# Drop "event\_data." from data field

**URL:** <https://discuss.elastic.co/t/drop-event-data-from-data-field/78608>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 14, 2017, 10:01pm UTC](https://discuss.elastic.co/t/drop-event-data-from-data-field/78608 "2017-03-14T22:01:46Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![peanut](https://avatars.discourse-cdn.com/v4/letter/p/b5e925/32.png) [@peanut](https://discuss.elastic.co/u/peanut)\
**Post date:** [March 16, 2017, 11:50pm UTC](https://discuss.elastic.co/t/drop-event-data-from-data-field/78608/5 "2017-03-16T23:50:11Z")

</div>

1- Too long for visualizations. As you can see below. The data field name such as:

event\_data.DestinationIP.Keyword is too long and plus the word "Descending", pushes the column name "count" to the right. So my visualization needs to be a certain size to accommodate the columns I want to show. If I reduce its size, I dont see the "Count column"

 ![](https://us1.discourse-cdn.com/elastic/original/3X/a/9/a9a3780ef28e46939996c8a17c2773f42d201f58.jpg)

2- Too long to type queries manually. lets say i want to create chains of events to know processes calling out to a specific external IP address via a specific port name:

event\_data.Image: "C:\bla\bla\bla.exe AND event\_data.DestinationIP: "x.x.x.x" AND event\_data.DestinationPortName: "https"

it could be:

image: C:\bla\bla\bla.exe AND DestinationIP: "x.x.x.x" AND DestinationPortName: "https"

Thats it. If most people are using them as is, then I will just using the data fields like that. I just wasnt sure if the "event\_data" part added to the original data field name was something that I needed to split or take out to clean how the data fields are presented. Once again, I am new to Winlogbeat sending the logs. I used nxlog in the past and the logs are sent and named the way how they are presented in the raw log. For example, the log showed below will keep the same data field names without adding "event\_data".

![](https://us1.discourse-cdn.com/elastic/original/3X/f/3/f3ad366686bd9cb974c80b4c9d4f8370d2fedffb.png)

however, according to what you posted before, thats the way how Winlogbeat tags events so that we dont have to use Grok to parse logs properly

> [@Event messages are splitted in event\_data.param xy? How to fix that?](https://discuss.elastic.co/t/event-messages-are-splitted-in-event-data-param-xy-how-to-fix-that/61087/2):
>
> Assuming that the events were forwarded from the original host to the collector in "RenderedText" format, then they should have a message field that contains the full text of the event. The event\_data.\* fields are the raw data that was provided by the application that logged the event. This is included in the event published by Winlogbeat so that you don't have to grok the message field to extract data needed for other analysis you might want to do. To debug the issue I would add the [include\_xm…](https://www.elastic.co/guide/en/beats/winlogbeat/5.0/configuration-winlogbeat-options.html#_event_logs_include_xml)

---

_[View the full topic](https://discuss.elastic.co/t/drop-event-data-from-data-field/78608)._
