Winlogbeat fields name:
"event_data": {
"ProcessName"
"LogonGuid"
"IpPort"
"SubjectLogonId"
"TargetLogonGuid"
"SubjectUserName"
"TargetInfo"
"TargetServerName"
"SubjectDomainName"
"IpAddress"
"TargetUserName"
"ProcessId"
"TargetDomainName"
"SubjectUserSid"
},
But I wish
"ProcessName"
"LogonGuid"
"IpPort"
"SubjectLogonId"
"TargetLogonGuid"
"SubjectUserName"
"TargetInfo"
"TargetServerName"
"SubjectDomainName"
"IpAddress"
"TargetUserName"
"ProcessId"
"TargetDomainName"
"SubjectUserSid"
So how can I remove "event_data" from every fields?
need help.
Thanks