# Log Data in ES from CloudWatch log

**URL:** <https://discuss.elastic.co/t/log-data-in-es-from-cloudwatch-log/160935>\
**Category:** Kibana\
**Created:** [December 14, 2018, 4:05pm UTC](https://discuss.elastic.co/t/log-data-in-es-from-cloudwatch-log/160935 "2018-12-14T16:05:51Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Francesco\_De\_Nardi](https://avatars.discourse-cdn.com/v4/letter/f/c2a13f/32.png) [@Francesco\_De\_Nardi](https://discuss.elastic.co/u/Francesco_De_Nardi)\
**Post date:** [December 14, 2018, 4:05pm UTC](https://discuss.elastic.co/t/log-data-in-es-from-cloudwatch-log/160935/1 "2018-12-14T16:05:51Z")

</div>

Hi,

I do not know how to solve a problem .. I try to explain ... I have centralized logs on AWS CloudWatch and I send these logs to an instance of elasticsearch through Lambda function.  
I create a newspaper index for each log.  
only that on elasticsearch it creates me only 16 fields (@id  
id.keyword  
log\_group  
log\_group.keyword  
log\_stream  
log\_stream.keyword  
message  
message.keyword  
owner  
owner.keyword  
timestamp  
\_id  
\_index  
\_score  
\_source  
\_type  
) and the record of the log inside the fields (@message). and with only these 16 fields I can not create correct views.  
for example if I collect the active directory logs from cloudwatch I will find all the log records in the @message field and I can not separate the windows eventid.  
I know that you should use winlogon beats to collect the logs correctly but since I already have the logs in the cloudwatch I preferred to use it.  
is there a solution?  
can someone help me?

Thanks a lot

---

<div class="post-metadata">

**Author:** ![bryan\_stuhlsatz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bryan_stuhlsatz/32/49123_2.png) [@bryan\_stuhlsatz](https://discuss.elastic.co/u/bryan_stuhlsatz)\
**Post date:** [December 15, 2018, 10:27pm UTC](https://discuss.elastic.co/t/log-data-in-es-from-cloudwatch-log/160935/2 "2018-12-15T22:27:57Z")

</div>

If you wrote a lamda function to process the events, you should be able to modify your function to create the fields that you want, instead of putting them all in the message field. You could also create a pipeline that can do the same thing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 12, 2019, 10:27pm UTC](https://discuss.elastic.co/t/log-data-in-es-from-cloudwatch-log/160935/3 "2019-01-12T22:27:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
