# Removing "winlog" prefix in winlogbeat

**URL:** <https://discuss.elastic.co/t/removing-winlog-prefix-in-winlogbeat/242344>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [July 23, 2020, 1:31pm UTC](https://discuss.elastic.co/t/removing-winlog-prefix-in-winlogbeat/242344 "2020-07-23T13:31:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ssiws](https://avatars.discourse-cdn.com/v4/letter/s/4af34b/32.png) [@ssiws](https://discuss.elastic.co/u/ssiws)\
**Post date:** [July 23, 2020, 1:31pm UTC](https://discuss.elastic.co/t/removing-winlog-prefix-in-winlogbeat/242344/1 "2020-07-23T13:31:34Z")

</div>

Hello,

I'm upgrading winlogbeat 5.4.1 to 7.8.0. I saw that some fields are now prefixed by "winlog" (example: **event\_id** became **winlog\_event\_id** ).

Is there a setting, or is it possible to add rule to remove this prefix ? I saw the "rename" processor, but you can't use a rename pattern and I don't want to list all the fields to rename.

Thanks

EDIT: In fact, it's not a prefix but [event\_id] is nested in [winlog]. So, is it possible to remove the additional [winlog] ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 20, 2020, 3:31pm UTC](https://discuss.elastic.co/t/removing-winlog-prefix-in-winlogbeat/242344/2 "2020-08-20T15:31:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
