Logstash: creating new fields from windows event log


#1

Hi, please don't judge me too harsh. I'm new to ELK and have question regarding creation of new fields from windows log in logstash. Windows logs are forwarded to logstash by winlogbeat plugin.
I need extract eventlog subject from eventlog and create new field from it. In the following image its
"Special privileges assigned to new logon." message.
Capture1
Standart winlogbeat "message" field extracts whole message text as in the following picture.
Capture2
I additionally need "Special privileges assigned to new logon." message as a new filed lets say "message_small".

Could you please list all neccesary steps for this.
Thanks in advance


#2

anyone can help me?


(system) #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.