Parse MSSQL logs from event log

Im trying to parse MSSQL logs from Windows event log, into Elastic stack.
Currently MSSQL logs to event viewer, and i use Winlogbeat 7,6 and Elastic stack 7,6 also. (installed under 1 month ago)
indent preformatted text by 4 spaces
Currently, all the MSSQL event logs goes into the message field, without getting parsed to seperate fields like it should.

Basically it seems like the same issue as Parsing additional data in a windows event log

I am unsucsessful in using gsub to replace the delimiter, and was hoping for some guidance on the parsing.


    input {
      beats {
        port => 5044
            tags => [ "winlogbeat2" ]


filter {
  mutate {
gsub => [
  "message", "[\\n]", ","
    output {
      elasticsearch {
        hosts => ["http://localhost:9200"]
        index => "%{[@metadata][beat]}-%{[@metadata][version]}"

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.