# Split "event\_data" to only show the original data field

**URL:** <https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-data-field/78561>\
**Category:** Logstash\
**Created:** [March 14, 2017, 4:46pm UTC](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-data-field/78561 "2017-03-14T16:46:51Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![peanut](https://avatars.discourse-cdn.com/v4/letter/p/b5e925/32.png) [@peanut](https://discuss.elastic.co/u/peanut)\
**Post date:** [March 16, 2017, 10:43pm UTC](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-data-field/78561/3 "2017-03-16T22:43:24Z")

</div>

I have been reading since I posted this two days ago and I found this post in this forum:

> [@Event messages are splitted in event\_data.param xy? How to fix that?](https://discuss.elastic.co/t/event-messages-are-splitted-in-event-data-param-xy-how-to-fix-that/61087/2):
>
> Assuming that the events were forwarded from the original host to the collector in "RenderedText" format, then they should have a message field that contains the full text of the event. The event\_data.\* fields are the raw data that was provided by the application that logged the event. This is included in the event published by Winlogbeat so that you don't have to grok the message field to extract data needed for other analysis you might want to do. To debug the issue I would add the [include\_xm…](https://www.elastic.co/guide/en/beats/winlogbeat/5.0/configuration-winlogbeat-options.html#_event_logs_include_xml)

"The event\_data.\* fields are the raw data that was provided by the application that logged the event. This is included in the event published by Winlogbeat so that you don't have to grok the message field to extract data needed for other analysis you might want to do."

So all new data fields from, for example, Sysmon logs, have the event\_data name at the beginning .

event\_data.CommandLine  
event\_data.ProcessName

I was wondering if I could split that and only show the original Field name. For example, following the two examples that i provided, "CommandLine" & "ProcessName".

After a lot of reading, I think thats how Winlogbeat send the logs to Logstash and mutating.renaming logs will cause some performance issues . correct? Is it normal to leave the field names like that with event\_data at the beginning? This is my first time working with winlogbeat and ELK. If so, then I dont have to do anything to them and work with them named that way.

thank you

---

_[View the full topic](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-data-field/78561)._
