All events from provider "Microsoft-Windows-Security-Auditing" contain the same common value for winlog.task instead of the value matching the corresponding winlog.event_id.
The logged value changes occasionally (few days).
The incorrect behaviour has been observed with Windows Server 2025 (we tried winlogbeat versions 8.0.1 and 8.17.10 and the problem exists regardless of the winlogbeat version)
In the same environment, Windows Server 2019 along with winlogbeat agent 8.0.1 works fine.