# Event\_data.param# instead of the correct fields

**URL:** <https://discuss.elastic.co/t/event-data-param-instead-of-the-correct-fields/146805>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [August 31, 2018, 6:08am UTC](https://discuss.elastic.co/t/event-data-param-instead-of-the-correct-fields/146805 "2018-08-31T06:08:51Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Badb0y](https://avatars.discourse-cdn.com/v4/letter/b/50afbb/32.png) [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Post date:** [August 31, 2018, 6:08am UTC](https://discuss.elastic.co/t/event-data-param-instead-of-the-correct-fields/146805/1 "2018-08-31T06:08:51Z")

</div>

Hi,

On kibana when I forwarded the logs I don't see like message id or message fields and a parsed fields, I just see this event\_data.param.

How can I send in the proper format?

[This](https://pastebin.com/ciFGHRcE) is the raw json.

Our flow loks like this:

Client -\> Indexerserver -\> elastic search -\> kibana

Should be the messages sent by default in this format or the indexer server should parse it?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 31, 2018, 5:01pm UTC](https://discuss.elastic.co/t/event-data-param-instead-of-the-correct-fields/146805/2 "2018-08-31T17:01:26Z")

</div>

Please read my response in [Generically named event\_data.paramN on Windows XP and 2003](https://discuss.elastic.co/t/generically-named-event-data-paramn-on-windows-xp-and-2003/46329/2?u=andrewkroh). I think it explains what you are seeing.

---

<div class="post-metadata">

**Author:** ![Badb0y](https://avatars.discourse-cdn.com/v4/letter/b/50afbb/32.png) [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Post date:** [September 1, 2018, 1:09am UTC](https://discuss.elastic.co/t/event-data-param-instead-of-the-correct-fields/146805/3 "2018-09-01T01:09:56Z")

</div>

Hmm, strange because this servers are windows 2012 servers not vista or older things.  
So it means we have to parse it on the logstash server?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 1, 2018, 1:32am UTC](https://discuss.elastic.co/t/event-data-param-instead-of-the-correct-fields/146805/4 "2018-09-01T01:32:40Z")

</div>

> [@Badb0y](#):
>
> Hmm, strange because this servers are windows 2012 servers not vista or older things.

It's not the operating system causing the issue, it's the application and the means by which it writes to the log.

> [@Badb0y](#):
>
> So it means we have to parse it on the logstash server?

Yes, you'll need to use LS to rename the fields to something more meaningful. And by the looks of the data you might need to parse some of the `paramN` values to get the data you need.

---

<div class="post-metadata">

**Author:** ![Badb0y](https://avatars.discourse-cdn.com/v4/letter/b/50afbb/32.png) [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Post date:** [September 3, 2018, 1:53am UTC](https://discuss.elastic.co/t/event-data-param-instead-of-the-correct-fields/146805/5 "2018-09-03T01:53:31Z")

</div>

Thank you.

---

<div class="post-metadata">

**Author:** ![Badb0y](https://avatars.discourse-cdn.com/v4/letter/b/50afbb/32.png) [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Post date:** [September 6, 2018, 3:45am UTC](https://discuss.elastic.co/t/event-data-param-instead-of-the-correct-fields/146805/6 "2018-09-06T03:45:49Z")

</div>

Is there any way to drop everything with event\_data.param ? If I list 1 by 1 I can drop the fields but the wildcard doesn't work.

This is how I try:

```
winlogbeat.event_logs:
  - name: Application
    processors: 
        - drop_fields:
            fields: ["event_data.param*"]
    #level: critical, error, warning
    #include_xml: true
    ignore_older: 72h
  - name: System
    processors: 
        - drop_fields:
            fields: ["event_data.param.*"]
    # level: critical, error, warning
    #include_xml: true
  - name: Setup
    level: critical, error, warning
  - name: "Windows PowerShell"
    level: critical, error, warning
output.logstash:
  hosts: []

```

Or how can we rename that fields?

When you say LS in your previous comment you mean like this flow: winlogbeat raw event -\> logstash and here do the magic -\> elastic search -\> kibana ?

Cannot somehow let the events know what they are sending? When we used nxlog everything transferred correctly.

Or another idea, I just see that the event\_data.params actually the message and the message we have in the message field, so how we can just disable or set something don't try to parse the message itself. If it doesn't try to parse the message these fields wouldn't come up.

```
Or how to do this, it would be also a solution:
    processors: 
            - drop_fields:
                when:
                    has_fields: ['event_data.param']
                fields: ["event_data.param"] 

```

The above doesn't work it says Exiting: Failed to create new event log. missing condition. If we have ot with wildcard or somehow make it work I'm happy.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2018, 3:46am UTC](https://discuss.elastic.co/t/event-data-param-instead-of-the-correct-fields/146805/7 "2018-10-04T03:46:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
