# "message" filed missing from windows event logs

**URL:** <https://discuss.elastic.co/t/message-filed-missing-from-windows-event-logs/137854>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [June 28, 2018, 7:28pm UTC](https://discuss.elastic.co/t/message-filed-missing-from-windows-event-logs/137854 "2018-06-28T19:28:38Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)\
**Post date:** [June 28, 2018, 7:28pm UTC](https://discuss.elastic.co/t/message-filed-missing-from-windows-event-logs/137854/1 "2018-06-28T19:28:38Z")

</div>

Hi,

I am sending all the event logs to Logstash using Winlogbeat. Here is part of Winlogbeat.yml,

```
winlogbeat.event_logs:
  - name: Application
    level: error, warning, info

output.logstash:
  # The Logstash hosts
  hosts: ["localhost:5044"]

```

Issue is that - I can see error message in Windows event viewer but there is no "message" field at all for some events when checked in Kibana. I am not able to find what the issue is. Here is Logstash config file,

```
input {
	beats {
		port => 5044
	}
}

filter{
	
	mutate{
		add_field =>{"app_name" => "***"}
		add_field =>{"time" => "%{@timestamp}"}
		rename => {"[beat][name]" => "source_host"}
		remove_field => ["event_data", "tags", "[beat][hostname]", "[beat][version]"]
	}
	
	
}

output {
	http {
       url=> "http:// *****"
        http_method=> "post"
        format=> "json"
    }

}

```

Can someone please help me with the issue?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 28, 2018, 7:50pm UTC](https://discuss.elastic.co/t/message-filed-missing-from-windows-event-logs/137854/2 "2018-06-28T19:50:14Z")

</div>

Winlogbeat will add a `message_error` field if it cannot provide a `message`.

- [Winlogbeat field list](https://www.elastic.co/guide/en/beats/winlogbeat/current/exported-fields-eventlog.html)

---

<div class="post-metadata">

**Author:** ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)\
**Post date:** [June 28, 2018, 7:57pm UTC](https://discuss.elastic.co/t/message-filed-missing-from-windows-event-logs/137854/3 "2018-06-28T19:57:26Z")

</div>

Hi Andrew,

There is no `message_error` field either. It says `level:error` in kibana but there's no `message` or `message_error` field.

I know that Logstash by default would add `message` field unless we explicitly drop that field but here I don't see message field at all.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 28, 2018, 8:32pm UTC](https://discuss.elastic.co/t/message-filed-missing-from-windows-event-logs/137854/4 "2018-06-28T20:32:42Z")

</div>

What version of Winlogbeat are you running? And what OS version?

If you can turn on debug logging this will give you some more detail about the events on the Winlogbeat side. The log will then contain the raw XML received from Windows so we can see if it has any rendering errors in it (these are what will be added to `message_error`).

```auto
logging.level: debug
logging.selectors: [eventlog, eventlog_detail, publish]

```

---

<div class="post-metadata">

**Author:** ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)\
**Post date:** [July 16, 2018, 3:31pm UTC](https://discuss.elastic.co/t/message-filed-missing-from-windows-event-logs/137854/5 "2018-07-16T15:31:51Z")

</div>

> [@andrewkroh](#):
>
> What version of Winlogbeat are you running? And what OS version?

I am using winlogbeat 5.5.0

Here is the xml,

```
<Event xmlns='http://example.com'><System><Provider Name='test'/><EventID Qualifiers='1000'>0</EventID><Level>4</Level><Task>0</Task><Keywords>xxxx</Keywords><TimeCreated SystemTime='2018-07-12T16:56:54.000000000Z'/><EventRecordID>4153686</EventRecordID><Channel>Application</Channel><Computer>xxxxxx</Computer><Security/></System><EventData><Data>Timestamp Local: 7/12/2018 16:56:54 AM
Message: some message
Category: General
Priority: 3
EventId: 0
Severity: Information
Title:example
Machine: xxxxx
Application Domain: xxxxx
Process Id: 14335536
Process Name: c:\windows\system32\inetsrv\w3wp.exe
Win32 Thread Id: 324556
Thread Name: 
Extended Properties: xxxx
SessionID - xxxx
MemberId - xxxx
ClientID - xxxx
CampaignID - xxx
</Data></xxxx><RenderingInfo Culture='en-US'><Message></Message><Level>Information</Level><Task></Task><Opcode>Info</Opcode><Channel></Channel><Provider></Provider><Keywords><Keyword>Classic</Keyword></Keywords></RenderingInfo></Event>

```

Please let me know the issue..

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 16, 2018, 5:57pm UTC](https://discuss.elastic.co/t/message-filed-missing-from-windows-event-logs/137854/6 "2018-07-16T17:57:44Z")

</div>

> [@amruth](#):
>
> \<Message\>\</Message\>

It looks like there is no message contained in the event from Windows. Nor is there a rendering error. There might be an issue with the application that is logging the message (in particular the [message text file](https://docs.microsoft.com/en-us/windows/desktop/EventLog/reporting-an-event)).

As a workaround you could use Logstash to copy the `event_data.Data` value to `message` when you see this event ID value in the Application log and it does not have a message.

---

<div class="post-metadata">

**Author:** ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)\
**Post date:** [July 17, 2018, 3:11pm UTC](https://discuss.elastic.co/t/message-filed-missing-from-windows-event-logs/137854/7 "2018-07-17T15:11:55Z")

</div>

> [@andrewkroh](#):
>
> As a workaround you could use Logstash to copy the `event_data.Data` value to `message` when you see this event ID value in the Application log and it does not have a message.

Could you please help me with this?

---

<div class="post-metadata">

**Author:** ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)\
**Post date:** [July 17, 2018, 7:23pm UTC](https://discuss.elastic.co/t/message-filed-missing-from-windows-event-logs/137854/8 "2018-07-17T19:23:53Z")

</div>

I used to drop event\_data field using mutate filter in Logstash

```
mutate{
       remove_field => ["event_data"]
}

```

Now, I am not dropping this field, so in some documents I see just one filed as event\_data.param1(which contains the message) but in some cases I see lot of fields event\_data.param1 to event\_data.param30. In this case event\_data.param1 would contain an integer(not the message).

Please say if I am missing anything here. My goal is to combine all these fields into a single field "message" instead of having 30 different fields.

Thanks

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 17, 2018, 10:04pm UTC](https://discuss.elastic.co/t/message-filed-missing-from-windows-event-logs/137854/9 "2018-07-17T22:04:51Z")

</div>

> [@amruth](#):
>
> Could you please help me with this?

Assuming the application creates just this one event with the problem, then I'd put a condition around the logic so that it does not affect other events.

```auto
filters {
  if ![message] and [event_data][param1] and [log_name] == "Application" and [source_name] == "test" and [event_id] == 0 {
    mutate {
      rename => {
        "[event_data][param1]" => "message"
      }
    }
  }
}

```

This may need some tweaking since I am not working off the real data.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 17, 2018, 10:15pm UTC](https://discuss.elastic.co/t/message-filed-missing-from-windows-event-logs/137854/10 "2018-07-17T22:15:03Z")

</div>

Or if this is affecting all events being logged by this one application then you could do a hack like this to convert the parameters logged by the application to a json string and put that into `message`. I must say that is the opposite of what most users do; mostly they want to have each piece of data is its own field in order to do various types of analysis or aggregations.

```auto
filter {
  if ![message] and [event_data][param1] and [log_name] == "Application" and [source_name] == "test" {
    json_encode {
      source => "event_data"
      target => "message"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)\
**Post date:** [July 23, 2018, 3:33pm UTC](https://discuss.elastic.co/t/message-filed-missing-from-windows-event-logs/137854/11 "2018-07-23T15:33:43Z")

</div>

Thanks Andrew. Will try it 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 20, 2018, 3:33pm UTC](https://discuss.elastic.co/t/message-filed-missing-from-windows-event-logs/137854/12 "2018-08-20T15:33:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
