Extract field from Messages section of Windows Event Log

We are trying to extract a couple fields via filters from within the nested 'messages' section of a Windows Event Log. Below is the nested info from event_data.param2 :

<?xml version="1.0" encoding="utf-16"?>
<AuditBase xmlns:xsd="http://www.w3.org/2001/XMLSchema" 
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="ExtranetLockoutAudit">
<Component xsi:type="ResourceAuditComponent">
<Component xsi:type="RequestAuditComponent">
<Component xsi:type="LockoutConfigAuditComponent">
  <LastBadAttempt>10/30/2018 16:38:47</LastBadAttempt>

We are trying to pull out the following nested fields

ForwardedIpAddress and UserId

We are trying to filter the data and have:


filter {
if "wineventlog" in [tags] and [event_id] == 1210 {

xml {
source => "event_data.param2"
store_xml => false
xpath => ["/AuditBase/ContextComponents/Component/ForwardedIpAddress/text()","ForwardedIp"]

Xpath path works in an online generator and extracts the IP, but this never happens in Logstash...Any thoughts on how to make this work. Ideally we want to extra just the (the first IP address)



