message* | `str` |  |
> | *winlog__activity_id* | `str` |  |
> | *winlog__channel* | `str` |  |
> | *winlog__computer_name* | `str` |  |
> | *winlog__event_id* | `int4` |  |
> | *winlog__opcode* | `str` |  |
> | *winlog__process__pid* | `int4` |  |
> | *winlog__process__thread__id* | `int4` |  |
> | *winlog__provider_guid* | `str` |  |
> | *winlog__provider_name* | `str` |  |
> | *winlog__record_id* | `int8` |  |
> | *winlog__task* | `str` |  |
> | *winlog__user__domain* | `str` |  |
> | *winlog__user__identifier* | `str` |  |
> | *winlog__user__name* | `str` |  |
> | *winlog__user__type* | `str` |  |
> | *winlog__user_data__CONSUMER* | `str` |  |
> | *winlog__user_data__ClientMachine* | `str` |  |
> | *winlog__user_data__ClientProcessId* | `str` |  |
> | *winlog__user_data__Code* | `str` |  |
> | *winlog__user_data__Component* | `str` |  |
> | *winlog__user_data__ESS* | `str` |  |
> | *winlog__user_data__HostProcess* | `str` |  |
> | *winlog__user_data__Id* | `str` |  |
> | *winlog__user_data__Namespace* | `str` |  |
> | *winlog__user_data__NamespaceName* | `str` |  |
> | *winlog__user_data__Operation* | `str` |  |
> | *winlog__user_data__PossibleCause* | `str` |  |
> | *winlog__user_data__ProcessID* | `str` |  |
> | *winlog__user_data__Processid* | `str` |  |
> | *winlog__user_data__ProviderName* | `str` |  |
> | *winlog__user_data__ProviderPath* | `str` |  |
> | *winlog__user_data__Query* | `str` |  |
> | *winlog__user_data__ResultCode* | `str` |  |
> | *winlog__user_data__User* | `str` |  |
> | *winlog__user_data__xml_name* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |