# Parsing the message field in security event.code 4624

**URL:** <https://discuss.elastic.co/t/parsing-the-message-field-in-security-event-code-4624/338046>\
**Category:** Logstash\
**Created:** [July 11, 2023, 1:37am UTC](https://discuss.elastic.co/t/parsing-the-message-field-in-security-event-code-4624/338046 "2023-07-11T01:37:31Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 11, 2023, 2:39am UTC](https://discuss.elastic.co/t/parsing-the-message-field-in-security-event-code-4624/338046/2 "2023-07-11T02:39:26Z")

</div>

[This](https://discuss.elastic.co/t/multiple-match-in-one-grok/246569) post is related to parsing these messages, but it's not the approach I would recommend. [This](https://discuss.elastic.co/t/grok-for-email-log/171750/4) post may be a better way of doing it.

---

_[View the full topic](https://discuss.elastic.co/t/parsing-the-message-field-in-security-event-code-4624/338046)._
