1. Describe your incident:
I started my Graylog server and configured and ran Winlogbeat. In Graylog I see the flows from my Windows computer, but I have for example: account name: %1 domain name: %2 logon type: %9ect.
For example, on Windows %1 is Computer1, domain name is testDomian ect.
2. describe your environment:
OS Information:
Ubuntu 22.04
Package version:
Graylog v5.0.3
3. what steps have you already taken to solve the problem?
4. how can the community help?
How do I configure winlogbeat or openserach or graylog to get correct values for windows events?