# Split "event\_data" to only show the original field

**URL:** <https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-field/78587>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 14, 2017, 7:41pm UTC](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-field/78587 "2017-03-14T19:41:37Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![peanut](https://avatars.discourse-cdn.com/v4/letter/p/b5e925/32.png) [@peanut](https://discuss.elastic.co/u/peanut)\
**Post date:** [March 16, 2017, 10:46pm UTC](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-field/78587/3 "2017-03-16T22:46:26Z")

</div>

> [@Split "event\_data" to only show the original data field](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-data-field/78561/3):
>
> I have been reading since I posted this two days ago and I found this post in this forum: "The event\_data.\* fields are the raw data that was provided by the application that logged the event. This is included in the event published by Winlogbeat so that you don't have to grok the message field to extract data needed for other analysis you might want to do." So all new data fields from, for example, Sysmon logs, have the event\_data name at the beginning . event\_data.CommandLine event\_data.Pr…

---

_[View the full topic](https://discuss.elastic.co/t/split-event-data-to-only-show-the-original-field/78587)._
