L-Flow›Agents›Windows fields

ฟิลด์ของ Windows

Windows agent อ่าน Event Log แล้วส่งค่าใน EventData ของแต่ละ event มาเป็นฟิลด์แยก L-Flow แปลงฟิลด์ที่สำคัญเป็นชื่อ ECS และตั้ง event.action ตาม Event ID ฟิลด์ EventData ที่ไม่ได้แปลงจะถูกเก็บด้วยชื่อเดิมของ Windows เช่น SubjectDomainName, LogonId

ตัวอย่าง

Event 4625 (logon ไม่สำเร็จ) จาก Security log หลังแปลงแล้ว จะเห็นใน Explore เป็น:

timestamp               2026-09-24T03:15:32.1234567Z
vendor                  windows
devid                   windows-3f9a1c7e2b8d4e6fa1b2c3d4e5f60718
type                    auth
severity                high
winlog.channel          Security
winlog.provider_name    Microsoft-Windows-Security-Auditing
winlog.record_id        884213
event.code              4625
event.action            logon_failed
event.outcome           failure
host.hostname           FIN-PC07.corp.example.com
user.name               jdoe
user.domain             CORP
source.ip               203.0.113.50
source.port             51122
source.domain           ATTACKER-PC
winlog.logon.type       3
message                 Microsoft-Windows-Security-Auditing event 4625 (Failure)

ฟิลด์ที่มีในทุก event

ฟิลด์ ECSมาจากความหมาย
timestampTimeCreatedเวลาที่ Windows บันทึก event เป็น UTC
vendor—ค่าคงที่ windows
devidagentรหัสเครื่องที่ได้ตอนลงทะเบียน agent รูปแบบ windows- ตามด้วย machine ID ไม่ใช่ hostname
typeChannelหมวดของ event ดู ค่าของ type
winlog.channelChannelชื่อ log เช่น Security, Microsoft-Windows-Sysmon/Operational
winlog.provider_nameProviderโปรแกรมที่เขียน event
event.codeEventIDEvent ID ของ Windows
winlog.record_idEventRecordIDลำดับของ event ใน log นั้น
host.hostnameComputerชื่อเครื่องตามที่ Windows บันทึก
event.outcomeKeywordssuccess หรือ failure (Audit Success / Audit Failure) มีเฉพาะ event ประเภท audit
severityLevelระดับความรุนแรง ดู severity
event.actionEvent IDสิ่งที่เกิดขึ้น ดูแต่ละหัวข้อด้านล่าง
message—สรุปสั้น Provider event EventID (Outcome) ไม่ใช่ข้อความที่ Event Viewer แสดง

ค่าของ type

typeChannel
authSecurity, Microsoft-Windows-TerminalServices-*
systemSystem, Directory Service, DFS Replication, Microsoft-Windows-DNS-Server/*
appApplication
antivirusMicrosoft-Windows-Windows Defender/Operational
wineventchannel อื่นทั้งหมด เช่น Sysmon, PowerShell, WMI-Activity, Task Scheduler, Windows Firewall
Note:event ของ Sysmon อยู่ใน type:winevent ค้นด้วย winlog.channel:"Microsoft-Windows-Sysmon/Operational" หรือด้วย event.action เช่น event.action:network_connection

severity

severityLevel ของ Windows
criticalCritical
highError
mediumWarning
informationInformation, Verbose

event ใน Security log เป็น Level Information เสมอ แม้เป็น Audit Failure L-Flow จึงปรับ event ที่ event.outcome เป็น failure ให้เป็น high และการปิด Windows Defender (5001, 5010, 5012) เป็น high เสมอ

Security log

Logon

Event IDevent.actionฟิลด์ที่ได้
4624logon_successuser.name, user.domain, source.ip, source.port, source.domain (ชื่อเครื่องต้นทาง), winlog.logon.type
4625logon_failedเหมือน 4624
4634, 4647logoffuser.name
4672privileged_logonuser.name (บัญชีที่ได้สิทธิ์ผู้ดูแลตอน logon)
4740account_lockeduser.name
4776ntlm_authuser.name, source.domain

winlog.logon.type คือวิธี logon: 2 ที่หน้าเครื่อง, 3 ผ่านเครือข่าย (เช่น แชร์ไฟล์), 4 batch, 5 service, 7 ปลดล็อกหน้าจอ, 10 RDP, 11 cached credential

Process

Event IDevent.actionฟิลด์ที่ได้
4688process_startprocess.executable, process.command_line, process.parent.executable, user.name
4689process_endprocess.executable, user.name
4673, 4674sensitive_privilege_useuser.name, winlog.privilege_list

process.command_line ใน 4688 มีค่าเฉพาะเครื่องที่เปิดการบันทึก command line ของ process creation แล้ว

บัญชีและกลุ่ม

ทุก event ในหัวข้อนี้มี user.name = คนที่ทำรายการ, user.target.name = บัญชีที่ถูกกระทำ และ group.name = กลุ่ม (ถ้ามี) ใช้กรองกลุ่มสำคัญได้ด้วยชื่อ เช่น group.name:"Domain Admins"

Event IDevent.action
4720user_created
4722user_enabled
4723password_change_attempt
4724password_reset
4725user_disabled
4726user_deleted
4728group_member_added (global group)
4729group_member_removed (global group)
4732local_group_member_added
4733local_group_member_removed
4738user_changed
4741computer_created
4742computer_changed
4743computer_deleted
4756universal_group_member_added
4757universal_group_member_removed
4781account_renamed
Event ID อื่นในช่วง 4720–4781 รวม Kerberos (4768–4772) และ 4739account_management

อื่นๆ ใน Security log

Event IDevent.actionฟิลด์ที่ได้
4698–4702scheduled_task_created / deleted / enabled / disabled / updatedfile.name (ชื่อ task), user.name
4662directory_service_accesswinlog.ds_access.object_name, winlog.ds_access.properties (GUID ของสิทธิ์ที่ใช้ ใช้ตรวจ DCSync), user.name
5136–5139directory_object_modified / created / undeleted / movedwinlog.ds_change.object_dn, user.name
4713, 4719policy_change—
6416, 6419–6422removable_device_changefile.name (ชื่ออุปกรณ์)

System log

Event IDevent.actionฟิลด์ที่ได้
7045service_installedservice.name, file.path (path ของโปรแกรม service), user.name (บัญชีที่ service ใช้รัน)
7034service_crashedservice.name
7035service_control_sentservice.name
7036service_state_changedservice.name
7040service_start_type_changedservice.name
6005system_startup—
6006system_shutdown—
6008system_unexpected_shutdown—

Sysmon

มีเฉพาะเครื่องที่ติดตั้ง Sysmon ทุก event ของ Sysmon ที่มีฟิลด์เหล่านี้จะได้: process.executable (Image), process.command_line, process.parent.executable, process.parent.command_line, user.name, file.hash.sha256 และ file.hash.md5 (แยกจาก Hashes)

Event IDevent.actionฟิลด์ที่ได้เพิ่ม
1process_start—
3network_connectionsource.ip, source.port, destination.ip, destination.port, network.transport
5process_end—
6driver_loadfile.path (ไฟล์ driver)
7image_loadfile.path (DLL ที่โหลด)
8process_injectionprocess.executable (ต้นทาง), process.target.executable (process ที่ถูก inject)
10process_accessprocess.executable, process.target.executable, winlog.granted_access · ถ้าเป้าหมายคือ lsass.exe จะมี tags:lsass_access
11file_createfile.path
12registry_key_createregistry.path
13registry_value_setregistry.path, registry.value
14registry_key_renameregistry.path
17named_pipe_createfile.name (ชื่อ pipe)
18named_pipe_connectfile.name (ชื่อ pipe)
19wmi_filter_eventwinlog.wmi.name, winlog.wmi.query
20wmi_consumer_eventwinlog.wmi.name, winlog.wmi.consumer
21wmi_binding_eventwinlog.wmi.consumer, winlog.wmi.filter
22dns_querydns.question.name, dns.answers

Channel อื่น

ChannelEvent IDevent.actionฟิลด์ที่ได้
PowerShell/Operational4104powershell_script_blockpowershell.script_block_text (ตัดที่ 4,096 ตัวอักษร, powershell.script_block_truncated = true เมื่อถูกตัด), powershell.script_block_id, file.path
PowerShell/Operational4103powershell_module_loggingpowershell.command_details (ตัดที่ 4,096 ตัวอักษร)
TerminalServices-*1149rdp_auth_successuser.name, user.domain, source.ip
TerminalServices-*21rdp_session_logon—
TerminalServices-*22rdp_shell_start—
TerminalServices-*25rdp_session_reconnect—
Windows Defender/Operational1116malware_detected—
Windows Defender/Operational1117malware_action_taken—
Windows Defender/Operational5001, 5010, 5012protection_disabledseverity high
Windows Firewall With Advanced Security/Firewallทุก IDfirewall_rule_change—
WMI-Activity/Operationalทุก IDwmi_activity—
TaskScheduler/Operationalทุก IDscheduled_task_activity—
Directory Serviceทุก IDdirectory_service_event—
DFS Replicationทุก IDdfs_replication_event—
DNS-Server/*ทุก IDdns_server_event—
Note:event ของ Windows Defender และ DNS Server ยังไม่ได้แปลงฟิลด์เป็น ECS ชื่อภัยคุกคามและรายละเอียดอื่นยังอยู่ในฟิลด์ชื่อเดิมของ Windows ค้นได้ตามปกติ

ฟิลด์ที่ไม่ได้แปลงชื่อ

ฟิลด์ EventData อื่นทั้งหมดถูกเก็บด้วยชื่อเดิมของ Windows (ขึ้นต้นด้วยตัวพิมพ์ใหญ่) เช่น SubjectDomainName, LogonId, ProcessId, Status, SubStatus ชื่อและความหมายของแต่ละฟิลด์ดูได้จาก เอกสารของ Microsoft สำหรับ Event ID นั้น

ติดตั้ง agent ดูที่ Windows · ฟิลด์ของ Linux ดูที่ ฟิลด์ของ Linux