diff --git a/x-pack/winlogbeat/module/security/test/testdata/4912_WindowsSrv2016.evtx b/x-pack/winlogbeat/module/security/test/testdata/4912_WindowsSrv2016.evtx deleted file mode 100644 index 15a93a947a2..00000000000 Binary files a/x-pack/winlogbeat/module/security/test/testdata/4912_WindowsSrv2016.evtx and /dev/null differ diff --git a/x-pack/winlogbeat/module/security/test/testdata/4912_WindowsSrv2016.evtx.golden.json b/x-pack/winlogbeat/module/security/test/testdata/4912_WindowsSrv2016.evtx.golden.json deleted file mode 100644 index 5e9a933c7bb..00000000000 --- a/x-pack/winlogbeat/module/security/test/testdata/4912_WindowsSrv2016.evtx.golden.json +++ /dev/null @@ -1,70 +0,0 @@ -[ - { - "@timestamp": "2020-08-18T14:36:41.2936839Z", - "event": { - "action": "per-user-audit-policy-changed", - "category": [ - "iam", - "configuration" - ], - "code": 4912, - "kind": "event", - "module": "security", - "outcome": "success", - "provider": "Microsoft-Windows-Security-Auditing", - "type": [ - "admin", - "change" - ] - }, - "host": { - "name": "WIN-BVM4LI1L1Q6.TEST.local" - }, - "log": { - "level": "information" - }, - "related": { - "user": "Administrator" - }, - "user": { - "domain": "TEST", - "id": "S-1-5-21-2024912787-2692429404-2351956786-500", - "name": "Administrator" - }, - "winlog": { - "activity_id": "{65461d39-753f-0000-731d-46653f75d601}", - "api": "wineventlog", - "channel": "Security", - "computer_name": "WIN-BVM4LI1L1Q6.TEST.local", - "event_data": { - "AuditPolicyChanges": "%%8452", - "CategoryId": "%%8276", - "SubcategoryGuid": "{0cce924a-69ae-11d9-bed3-505054503030}", - "SubcategoryId": "%%13317", - "SubjectDomainName": "TEST", - "SubjectLogonId": "0x44d7d", - "SubjectUserName": "Administrator", - "SubjectUserSid": "S-1-5-21-2024912787-2692429404-2351956786-500", - "TargetUserSid": "S-1-5-21-2024912787-2692429404-2351956786-500" - }, - "event_id": 4912, - "keywords": [ - "Audit Success" - ], - "logon": { - "id": "0x44d7d" - }, - "opcode": "Info", - "process": { - "pid": 780, - "thread": { - "id": 3300 - } - }, - "provider_guid": "{54849625-5478-4994-a5ba-3e3b0328c30d}", - "provider_name": "Microsoft-Windows-Security-Auditing", - "record_id": 123917, - "task": "Audit Policy Change" - } - } -] \ No newline at end of file