I'm trying to get "event.original" field from "_source" field but i don't suceed to get it on the winlogbeat conf.

Is someone have a solution to get it ?


The original event is the XML Winlogbeat receives from Windows. To include it set include_xml: true in the configuration for the event log. See the example in https://www.elastic.co/guide/en/beats/winlogbeat/7.7/configuration-winlogbeat-options.html#_event_logs_include_xml.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.