Skip to content

Winlogbeat reporting incorrect winlog.task on Windows Server 2025 #49242

@schlitte

Description

@schlitte

All events from provider "Microsoft-Windows-Security-Auditing" contain the same common value for winlog.task instead of the value matching the corresponding winlog.event_id.
The logged value changes occasionally (few days).

The incorrect behaviour has been observed with Windows Server 2025 (we tried winlogbeat versions 8.0.1 and 8.17.10 and the problem exists regardless of the winlogbeat version)
In the same environment, Windows Server 2019 along with winlogbeat agent 8.0.1 works fine.

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs_teamIndicates that the issue/PR needs a Team:* label

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions