# Split "event\_data" to only show the original field

**URL:** <https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-field/78587>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 14, 2017, 7:41pm UTC](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-field/78587 "2017-03-14T19:41:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![peanut](https://avatars.discourse-cdn.com/v4/letter/p/b5e925/32.png) [@peanut](https://discuss.elastic.co/u/peanut)\
**Post date:** [March 14, 2017, 7:41pm UTC](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-field/78587/1 "2017-03-14T19:41:37Z")

</div>

Good afternoon elastic community,

I posted this question on the Logstash section but I figured it would be helpful to get your Winlogbeat expertise too. Is it best practice to mutate all the fields with the "event\_data" attached to it to its original data field name? If so, what is the easiest way to do it in a filter? I am forwarding native Windows events and also Sysmon Events. I am forwarding my logs with Winlogbeat 5.2.1 and my logstash configurations are the following:

02-beats-input.conf

```auto
input {
beats {
port => 5044
add_field => { "[@metadata][source]" => "winlogbeat" }
}

```

50-elasticsearch-output.conf

```auto
output {
if [@metadata][source] == "winlogbeat" {
elasticsearch {
hosts = ["localhost:9200"]
sniffing => true
manage_template => false
index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
document_type => "%{[@metadata][type]}"
}
}
}

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 16, 2017, 3:18pm UTC](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-field/78587/2 "2017-03-16T15:18:30Z")

</div>

> [@peanut](#):
>
> Is it best practice to mutate all the fields with the "event\_data" attached to it to its original data field name?

It's not clear what you are asking. Can you please clarify and maybe provide an example.

---

<div class="post-metadata">

**Author:** ![peanut](https://avatars.discourse-cdn.com/v4/letter/p/b5e925/32.png) [@peanut](https://discuss.elastic.co/u/peanut)\
**Post date:** [March 16, 2017, 10:46pm UTC](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-field/78587/3 "2017-03-16T22:46:26Z")

</div>

> [@Split "event\_data" to only show the original data field](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-data-field/78561/3):
>
> I have been reading since I posted this two days ago and I found this post in this forum: "The event\_data.\* fields are the raw data that was provided by the application that logged the event. This is included in the event published by Winlogbeat so that you don't have to grok the message field to extract data needed for other analysis you might want to do." So all new data fields from, for example, Sysmon logs, have the event\_data name at the beginning . event\_data.CommandLine event\_data.Pr…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2017, 10:46pm UTC](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-field/78587/4 "2017-04-13T22:46:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
