# Split "event\_data" to only show the original data field

**URL:** <https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-data-field/78561>\
**Category:** Logstash\
**Created:** [March 14, 2017, 4:46pm UTC](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-data-field/78561 "2017-03-14T16:46:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![peanut](https://avatars.discourse-cdn.com/v4/letter/p/b5e925/32.png) [@peanut](https://discuss.elastic.co/u/peanut)\
**Post date:** [March 14, 2017, 4:46pm UTC](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-data-field/78561/1 "2017-03-14T16:46:51Z")

</div>

Good afternoon elastic community,

Is it best practice to mutate all the fields with the "event\_data" attached to it to its original data field name? If so, what is the easiest way to do it in a filter? I am forwarding native Windows events and also Sysmon Events. I am forwarding my logs with Winlogbeat 5.2.1 and my logstash configurations are the following:

02-beats-input.conf

input {  
beats {  
port =\> 5044  
add\_field =\> { "[@metadata][source]" =\> "winlogbeat" }  
}

50-elasticsearch-output.conf

output {  
if [@metadata][source] == "winlogbeat" {  
elasticsearch {  
hosts = ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![whyapenny](https://avatars.discourse-cdn.com/v4/letter/w/90db22/32.png) [@whyapenny](https://discuss.elastic.co/u/whyapenny)\
**Post date:** [March 16, 2017, 4:46am UTC](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-data-field/78561/2 "2017-03-16T04:46:49Z")

</div>

I dont think the question is clear.

---

<div class="post-metadata">

**Author:** ![peanut](https://avatars.discourse-cdn.com/v4/letter/p/b5e925/32.png) [@peanut](https://discuss.elastic.co/u/peanut)\
**Post date:** [March 16, 2017, 10:43pm UTC](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-data-field/78561/3 "2017-03-16T22:43:24Z")

</div>

I have been reading since I posted this two days ago and I found this post in this forum:

> [@Event messages are splitted in event\_data.param xy? How to fix that?](https://discuss.elastic.co/t/event-messages-are-splitted-in-event-data-param-xy-how-to-fix-that/61087/2):
>
> Assuming that the events were forwarded from the original host to the collector in "RenderedText" format, then they should have a message field that contains the full text of the event. The event\_data.\* fields are the raw data that was provided by the application that logged the event. This is included in the event published by Winlogbeat so that you don't have to grok the message field to extract data needed for other analysis you might want to do. To debug the issue I would add the [include\_xm…](https://www.elastic.co/guide/en/beats/winlogbeat/5.0/configuration-winlogbeat-options.html#_event_logs_include_xml)

"The event\_data.\* fields are the raw data that was provided by the application that logged the event. This is included in the event published by Winlogbeat so that you don't have to grok the message field to extract data needed for other analysis you might want to do."

So all new data fields from, for example, Sysmon logs, have the event\_data name at the beginning .

event\_data.CommandLine  
event\_data.ProcessName

I was wondering if I could split that and only show the original Field name. For example, following the two examples that i provided, "CommandLine" & "ProcessName".

After a lot of reading, I think thats how Winlogbeat send the logs to Logstash and mutating.renaming logs will cause some performance issues . correct? Is it normal to leave the field names like that with event\_data at the beginning? This is my first time working with winlogbeat and ELK. If so, then I dont have to do anything to them and work with them named that way.

thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2017, 10:43pm UTC](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-data-field/78561/4 "2017-04-13T22:43:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
