Create Field in windows for workstation name

Hi @juancamiloll Welcome to the community.

Its probably better idea to use an ingest pipeline to extract the field than a runtime field in the data view

Can you provide a sample document in JSon from discover with event.original and and perhaps we can help. Provide the whole document as it will provide other information to help. You can anonymize sensitive fields.

Also exactly what version of the elastic stack and which integration