# How to convert "Selection Fields" to code?

**URL:** <https://discuss.elastic.co/t/how-to-convert-selection-fields-to-code/98087>\
**Category:** Kibana\
**Created:** [August 23, 2017, 1:55pm UTC](https://discuss.elastic.co/t/how-to-convert-selection-fields-to-code/98087 "2017-08-23T13:55:41Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![hack3rcon](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@hack3rcon](https://discuss.elastic.co/u/hack3rcon)\
**Post date:** [August 23, 2017, 1:55pm UTC](https://discuss.elastic.co/t/how-to-convert-selection-fields-to-code/98087/1 "2017-08-23T13:55:42Z")

</div>

Hello.  
I forward my windows Event Log via "Winlogbeat" to my Linux box that I installed "Elasticsearch" and "Kibana" on it. I can customize my Event logs via "Selection Fields" but I must create it each time that I open "Kibana", How can I write a config file that do it automatically for me?

 ![Untitled](https://us1.discourse-cdn.com/elastic/original/3X/7/c/7c8c674f5c3ec60519d5ec753f46c5d459359fb1.png)

Thank you.

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [August 23, 2017, 6:00pm UTC](https://discuss.elastic.co/t/how-to-convert-selection-fields-to-code/98087/2 "2017-08-23T18:00:18Z")

</div>

I'm not super familiar with winlog beat personally, but I've used filebeat before, and the trick was to configure the beat to correctly parse the information that it was ingesting. Winlogbeat looks the similar, and offers ways to [configure and enrich the input](https://www.elastic.co/guide/en/beats/winlogbeat/current/filtering-and-enhancing-data.html) from the events. If you need really powerful enrichment (which shouldn't be required in this case, the issue here is more about parsing), you can check out the [docs on using ingest node](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuring-ingest-node.html).

---

<div class="post-metadata">

**Author:** ![hack3rcon](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@hack3rcon](https://discuss.elastic.co/u/hack3rcon)\
**Post date:** [August 27, 2017, 9:15am UTC](https://discuss.elastic.co/t/how-to-convert-selection-fields-to-code/98087/3 "2017-08-27T09:15:14Z")

</div>

Thank you. I just need to extract some fields.  
"drop" command will remove fields or it is the fields that I needed?

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [August 28, 2017, 4:06pm UTC](https://discuss.elastic.co/t/how-to-convert-selection-fields-to-code/98087/4 "2017-08-28T16:06:48Z")

</div>

I'm not sure what you are asking about. What drop command?

---

<div class="post-metadata">

**Author:** ![hack3rcon](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@hack3rcon](https://discuss.elastic.co/u/hack3rcon)\
**Post date:** [August 29, 2017, 8:02am UTC](https://discuss.elastic.co/t/how-to-convert-selection-fields-to-code/98087/5 "2017-08-29T08:02:41Z")

</div>

I saw it in the examples. What this command doing?

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [August 29, 2017, 4:28pm UTC](https://discuss.elastic.co/t/how-to-convert-selection-fields-to-code/98087/6 "2017-08-29T16:28:09Z")

</div>

Are you talking about the `drop_fields` processor in the example? It's one of the Beats [processors](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-processors.html), which are used to process data before it is indexed.

You can find the docs for that specific processor [here](https://www.elastic.co/guide/en/beats/winlogbeat/current/drop-fields.html).

---

<div class="post-metadata">

**Author:** ![hack3rcon](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@hack3rcon](https://discuss.elastic.co/u/hack3rcon)\
**Post date:** [September 1, 2017, 11:18am UTC](https://discuss.elastic.co/t/how-to-convert-selection-fields-to-code/98087/7 "2017-09-01T11:18:50Z")

</div>

Thank you.  
To be honest, I don't like you spoon me but I'm a non geek and I want to know can you show me an example or write an example that extract "Subject", "Object" and "Accesses" from "message" ?

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [September 1, 2017, 4:46pm UTC](https://discuss.elastic.co/t/how-to-convert-selection-fields-to-code/98087/8 "2017-09-01T16:46:07Z")

</div>

Haha, it's no problem. All this stuff can be overwhelming, and guidance is what the forums are for, right?

Unfortunately, I'm not really a Beats user though. I used Filebeat once and poked at it just long enough to get what I was trying to do working. I don't even remember what it was I was doing, let alone how I did it. I could probably dig through everything and point you to some more spots in the documentation, but I wouldn't have any more insight than you would finding those resources on your own.

I'd recommend asking over in the [Beats section of the forums](https://discuss.elastic.co/c/beats) for help. That's monitored by the folks the work on Beats, they certainly know a lot more than I do. 😉

---

<div class="post-metadata">

**Author:** ![hack3rcon](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@hack3rcon](https://discuss.elastic.co/u/hack3rcon)\
**Post date:** [September 6, 2017, 5:52am UTC](https://discuss.elastic.co/t/how-to-convert-selection-fields-to-code/98087/9 "2017-09-06T05:52:50Z")

</div>

I created a [thread](https://discuss.elastic.co/t/extract-windows-event-log-fields/99185) but not get any reply ☹

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2017, 5:53am UTC](https://discuss.elastic.co/t/how-to-convert-selection-fields-to-code/98087/10 "2017-10-04T05:53:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
