# How to extract first line of message from Winlogbeat

**URL:** <https://discuss.elastic.co/t/how-to-extract-first-line-of-message-from-winlogbeat/169466>\
**Category:** Logstash\
**Created:** [February 21, 2019, 4:52pm UTC](https://discuss.elastic.co/t/how-to-extract-first-line-of-message-from-winlogbeat/169466 "2019-02-21T16:52:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mark\_Tellier](https://avatars.discourse-cdn.com/v4/letter/m/c77e96/32.png) [@Mark\_Tellier](https://discuss.elastic.co/u/Mark_Tellier)\
**Post date:** [February 21, 2019, 4:52pm UTC](https://discuss.elastic.co/t/how-to-extract-first-line-of-message-from-winlogbeat/169466/1 "2019-02-21T16:52:45Z")

</div>

Winlogbeat is sending Windows Event logs to logstash and I would like to create a new field by extracting the first line of the message field.

`"message": "Special privileges assigned to new logon.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tCORP-DC02$\n\tAccount Domain:\t\tACME\n\tLogon ID:\t\t0x238BCEAE\n\nPrivileges:\t\tSeSecurityPrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeDebugPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeImpersonatePrivilege\n\t\t\tSeEnableDelegationPrivilege\n\t\t\tSeAssignPrimaryTokenPrivilege"`

I have tried many filter variations without success, here is my current but results in only a copy of the message, like it's unable to split the message by newline:

```
filter {

  mutate {
    copy => { "message" => "message_head" }
  }

  mutate {
    split => ["message_head", "\n"]
  }

  mutate {
    replace => { "message_head" => "%{message_head[0]}" }
  }

}

```

This is the result I am after:  
`message_head: Special privileges assigned to new logon.`

When testing the above filter sending a message with postman, it splits the string into an array and produces the desired results. However, I get a string copy of the message when received from Winlogbeat.

Any suggestions would be most appreciated.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 21, 2019, 5:30pm UTC](https://discuss.elastic.co/t/how-to-extract-first-line-of-message-from-winlogbeat/169466/2 "2019-02-21T17:30:24Z")

</div>

There is no fancy quoting or escaping in logstash configurations 🙂 You want a liternal newline embedded in the string.

```
    mutate { split => { "message" => "
" } }

```

Or [config.support\_escapes](https://www.elastic.co/guide/en/logstash/current/logstash-settings-file.html).

---

<div class="post-metadata">

**Author:** ![Mark\_Tellier](https://avatars.discourse-cdn.com/v4/letter/m/c77e96/32.png) [@Mark\_Tellier](https://discuss.elastic.co/u/Mark_Tellier)\
**Post date:** [February 21, 2019, 7:55pm UTC](https://discuss.elastic.co/t/how-to-extract-first-line-of-message-from-winlogbeat/169466/3 "2019-02-21T19:55:38Z")

</div>

Thanks for the recommendation Badger, but the output is now just "A", so looks like the string isn't being parsed and it's taking the first character.

```
filter {

  mutate {
    copy => { "message" => "message_head" }
  }

  mutate {
    split => ["message_head", ""]
  }

  mutate {
    replace => { "message_head" => "%{message_head[0]}" }
  }
}

```

Output:  
`"message_head": "A"`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 21, 2019, 8:41pm UTC](https://discuss.elastic.co/t/how-to-extract-first-line-of-message-from-winlogbeat/169466/4 "2019-02-21T20:41:32Z")

</div>

> [@Mark\_Tellier](#):
>
> mutate { split =\> ["message\_head", ""] }

That will split it into an array of several hundred single characters. So yes, "%{message\_head[0]}" will just pick up the first character of the original message.

---

<div class="post-metadata">

**Author:** ![Mark\_Tellier](https://avatars.discourse-cdn.com/v4/letter/m/c77e96/32.png) [@Mark\_Tellier](https://discuss.elastic.co/u/Mark_Tellier)\
**Post date:** [February 21, 2019, 9:28pm UTC](https://discuss.elastic.co/t/how-to-extract-first-line-of-message-from-winlogbeat/169466/5 "2019-02-21T21:28:49Z")

</div>

Badger, I finally understood what you were saying and it works perfect, thanks for helping me out. I've searched through the forums and read through the documentation and nowhere did I come across anything that refers to a literal return.

Here is my final filter:

```
filter {

  mutate {
    copy => { "message" => "message_head" }
  }

  mutate {
    split => ["message_head", "
"]}

  mutate {
    replace => { "message_head" => "%{message_head[0]}" }
  }

}

```

And a sample result:  
`"message_head": "An account was logged off."`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 21, 2019, 9:29pm UTC](https://discuss.elastic.co/t/how-to-extract-first-line-of-message-from-winlogbeat/169466/6 "2019-03-21T21:29:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
