# Document all possible event\_data.\* fields?

**URL:** <https://discuss.elastic.co/t/document-all-possible-event-data-fields/63301>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [October 18, 2016, 1:40pm UTC](https://discuss.elastic.co/t/document-all-possible-event-data-fields/63301 "2016-10-18T13:40:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rivaanbechan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rivaanbechan/32/12900_2.png) [@rivaanbechan](https://discuss.elastic.co/u/rivaanbechan)\
**Post date:** [October 18, 2016, 1:40pm UTC](https://discuss.elastic.co/t/document-all-possible-event-data-fields/63301/1 "2016-10-18T13:40:52Z")

</div>

Hi,

Is there any list out there with all the **current fields** that is possible to receive within **"event\_data"**.

I would like to further **filter** the **subfields**. Although I need the list to get a baseline.

Please assist me.

Thank you,  
Rivaan

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 18, 2016, 2:36pm UTC](https://discuss.elastic.co/t/document-all-possible-event-data-fields/63301/2 "2016-10-18T14:36:48Z")

</div>

It's not feasible to compile a list of all possible fields for all events since it's up to the applications that log the events to name their fields.

You could build up a list of field names for different applications. The field names are specific to an event ID. So the meaning of a given field's data could vary between events with different IDs.

Could you whitelist fields that you do want to allow? This would require you to know only the fields that you want to keep vs. knowing all fields you want to drop.

---

<div class="post-metadata">

**Author:** ![rivaanbechan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rivaanbechan/32/12900_2.png) [@rivaanbechan](https://discuss.elastic.co/u/rivaanbechan)\
**Post date:** [October 18, 2016, 2:57pm UTC](https://discuss.elastic.co/t/document-all-possible-event-data-fields/63301/3 "2016-10-18T14:57:43Z")

</div>

Hi Andrew,

Thank you! I didn't realize that this is up to the application that logs the event. I assumed that winlogbeats did renaming and extractions on the "message" field.

Yes, the plan is to whitelist, although just wanted a broad scope to understand the dataset and what provides enough value to keep.

So the way forward for me would be?

My assumption is, index a large volume of event logs, identify valuable fields within event\_data and then do the whitelisting?

Thank you,  
Rivaan

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 18, 2016, 3:04pm UTC](https://discuss.elastic.co/t/document-all-possible-event-data-fields/63301/4 "2016-10-18T15:04:26Z")

</div>

> [@rivaanbechan](#):
>
> My assumption is, index a large volume of event logs, identify valuable fields within event\_data and then do the whitelisting?

That sounds like a sane approach. You'll probably also want to blacklist some events that add no value to your use case (by using `source_name` + `event_id` to uniquely identify the event).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 8, 2016, 3:04pm UTC](https://discuss.elastic.co/t/document-all-possible-event-data-fields/63301/5 "2016-11-08T15:04:36Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
