# Event messages are splitted in event\_data.param xy? How to fix that?

**URL:** <https://discuss.elastic.co/t/event-messages-are-splitted-in-event-data-param-xy-how-to-fix-that/61087>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [September 21, 2016, 7:34am UTC](https://discuss.elastic.co/t/event-messages-are-splitted-in-event-data-param-xy-how-to-fix-that/61087 "2016-09-21T07:34:28Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 21, 2016, 2:17pm UTC](https://discuss.elastic.co/t/event-messages-are-splitted-in-event-data-param-xy-how-to-fix-that/61087/2 "2016-09-21T14:17:13Z")

</div>

Assuming that the events were forwarded from the original host to the collector in "RenderedText" format, then they should have a `message` field that contains the full text of the event. The `event_data.*` fields are the raw data that was provided by the application that logged the event. This is included in the event published by Winlogbeat so that you don't have to grok the `message` field to extract data needed for other analysis you might want to do.

To debug the issue I would add the [`include_xml: true`](https://www.elastic.co/guide/en/beats/winlogbeat/5.0/configuration-winlogbeat-options.html#_event_logs_include_xml) configuration option so that the raw XML event that was forwarded by the original host is included. Then you can check this XML to see if it includes a `RenderingInfo` field with a message.

You should also enable debug logging (`logging.level: debug`) and check the log for problems (or post it to pastebin or gist and I can take a look).

As a general note about your config, I also recommend adding a `forwarded` tag events read from the `ForwardedEvents` log so that you can easily tell that they were forwarded. WIthout this tag it can be difficult to know since the `log_name` field gets set to the original log name.

It appears that the indentation is wrong in the config you posted.

```auto
winlogbeat.registry_file: 'C:/Elkwin_Free_x64/winlogbeat/.winlogbeat.yml'

winlogbeat.event_logs:
- name: ForwardedEvents
  level: critical, error, warning
  forwarded: true
  include_xml: true
  tags: [forwarded]

output.elasticsearch:
  hosts: ["localhost:9200"]

logging.level: debug
logging.to_files: true
logging.files:
  path: 'C:/Elkwin_Free_x64/winlogbeat/Logs'
  rotateeverybytes: 10485760
  keepfiles: 7

```

---

_[View the full topic](https://discuss.elastic.co/t/event-messages-are-splitted-in-event-data-param-xy-how-to-fix-that/61087)._
