# Extracting fields from existing message field in windows logs

**URL:** <https://discuss.elastic.co/t/extracting-fields-from-existing-message-field-in-windows-logs/291705>\
**Category:** Logstash\
**Created:** [December 13, 2021, 6:34pm UTC](https://discuss.elastic.co/t/extracting-fields-from-existing-message-field-in-windows-logs/291705 "2021-12-13T18:34:44Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rusty\_cole](https://avatars.discourse-cdn.com/v4/letter/r/a4c791/32.png) [@rusty\_cole](https://discuss.elastic.co/u/rusty_cole)\
**Post date:** [December 13, 2021, 6:34pm UTC](https://discuss.elastic.co/t/extracting-fields-from-existing-message-field-in-windows-logs/291705/1 "2021-12-13T18:34:45Z")

</div>

Hi,  
I have winlogbeat that sends evtx files to logstash and than the output of logstash goes to elastic.  
In the windows event logs, there is a field named "message". the problem is that the field type is text, so i cannot use sql wildcard (like '%') on that field.  
I am trying to extract, for example the "Error code:" from the long text in the message field.  
I tried grok, kv splits filters, nothing worked.  
Can anyone help?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 13, 2021, 6:59pm UTC](https://discuss.elastic.co/t/extracting-fields-from-existing-message-field-in-windows-logs/291705/2 "2021-12-13T18:59:52Z")

</div>

I suspect Most of this would be done for you with the pipelines if you just sent winlogbeat directly to elasticsearch .... if configured correctly... and you run setup etc.

I always recommend getting the Beats-\>Elasticsearch architecture working first _before_ introducing Logastash

Once you get that working then you can move towards

Beats-\>Logstash-\>Elastcsearch Ingest Architecture

When you put logstash in the middle some important data is not forwarded unless you use the correctly

Here is a post on similar.. its filebeat but the concept is the same

> [@Filebeat modules via Logstash](https://discuss.elastic.co/t/filebeat-modules-via-logstash/263612/2):
>
> Hi @st1988 Welcome the community and thanks for trying the Elastic Stack. It can be a bit challenging the first time you enter into the stack we are working to make this easier with our new feet So here is what I do Macro I make Filebeat to Elasticsearch Work direct first then I route thought Logstash.... if you can not do that thats ok but that is the best way to check if every thing works before routing through logstash 1st) clean up if you have any filbeat indices as the may be not setup…

---

<div class="post-metadata">

**Author:** ![rusty\_cole](https://avatars.discourse-cdn.com/v4/letter/r/a4c791/32.png) [@rusty\_cole](https://discuss.elastic.co/u/rusty_cole)\
**Post date:** [December 14, 2021, 4:33am UTC](https://discuss.elastic.co/t/extracting-fields-from-existing-message-field-in-windows-logs/291705/3 "2021-12-14T04:33:24Z")

</div>

Hi stephenb,  
Thanks for your reply.  
I did not find a way to achieve my need with pipelines(I checked the official documents again) . that's why I went with logstash.

Thanks,  
Itzik

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 14, 2021, 4:55am UTC](https://discuss.elastic.co/t/extracting-fields-from-existing-message-field-in-windows-logs/291705/4 "2021-12-14T04:55:32Z")

</div>

Fair enough, if you want help with a logstash pipeline perhaps you should post a sample of you logs and your logstash pipeline and perhaps someone can help.

You did look at [this](https://www.elastic.co/guide/en/beats/winlogbeat/current/reading-from-evtx.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 11, 2022, 4:56am UTC](https://discuss.elastic.co/t/extracting-fields-from-existing-message-field-in-windows-logs/291705/5 "2022-01-11T04:56:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
