# Active Directory - Parse Message Log and Username

**URL:** <https://discuss.elastic.co/t/active-directory-parse-message-log-and-username/194537>\
**Category:** Logstash\
**Created:** [August 9, 2019, 3:33am UTC](https://discuss.elastic.co/t/active-directory-parse-message-log-and-username/194537 "2019-08-09T03:33:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![awataszko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/awataszko/32/54457_2.png) [@awataszko](https://discuss.elastic.co/u/awataszko)\
**Post date:** [August 9, 2019, 3:33am UTC](https://discuss.elastic.co/t/active-directory-parse-message-log-and-username/194537/1 "2019-08-09T03:33:42Z")

</div>

Hi,

I am trying to build a simple report for something like AD group changes. Wondering if the "message" in the event ID can be parsed further?(ie have more fields) Also wondering if any regex can be applied. For example, instead of the entire account name in the CN format, just grab part of it. My understanding is logstash can do this 🙂

I'm working off EventID 4728

A member was added to a security-enabled global group.

Subject:

Security ID: ACME\Administrator  
Account Name: Administrator  
Account Domain: ACME  
Logon ID: 0x27a79

Member:

Security ID: ACME\gkhan  
Account Name: cn=Ghenghis Khan,CN=Users,DC=acme,DC=local

Group:

Security ID: S-1-5-21-3108364787-189202583-342365621-1108  
Group Name: Historical Figures  
Group Domain: ACME

Additional Information:

Privileges: -

So for example, I would like A member was added to a security-enabled global group to be a field. I would also like to have a field just for the Security ID and Account name, also parsing the format to just the Name.

I've found this post:  
[https://www.syspanda.com/index.php/2018/01/09/monitoring-domain-group-membership-changes-elk/](https://www.syspanda.com/index.php/2018/01/09/monitoring-domain-group-membership-changes-elk/)

However, the extra field short\_message isn't being created. Here's a snippit incase the link is not allowed or removed.  
filter {  
if "winlogbeat" in [tags] and [event\_id] == 4727 {  
mutate {  
add\_field =\> { "short\_message" =\> "A security-enabled global group was created" }  
}  
}  
else if [event\_id] == 4728 {  
mutate {  
add\_field =\> { "short\_message" =\> "A member was added to a security-enabled global group" }  
}  
}

Any feedback or suggestions would be awesome 🙂

Thanks - AW

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 9, 2019, 12:54pm UTC](https://discuss.elastic.co/t/active-directory-parse-message-log-and-username/194537/2 "2019-08-09T12:54:08Z")

</div>

I would replace the long if else if else if else if with a call to a [translate](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html) filter.

What does one of your events look like if you use this output?...

```
output { stdout { codec => rubydebug } }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 6, 2019, 12:54pm UTC](https://discuss.elastic.co/t/active-directory-parse-message-log-and-username/194537/3 "2019-09-06T12:54:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
