# O365.audit to message field

**URL:** <https://discuss.elastic.co/t/o365-audit-to-message-field/286396>\
**Category:** Logstash\
**Created:** [October 11, 2021, 5:08pm UTC](https://discuss.elastic.co/t/o365-audit-to-message-field/286396 "2021-10-11T17:08:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![geetika\_gopi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/geetika_gopi/32/93548_2.png) [@geetika\_gopi](https://discuss.elastic.co/u/geetika_gopi)\
**Post date:** [October 11, 2021, 5:08pm UTC](https://discuss.elastic.co/t/o365-audit-to-message-field/286396/1 "2021-10-11T17:08:35Z")

</div>

Hello,

I have O365 logs coming in to my logstash via the O365 filebeat module. I am trying to create two outputs :

1. Elasticsearch output
2. S3 bucket output

The S3 bucket output requires a "message" field to be present. For other log sources I used a mutate filter to create the "message" field if required, and move the raw event to "message".  
But for O365 there is no such raw event. I know that I want to move the nested o365.audit JSON object to the message field. But im not sure how to do it (tried many possible ways to do so)

sample o365.audit field

```auto
"o365": {
      "audit": {
        "RecordType": x,
        "Parameters": {
          "SyncMailboxLocationGuids": "x",
          "Identity": "x",
          "WarningAction": "x",
          "ErrorAction": "x"
        },
        "ObjectId": "x",
        "OriginatingServer": "x",
        "UserKey": "x",
        "CreationTime": "x",
        "Version": x,
        "UserType": x,
        "UserId": "x",
        "ClientAppId": "",
        "OrganizationId": "x",
        "AppId": "",
        "Operation": "x",
        "ExternalAccess": x,
        "Id": "x",
        "OrganizationName": "x",
        "Workload": "x",
        "ResultStatus": "x"
      }
    },
    "event": {
      "action": "x",
      "id": "x",
      "type": "x",
      "provider": "x",
      "code": "x",
      "dataset": "x",
      "kind": "x",
      "module": "x",
      "category": "x",
      "outcome": "x"
    },
    "host": {
      "name": "x",
      "id": "x"
    },
    "@version": "x",
    "fileset": {
      "name": "x"
    },
    "@timestamp": "x"
  },
  "fields": {
    "@timestamp": [
      "x"
    ],
    "o365.audit.CreationTime": [
      "x"
    ]
  },
  "sort": [
    x
  ]
}

```

Any suggestions will be appreciated!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 11, 2021, 5:19pm UTC](https://discuss.elastic.co/t/o365-audit-to-message-field/286396/2 "2021-10-11T17:19:09Z")

</div>

Have you tried this?...

```
mutate { rename => { "[o365][audit]" => "message" } }
```

---

<div class="post-metadata">

**Author:** ![geetika\_gopi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/geetika_gopi/32/93548_2.png) [@geetika\_gopi](https://discuss.elastic.co/u/geetika_gopi)\
**Post date:** [October 16, 2021, 2:43pm UTC](https://discuss.elastic.co/t/o365-audit-to-message-field/286396/3 "2021-10-16T14:43:34Z")

</div>

This worked! Thank you 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 13, 2021, 2:44pm UTC](https://discuss.elastic.co/t/o365-audit-to-message-field/286396/4 "2021-11-13T14:44:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
