# Get the first line of \[message\] field coming from winlogbeat

**URL:** <https://discuss.elastic.co/t/get-the-first-line-of-message-field-coming-from-winlogbeat/288768>\
**Category:** Logstash\
**Created:** [November 9, 2021, 2:34pm UTC](https://discuss.elastic.co/t/get-the-first-line-of-message-field-coming-from-winlogbeat/288768 "2021-11-09T14:34:29Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![yquirion](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yquirion/32/107068_2.png) [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Post date:** [November 9, 2021, 2:34pm UTC](https://discuss.elastic.co/t/get-the-first-line-of-message-field-coming-from-winlogbeat/288768/1 "2021-11-09T14:34:29Z")

</div>

Hello,

I'm trying to get the first line of the message field because this is an important information to keep.

The [message] line, when I set the output to file using rudydebug option looks like this:

```auto
 "message" => "An HTTP request was received. See audit 510 with the same Instance ID for headers. \n\nInstance ID: 8ac2ca87-8958-4e0e-a79a-8be672341b5b \n\nActivity ID: 62f3ac59-1f9b-9254-97c8-b00a8bd00357 \n\nRequest Details: \n Date And Time: 2021-11-09 14:15:16 \n Client IP: 111.111.1.111 \n HTTP Method: POST \n Url Absolute Path: /adfs/oauth2/token/ \n Query string: - \n Local Port: 443 \n Local IP: 100.132.4.89 \n User Agent: Windows-AzureAD-Authentication-Provider/1.0 \n Content Length: 4223 \n Caller Identity: - \n Certificate Identity (if any): - \n Targeted relying party: - \n Through proxy: False \n Proxy DNS name: -"

```

I would like to have this:  
"An HTTP request was received. See audit 510 with the same Instance ID for headers."

Which is the first line before a \n.

In logstash I tried several solution I've found on this forum, but there is no one working:

```auto
  mutate {
    copy => { "message" => "message_head" }
  }

  mutate {
    gsub => ["message_head", "^([^\n]*)$", "\1" ]
  }

```

I also tried this:

```auto
  mutate {
    copy => { "message" => "message_head" }
  }

  mutate {
    split => ["message_head", " 
"]}

  mutate {
    replace => { "message_head" => "%{message_head[0]}" }
  }

```

And:

```auto
mutate { split => ["message_head" => "\n"] }

```

The result is almost all the same; the 'split' or 'gsub' are just not being applied:

```auto
"message_head" => "An HTTP request was received. See audit 510 with the same Instance ID for headers. \n\nInstance ID: 8ac2ca87-8958-4e0e-a79a-8be672341b5b \n\nActivity ID: 62f3ac59-1f9b-9254-97c8-b00a8bd00357 \n\nRequest Details: \n Date And Time: 2021-11-09 14:15:16 \n Client IP: 111.111.1.111 \n HTTP Method: POST \n Url Absolute Path: /adfs/oauth2/token/ \n Query string: - \n Local Port: 443 \n Local IP: 100.132.4.89 \n User Agent: Windows-AzureAD-Authentication-Provider/1.0 \n Content Length: 4223 \n Caller Identity: - \n Certificate Identity (if any): - \n Targeted relying party: - \n Through proxy: False \n Proxy DNS name: -",
"message" => "An HTTP request was received. See audit 510 with the same Instance ID for headers. \n\nInstance ID: 8ac2ca87-8958-4e0e-a79a-8be672341b5b \n\nActivity ID:62f3ac59-1f9b-9254-97c8-b00a8bd00357 \n\nRequest Details: \n Date And Time: 2021-11-09 14:15:16 \n Client IP: 111.111.1.111 \n HTTP Method: POST \n Url Absolute Path: /adfs/oauth2/token/ \n Query string: - \n Local Port: 443 \n Local IP: 100.132.4.89 \n User Agent: Windows-AzureAD-Authentication-Provider/1.0 \n Content Length: 4223 \n Caller Identity: - \n Certificate Identity (if any): - \n Targeted relying party: - \n Through proxy: False \n Proxy DNS name: -",

```

In some solution I've found, people said it was working, such as this thread: [https://discuss.elastic.co/t/add-winlogbeat-option-to-truncate-security-message-field-to-just-first-line/49409](https://discuss.elastic.co/t/add-winlogbeat-option-to-truncate-security-message-field-to-just-first-line/49409), but it is not the case on my side.

To see when I see into Kibana, please look at the attached screenshot.

 ![screenshot-000039](https://us1.discourse-cdn.com/elastic/original/3X/7/0/7034ab902fafb042ebd616bc5c142485bc46f2a8.jpeg)

You will notice the current filter, which is:

```auto
  mutate {
    copy => { "message" => "message_head" }
  }

  mutate { 
    gsub => ["message_head", "^([^\n]*)$", "\1" ]
  }

```

... did nothing.

If I test my regular expression into a "regular expression tester", I can see that it is working:

 ![screenshot-000040](https://us1.discourse-cdn.com/elastic/original/3X/7/b/7b65e31d65c9626451a645cd49714c262819457d.jpeg)

So I'm out of solutions here...

Is there anybody who can help me out with this issue?

Thank you and best regards,  
Yanick

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [November 9, 2021, 2:59pm UTC](https://discuss.elastic.co/t/get-the-first-line-of-message-field-coming-from-winlogbeat/288768/2 "2021-11-09T14:59:47Z")

</div>

Might be more efficient to do in Ruby. But here's how you can do it without.

**Test Conf**

```auto
input { generator { codec => json count => 1 lines => ['{ "message" : "An HTTP request was received. See audit 510 with the same Instance ID for headers. \n\nInstance ID: 8ac2ca87-8958-4e0e-a79a-8be672341b5b \n\nActivity ID: 62f3ac59-1f9b-9254-97c8-b00a8bd00357 \n\nRequest Details: \n Date And Time: 2021-11-09 14:15:16 \n Client IP: 111.111.1.111 \n HTTP Method: POST \n Url Absolute Path: /adfs/oauth2/token/ \n Query string: - \n Local Port: 443 \n Local IP: 100.132.4.89 \n User Agent: Windows-AzureAD-Authentication-Provider/1.0 \n Content Length: 4223 \n Caller Identity: - \n Certificate Identity (if any): - \n Targeted relying party: - \n Through proxy: False \n Proxy DNS name: -" }'] } }
filter {
    mutate {
       gsub => ["message", " \n\n", "::"]
    }
    mutate {
       split => {"message" => "::"}
       add_field => ["result", "%{[message][0]}"]
    }
}      
output {
  stdout { codec => json_lines }
}

```

**Output**

```auto
"result": "An HTTP request was received. See audit 510 with the same Instance ID for headers."

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 9, 2021, 6:13pm UTC](https://discuss.elastic.co/t/get-the-first-line-of-message-field-coming-from-winlogbeat/288768/3 "2021-11-09T18:13:49Z")

</div>

> [@yquirion](#):
>
> `gsub => ["message_head", "^([^\n]*)$", "\1" ]`

That is a no-op. It replaces the first line with the first line. Try

```
mutate { gsub => ["message_head", "(?m)^([^\n]*)$.*", "\1" ] }

```

---

<div class="post-metadata">

**Author:** ![yquirion](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yquirion/32/107068_2.png) [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Post date:** [November 9, 2021, 6:28pm UTC](https://discuss.elastic.co/t/get-the-first-line-of-message-field-coming-from-winlogbeat/288768/4 "2021-11-09T18:28:32Z")

</div>

Hi aaron.

I would like to know the ruby version as well. I tried both, but my knowledge are limited with this.

I will try you solution shortly.

Regards,  
Yanick

---

<div class="post-metadata">

**Author:** ![yquirion](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yquirion/32/107068_2.png) [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Post date:** [November 9, 2021, 6:39pm UTC](https://discuss.elastic.co/t/get-the-first-line-of-message-field-coming-from-winlogbeat/288768/5 "2021-11-09T18:39:44Z")

</div>

Hi Badger,

Much thanks, your solution works. However I'm not sure when means the:

```auto
(?m)

```

After asking my friend Google, it told me that means "multi-line". Is it correct?

Thank you again for your help,  
Yanick

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [November 9, 2021, 6:43pm UTC](https://discuss.elastic.co/t/get-the-first-line-of-message-field-coming-from-winlogbeat/288768/6 "2021-11-09T18:43:39Z")

</div>

> [@yquirion](#):
>
> Hi aaron.
> 
> I would like to know the ruby version as well. I tried both, but my knowledge are limited with this.
> 
> I will try you solution shortly.
> 
> Regards,  
> Yanick

I would go with Badgers suggestion vs Ruby. I was thinking it wasn't possible to target `\n` with gsub and might require Ruby to do it. I was wrong.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 9, 2021, 7:24pm UTC](https://discuss.elastic.co/t/get-the-first-line-of-message-field-coming-from-winlogbeat/288768/7 "2021-11-09T19:24:30Z")

</div>

> [@yquirion](#):
>
> After asking my friend Google, it told me that means "multi-line". Is it correct?

That is correct. By default a regexp will not match multiple lines, so you have to use (?m) to make it do so.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 7, 2021, 7:25pm UTC](https://discuss.elastic.co/t/get-the-first-line-of-message-field-coming-from-winlogbeat/288768/8 "2021-12-07T19:25:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
