# Logs are getting parsed in messages field for M365 Defender Logs

**URL:** <https://discuss.elastic.co/t/logs-are-getting-parsed-in-messages-field-for-m365-defender-logs/337698>\
**Category:** Elastic Agent\
**Created:** [July 5, 2023, 4:27pm UTC](https://discuss.elastic.co/t/logs-are-getting-parsed-in-messages-field-for-m365-defender-logs/337698 "2023-07-05T16:27:11Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![elastic12](https://avatars.discourse-cdn.com/v4/letter/e/d78d45/32.png) [@elastic12](https://discuss.elastic.co/u/elastic12)\
**Post date:** [July 5, 2023, 4:27pm UTC](https://discuss.elastic.co/t/logs-are-getting-parsed-in-messages-field-for-m365-defender-logs/337698/1 "2023-07-05T16:27:11Z")

</div>

The issue is with the logs in Microsoft 365 Defender. All of the logs are being stored in a single message field, instead of being stored in individual fields as shown in Elasticsearch documentation. Previously, the logs were able to be parsed into their respective individual fields. We have tried reconfiguring the logs, but the issue persists.  
We also have Azure Logs integration setup using same fleet agent and the Azure Logs are able to parse into individual fields.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/5/15951a54e6ceaff54ed0c2d09fda7e5b84875eb7.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2023, 4:27pm UTC](https://discuss.elastic.co/t/logs-are-getting-parsed-in-messages-field-for-m365-defender-logs/337698/2 "2023-08-02T16:27:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
