Let me explain the situation : I'm using 2 different server, one for my Rsyslog server and an onther for the ELK stack. I collect logs from Windows servers/computer on my Rsyslog server using Event to syslog. And then i transfer the logs to the ELK server via json. My problem is with some Windows' logs logstash seems to not interpret well the log. But with some other Windows' logs it work, and with Linux computer it work too.
In the source of the log a got a "message" before the actual log, it's strang.
And i'm using this json script on my Rsyslog server : https://gist.github.com/untergeek/0373ee85a41d03ae1b78
Thanks guys for taking a look at this for me.
Very much appreciate your time and suggestions.
PS : Sorry if my english is not that good