# Drop "event\_data." from data field

**URL:** <https://discuss.elastic.co/t/drop-event-data-from-data-field/78608>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 14, 2017, 10:01pm UTC](https://discuss.elastic.co/t/drop-event-data-from-data-field/78608 "2017-03-14T22:01:46Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![peanut](https://avatars.discourse-cdn.com/v4/letter/p/b5e925/32.png) [@peanut](https://discuss.elastic.co/u/peanut)\
**Post date:** [March 14, 2017, 10:01pm UTC](https://discuss.elastic.co/t/drop-event-data-from-data-field/78608/1 "2017-03-14T22:01:46Z")

</div>

Good afternoon Elastic team,

I am sending Sysmon logs to my ELK stack with Winlogbeat 5.2.1 and all of them have the "event\_data" string in the field names. For example:

event\_data.CommandLine should be only CommandLine

How can I make those changes on the client (winlogbeat) instead of configuring a Logstash filter?

Thank you

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 16, 2017, 3:20pm UTC](https://discuss.elastic.co/t/drop-event-data-from-data-field/78608/2 "2017-03-16T15:20:05Z")

</div>

You need to use Logstash or Ingest Node if you want to rename fields. It cannot be done in Beats.

Why do you want to rename them?

---

<div class="post-metadata">

**Author:** ![peanut](https://avatars.discourse-cdn.com/v4/letter/p/b5e925/32.png) [@peanut](https://discuss.elastic.co/u/peanut)\
**Post date:** [March 16, 2017, 10:53pm UTC](https://discuss.elastic.co/t/drop-event-data-from-data-field/78608/3 "2017-03-16T22:53:41Z")

</div>

Thank you very much. Thats what I read too. It cannot be done at the Host level (Winlogbeat). The reason why I want to rename them is because the data field names are too long, and I was not sure if others were trying to rename them or working like that by default. Sorry this is my first time working with Winlogbeat and ELK.

> [@Split "event\_data" to only show the original data field](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-data-field/78561/3):
>
> I have been reading since I posted this two days ago and I found this post in this forum: "The event\_data.\* fields are the raw data that was provided by the application that logged the event. This is included in the event published by Winlogbeat so that you don't have to grok the message field to extract data needed for other analysis you might want to do." So all new data fields from, for example, Sysmon logs, have the event\_data name at the beginning . event\_data.CommandLine event\_data.Pr…

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 16, 2017, 11:05pm UTC](https://discuss.elastic.co/t/drop-event-data-from-data-field/78608/4 "2017-03-16T23:05:37Z")

</div>

> [@peanut](#):
>
> the data field names are too long

Too long for what?

I think most people use them as is. I can see a case for some renames or copies if you want a common field name for certain types of data across your org.

---

<div class="post-metadata">

**Author:** ![peanut](https://avatars.discourse-cdn.com/v4/letter/p/b5e925/32.png) [@peanut](https://discuss.elastic.co/u/peanut)\
**Post date:** [March 16, 2017, 11:50pm UTC](https://discuss.elastic.co/t/drop-event-data-from-data-field/78608/5 "2017-03-16T23:50:11Z")

</div>

1- Too long for visualizations. As you can see below. The data field name such as:

event\_data.DestinationIP.Keyword is too long and plus the word "Descending", pushes the column name "count" to the right. So my visualization needs to be a certain size to accommodate the columns I want to show. If I reduce its size, I dont see the "Count column"

 ![](https://us1.discourse-cdn.com/elastic/original/3X/a/9/a9a3780ef28e46939996c8a17c2773f42d201f58.jpg)

2- Too long to type queries manually. lets say i want to create chains of events to know processes calling out to a specific external IP address via a specific port name:

event\_data.Image: "C:\bla\bla\bla.exe AND event\_data.DestinationIP: "x.x.x.x" AND event\_data.DestinationPortName: "https"

it could be:

image: C:\bla\bla\bla.exe AND DestinationIP: "x.x.x.x" AND DestinationPortName: "https"

Thats it. If most people are using them as is, then I will just using the data fields like that. I just wasnt sure if the "event\_data" part added to the original data field name was something that I needed to split or take out to clean how the data fields are presented. Once again, I am new to Winlogbeat sending the logs. I used nxlog in the past and the logs are sent and named the way how they are presented in the raw log. For example, the log showed below will keep the same data field names without adding "event\_data".

![](https://us1.discourse-cdn.com/elastic/original/3X/f/3/f3ad366686bd9cb974c80b4c9d4f8370d2fedffb.png)

however, according to what you posted before, thats the way how Winlogbeat tags events so that we dont have to use Grok to parse logs properly

> [@Event messages are splitted in event\_data.param xy? How to fix that?](https://discuss.elastic.co/t/event-messages-are-splitted-in-event-data-param-xy-how-to-fix-that/61087/2):
>
> Assuming that the events were forwarded from the original host to the collector in "RenderedText" format, then they should have a message field that contains the full text of the event. The event\_data.\* fields are the raw data that was provided by the application that logged the event. This is included in the event published by Winlogbeat so that you don't have to grok the message field to extract data needed for other analysis you might want to do. To debug the issue I would add the [include\_xm…](https://www.elastic.co/guide/en/beats/winlogbeat/5.0/configuration-winlogbeat-options.html#_event_logs_include_xml)

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 17, 2017, 4:02pm UTC](https://discuss.elastic.co/t/drop-event-data-from-data-field/78608/6 "2017-03-17T16:02:30Z")

</div>

> [@peanut](#):
>
> Too long for visualizations

Kibana allows a custom name to be used. So you can use anything you like for the column header.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0ecd933e244a23c868c71858e4afe420ba67776c.png)

> [@peanut](#):
>
> Too long to type queries manually.

I can't help with that. The reason the fields are namespaced under `event_data` is to provide context about where the data came from. Also since the fields can be named anything by the developer of the application that logged the event, the name could collide with other fields used by the Beat and this namespacing prevents it.

---

<div class="post-metadata">

**Author:** ![peanut](https://avatars.discourse-cdn.com/v4/letter/p/b5e925/32.png) [@peanut](https://discuss.elastic.co/u/peanut)\
**Post date:** [March 20, 2017, 11:43pm UTC](https://discuss.elastic.co/t/drop-event-data-from-data-field/78608/7 "2017-03-20T23:43:15Z")

</div>

Thank you very much Andrew. I didnt think of the Custom Labels. That will make it so much easier. Problem Solved then. 🙂 Have a good rest of the week!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 17, 2017, 11:43pm UTC](https://discuss.elastic.co/t/drop-event-data-from-data-field/78608/8 "2017-04-17T23:43:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
