# Drop "event\_data." from data field

**URL:** <https://discuss.elastic.co/t/drop-event-data-from-data-field/78608>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 14, 2017, 10:01pm UTC](https://discuss.elastic.co/t/drop-event-data-from-data-field/78608 "2017-03-14T22:01:46Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![peanut](https://avatars.discourse-cdn.com/v4/letter/p/b5e925/32.png) [@peanut](https://discuss.elastic.co/u/peanut)\
**Post date:** [March 16, 2017, 10:53pm UTC](https://discuss.elastic.co/t/drop-event-data-from-data-field/78608/3 "2017-03-16T22:53:41Z")

</div>

Thank you very much. Thats what I read too. It cannot be done at the Host level (Winlogbeat). The reason why I want to rename them is because the data field names are too long, and I was not sure if others were trying to rename them or working like that by default. Sorry this is my first time working with Winlogbeat and ELK.

> [@Split "event\_data" to only show the original data field](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-data-field/78561/3):
>
> I have been reading since I posted this two days ago and I found this post in this forum: "The event\_data.\* fields are the raw data that was provided by the application that logged the event. This is included in the event published by Winlogbeat so that you don't have to grok the message field to extract data needed for other analysis you might want to do." So all new data fields from, for example, Sysmon logs, have the event\_data name at the beginning . event\_data.CommandLine event\_data.Pr…

---

_[View the full topic](https://discuss.elastic.co/t/drop-event-data-from-data-field/78608)._
