# Фильтрация Message в логах Winlogbeat

**URL:** <https://discuss.elastic.co/t/message-winlogbeat/211456>\
**Category:** Вопросы на русском языке\
**Created:** [December 11, 2019, 11:08am UTC](https://discuss.elastic.co/t/message-winlogbeat/211456 "2019-12-11T11:08:57Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![KOTOXJle6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kotoxjle6/32/131136_2.png) [@KOTOXJle6](https://discuss.elastic.co/u/KOTOXJle6)\
**Post date:** [December 11, 2019, 11:08am UTC](https://discuss.elastic.co/t/message-winlogbeat/211456/1 "2019-12-11T11:08:57Z")

</div>

Добрый день.

Планируем собирать логи авторизаций на контроллерах домена, чтобы смотреть кто логинится под одной учётной записью на несколько компьютеров. Поставили сбор событий с кодом 4,624, но есть одна проблема - логов очень много и бОльшая часть текста в поле message в таких сообщениях лишняя. Есть ли какой-нибудь способ разбивать поле message на несколько более мелких полей, чтобы удалять ненужную информацию? В идеале без grok, так как даже не представляю насколько огромным будет выражение для таких логов.

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [December 11, 2019, 4:07pm UTC](https://discuss.elastic.co/t/message-winlogbeat/211456/2 "2019-12-11T16:07:05Z")

</div>

[https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest.html)

---

<div class="post-metadata">

**Author:** ![KOTOXJle6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kotoxjle6/32/131136_2.png) [@KOTOXJle6](https://discuss.elastic.co/u/KOTOXJle6)\
**Post date:** [December 11, 2019, 4:57pm UTC](https://discuss.elastic.co/t/message-winlogbeat/211456/3 "2019-12-11T16:57:29Z")

</div>

В моем случае вероятно подойдет вот это ?[https://www.elastic.co/guide/en/elasticsearch/reference/current/split-processor.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/split-processor.html)

Если я правильно понимаю, ingest работает для всех входящих логов вообще. Разве его можно применить только к тем, в которых будет event.code 4624?

---

<div class="post-metadata">

**Author:** ![KOTOXJle6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kotoxjle6/32/131136_2.png) [@KOTOXJle6](https://discuss.elastic.co/u/KOTOXJle6)\
**Post date:** [December 12, 2019, 10:49am UTC](https://discuss.elastic.co/t/message-winlogbeat/211456/4 "2019-12-12T10:49:46Z")

</div>

Кажется нашел подходящий фильтр - [https://www.elastic.co/guide/en/logstash/current/plugins-filters-split.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-split.html). Он как раз разбивает message построчно, только на каждую строчку создает отдельный документ. Теперь буду разбираться как их объединить в один, но только по нужным строкам. Если подскажете в каком направлении смотреть, буду очень признателен.

---

<div class="post-metadata">

**Author:** ![KOTOXJle6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kotoxjle6/32/131136_2.png) [@KOTOXJle6](https://discuss.elastic.co/u/KOTOXJle6)\
**Post date:** [December 19, 2019, 9:28am UTC](https://discuss.elastic.co/t/message-winlogbeat/211456/5 "2019-12-19T09:28:51Z")

</div>

Оказалось я пропустил один фильтр, который был настроен на удаление всех полей, кроме message. По умолчанию события, полученные через winlogbeat, уже разбиваются на нужные строки, нужно было только убрать лишнее. Решил это вот так:

winlogbeat:

```
processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~
  - drop_fields:
      fields: [winlog.event_data.ElevatedToken, winlog.event_data.ImpersonationLevel, winlog.event_data.KeyLength, winlog.event_data.LmPackageName, winlog.event_data.LogonGuid, winlog.event_data.RestrictedAdminMode, winlog.event_data.TargetLinkedLogonId, winlog.provider_guid, winlog.process.pid, winlog.event_data.TargetLogonId, winlog.event_data.TargetOutboundDomainName, winlog.event_data.TargetOutboundUserName, winlog.event_data.TargetUserSid, winlog.event_data.TransmittedServices, winlog.event_data.VirtualAccount, winlog.keywords, winlog.opcode, winlog.provider_name, winlog.record_id, winlog.process.thread.id, winlog.version]

```

logstash:

```
# Domain Controllers logs filtering

    if "windc" in [tags] and [event][code] == 4776 and [winlog][event_data][Status] == "0x0" {
        drop {}

  }

    if "windc" in [tags] and [event][code] == 4776 {
        prune {
        remove_field => ["[agent][id]","[agent][ephemeral_id]","[agent][hostname]","[agent][type]","[agent][version]","[ecs][version]","[event][kind]","[host][architecture]","[host][hostname]","[host][os][build]","[host][os][family]","[host][os][kernel]","[host][os][platform]","[host][os][version]"]
        blacklist_names => ["^.*winlog.*"]

        }
  }

# Domain Controllers logon events

    if "windc" in [tags] and [event][code] == 4624 and [winlog][event_data][TargetUserName] == "admin1 or [winlog][event_data][TargetUserName] == "admin2" {
        drop {}

  }

    if "windc" in [tags] and [event][code] == 4624 {
        prune {
        remove_field => ["[agent][id]","[agent][ephemeral_id]","[agent][hostname]","[agent][type]","[agent][version]","[ecs][version]","[event][kind]","[host][architecture]","[host][hostname]","[host][os][build]","[host][os][family]","[host][os][kernel]","[host][os][platform]","[host][os][version]"]
        blacklist_names => ["message"]
        }
  }

```

Получилось немного громоздко, но в целом то, что нужно. Можно будет еще немного подкрутить фильтры, чтобы сбрасывать лишние события, а оставшиеся еще чуть больше подрезать. Но даже так дневной индекс уменьшился с 10ГБ до 4ГБ.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 16, 2020, 9:28am UTC](https://discuss.elastic.co/t/message-winlogbeat/211456/6 "2020-01-16T09:28:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
