# Logstash: creating new fields from windows event log

**URL:** <https://discuss.elastic.co/t/logstash-creating-new-fields-from-windows-event-log/138541>\
**Category:** Logstash\
**Created:** [July 4, 2018, 11:04am UTC](https://discuss.elastic.co/t/logstash-creating-new-fields-from-windows-event-log/138541 "2018-07-04T11:04:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![solaris](https://avatars.discourse-cdn.com/v4/letter/s/43a26b/32.png) [@solaris](https://discuss.elastic.co/u/solaris)\
**Post date:** [July 4, 2018, 11:04am UTC](https://discuss.elastic.co/t/logstash-creating-new-fields-from-windows-event-log/138541/1 "2018-07-04T11:04:53Z")

</div>

Hi, please don't judge me too harsh. I'm new to ELK and have question regarding creation of new fields from windows log in logstash. Windows logs are forwarded to logstash by winlogbeat plugin.  
I need extract eventlog subject from eventlog and create new field from it. In the following image its  
"Special privileges assigned to new logon." message.  
 ![Capture1](https://us1.discourse-cdn.com/elastic/original/3X/5/1/51d988a214f3878a9d22494707183c86f4d5905e.JPG)  
Standart winlogbeat "message" field extracts whole message text as in the following picture.  
 ![Capture2](https://us1.discourse-cdn.com/elastic/original/3X/e/2/e29ba776026ae2aa8e86082d412a898dbddb893f.JPG)  
I additionally need "Special privileges assigned to new logon." message as a new filed lets say "message\_small".

Could you please list all neccesary steps for this.  
Thanks in advance

---

<div class="post-metadata">

**Author:** ![solaris](https://avatars.discourse-cdn.com/v4/letter/s/43a26b/32.png) [@solaris](https://discuss.elastic.co/u/solaris)\
**Post date:** [July 5, 2018, 1:13pm UTC](https://discuss.elastic.co/t/logstash-creating-new-fields-from-windows-event-log/138541/2 "2018-07-05T13:13:58Z")

</div>

anyone can help me?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2018, 1:29pm UTC](https://discuss.elastic.co/t/logstash-creating-new-fields-from-windows-event-log/138541/3 "2018-08-02T13:29:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
