# Extract field from Messages section of Windows Event Log

**URL:** <https://discuss.elastic.co/t/extract-field-from-messages-section-of-windows-event-log/154724>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [October 30, 2018, 8:40pm UTC](https://discuss.elastic.co/t/extract-field-from-messages-section-of-windows-event-log/154724 "2018-10-30T20:40:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dave\_Foster](https://avatars.discourse-cdn.com/v4/letter/d/ecb155/32.png) [@Dave\_Foster](https://discuss.elastic.co/u/Dave_Foster)\
**Post date:** [October 30, 2018, 8:40pm UTC](https://discuss.elastic.co/t/extract-field-from-messages-section-of-windows-event-log/154724/1 "2018-10-30T20:40:31Z")

</div>

We are trying to extract a couple fields via filters from within the nested 'messages' section of a Windows Event Log. Below is the nested info from event\_data.param2 :

```
<?xml version="1.0" encoding="utf-16"?>
<AuditBase xmlns:xsd="http://www.w3.org/2001/XMLSchema" 
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="ExtranetLockoutAudit">
  <AuditType>ExtranetLockout</AuditType>
  <AuditResult>Failure</AuditResult>
  <FailureType>ExtranetLockoutError</FailureType>
  <ErrorCode>AccountRestrictedAudit</ErrorCode>
  <ContextComponents>
<Component xsi:type="ResourceAuditComponent">
  <RelyingParty>N/A</RelyingParty>
  <ClaimsProvider>N/A</ClaimsProvider>
  <UserId>TEST\GuiltyUser</UserId>
</Component>
<Component xsi:type="RequestAuditComponent">
  <Server>N/A</Server>
  <AuthProtocol>N/A</AuthProtocol>
  <NetworkLocation>Extranet</NetworkLocation>
  <IpAddress>172.2.3.4,172.6.7.8</IpAddress>
  <ForwardedIpAddress>172.9.0.1,172.10.1.45</ForwardedIpAddress>
  <ProxyIpAddress>N/A</ProxyIpAddress>
  <NetworkIpAddress>N/A</NetworkIpAddress>
  <ProxyServer>OurServer</ProxyServer>
  <UserAgentString>N/A</UserAgentString>
  <Endpoint>/adfs/services/trust/2005/usernamemixed</Endpoint>
</Component>
<Component xsi:type="LockoutConfigAuditComponent">
  <CurrentBadPasswordCount>1</CurrentBadPasswordCount>
  <ConfigBadPasswordCount>1</ConfigBadPasswordCount>
  <LastBadAttempt>10/30/2018 16:38:47</LastBadAttempt>
  <LockoutWindowConfig>00:20:00</LockoutWindowConfig>
</Component>

```

We are trying to pull out the following nested fields

ForwardedIpAddress and UserId

We are trying to filter the data and have:

## extranet

filter {  
if "wineventlog" in [tags] and [event\_id] == 1210 {

xml {  
source =\> "event\_data.param2"  
store\_xml =\> false  
xpath =\> ["/AuditBase/ContextComponents/Component/ForwardedIpAddress/text()","ForwardedIp"]  
}  
}  
}

Xpath path works in an online generator and extracts the IP 172.9.0.1,172.10.1.45 but this never happens in Logstash...Any thoughts on how to make this work. Ideally we want to extra just the 172.9.0.1 (the first IP address)

thx

Dave

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [November 1, 2018, 5:33pm UTC](https://discuss.elastic.co/t/extract-field-from-messages-section-of-windows-event-log/154724/2 "2018-11-01T17:33:47Z")

</div>

It may be best to ask this question on the Logstash forum here [https://discuss.elastic.co/c/logstash](https://discuss.elastic.co/c/logstash) . This use case should work, but I don't have expertise with the XML filter.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2018, 5:33pm UTC](https://discuss.elastic.co/t/extract-field-from-messages-section-of-windows-event-log/154724/3 "2018-11-29T17:33:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
