# Logstash forwarding MSFT Server logs into Azure

**URL:** <https://discuss.elastic.co/t/logstash-forwarding-msft-server-logs-into-azure/281708>\
**Category:** Logstash\
**Created:** [August 17, 2021, 2:56pm UTC](https://discuss.elastic.co/t/logstash-forwarding-msft-server-logs-into-azure/281708 "2021-08-17T14:56:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![JBHuber](https://avatars.discourse-cdn.com/v4/letter/j/eb8c5e/32.png) [@JBHuber](https://discuss.elastic.co/u/JBHuber)\
**Post date:** [August 17, 2021, 2:56pm UTC](https://discuss.elastic.co/t/logstash-forwarding-msft-server-logs-into-azure/281708/1 "2021-08-17T14:56:31Z")

</div>

Hoping someone here has tried to do this same thing.

We are using Logstash as a forwarder of linux & windows logs into MSFT Azure Sentinel.

We do segregate (or TAG) the logs as "windows" and "linux". Linux is fine and it's a simple rsyslog configuration to send to Logstash who then send to Azure.

Microsoft...we use nxlog to send system and security logs to Logstash, who sends them on to Azure as JSON, it all works, however...

Azure Sentinel has a limit of 500 columns on a "log type" and the Windows servers routinely blow that out and then Azure starts throwing their logs on the floor.

Has anyone to any kind of filtering on the logstash side to get rid of all the "junk" from the Windows servers that nobody needs ?

Thanks for any ideas, pointers, help.

Jim

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 17, 2021, 4:45pm UTC](https://discuss.elastic.co/t/logstash-forwarding-msft-server-logs-into-azure/281708/2 "2021-08-17T16:45:54Z")

</div>

If you are dealing with top level fields then you may be able to do it with a prune filter, either with blacklist\_names or whitelist\_names.

Another option would be to create a file that lists all the fields you want to keep

```auto
@timestamp
@version
host
message
path
field1
field3

```

```
    ruby {
        init => '
            @fields = {}
            File.foreach( "/home/user/fields.txt" ) do |line|
                @fields[line.chomp] = true
            end
        '
        code => '
            event.to_hash.each { |k, v|
                unless @fields[k]
                    event.remove(k)
                end
            }
        '
    }

```

If nested fields are involved then it gets much more complicated.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2021, 4:46pm UTC](https://discuss.elastic.co/t/logstash-forwarding-msft-server-logs-into-azure/281708/3 "2021-09-14T16:46:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
