Parsing additional data in a windows event log

One additional tidbit. In Logstash I am able to duplicate the message field into a new field but unable to parse that new field either.