# Filebeat o365 module - Parsing o365.audit.data field

**URL:** <https://discuss.elastic.co/t/filebeat-o365-module-parsing-o365-audit-data-field/261591>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 19, 2021, 8:47pm UTC](https://discuss.elastic.co/t/filebeat-o365-module-parsing-o365-audit-data-field/261591 "2021-01-19T20:47:28Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [January 20, 2021, 9:17am UTC](https://discuss.elastic.co/t/filebeat-o365-module-parsing-o365-audit-data-field/261591/2 "2021-01-20T09:17:26Z")

</div>

I think that using a script processor for this fields is not a bad idea. You can give a try to JSON processor (ingest node): [https://www.elastic.co/guide/en/elasticsearch/reference/current/json-processor.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/json-processor.html)

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-o365-module-parsing-o365-audit-data-field/261591)._
