MY Logformat:
computer_name NAZ-TECH-PC-005.NTDAC.nazdaqTechnologies.local
event_data.TargetServerName VNTDACWSPRP001.NTDAC.nazdaqTechnologies.local
event_data.SubjectUserName Jhon
event_data.TargetUserName Tom
filter {
if [type] == "wineventlog" {
mutate {
remove_field => [ "tags", "opcode", "version", "beat", "message"]
}
mutate {
rename => [ "event_data.TargetServerName", "Target_fqdn" ]
rename => [ "computer_name", "source_fqdn" ]
rename => [ "event_data.TargetUserName", "Target_user" ]
rename => [ "data.SubjectUserName", "source_user" ]
}
}
}
source_fqdn NAZ-TECH-PC-005.NTDAC.nazdaqTechnologies.local
event_data.TargetServerName VNTDACWSPRP001.NTDAC.nazdaqTechnologies.local
event_data.SubjectUserName Jhon
event_data.TargetUserName Tom
Please help me to rename event_data. field name