# Unable to use sub-fields of event\_data

**URL:** <https://discuss.elastic.co/t/unable-to-use-sub-fields-of-event-data/91480>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [June 30, 2017, 7:06pm UTC](https://discuss.elastic.co/t/unable-to-use-sub-fields-of-event-data/91480 "2017-06-30T19:06:06Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ccampbell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ccampbell/32/15320_2.png) [@ccampbell](https://discuss.elastic.co/u/ccampbell)\
**Post date:** [June 30, 2017, 7:06pm UTC](https://discuss.elastic.co/t/unable-to-use-sub-fields-of-event-data/91480/1 "2017-06-30T19:06:06Z")

</div>

I'm trying to replicate some of the examples found in this blog piece:

> **[Monitoring Windows Logons with Winlogbeat
	  	 | Elastic](https://www.elastic.co/blog/monitoring-windows-logons-with-winlogbeat)**
>
> Windows event logs can provide invaluable insight into your Windows based infrastructure. The Windows operating system has many event log channels, each dedicated to a specific category of events. In ...

But I can't enter sub-fields of event\_data as terms in a Kibana visualization --

To be clear, I can definitely create a filter or perform a saved search in "Discover" to look for "event\_data.LogonType" or "event\_data.SubjectUserName". I'm also successfully using these terms for filtering incoming logs in Logstash.

How do I enter these terms into Kibana's Visualizations? I have already tried importing the JSON for this set of visualizations from the blog post, but the visualizations were rejected by Kibana.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 30, 2017, 7:54pm UTC](https://discuss.elastic.co/t/unable-to-use-sub-fields-of-event-data/91480/2 "2017-06-30T19:54:55Z")

</div>

If you put all the individual expressions together, you should be able to paste that into the search box.

`event_id:4624 AND !event_data.LogonType:0 AND !event_data.LogonType:5 AND !event_data.TargetUserName:"ANONYMOUS LOGON" AND !event_data.TargetDomainName:"Window Manager" AND !event_data.TargetUserName:*$ AND !tags:"dc"`

---

<div class="post-metadata">

**Author:** ![ccampbell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ccampbell/32/15320_2.png) [@ccampbell](https://discuss.elastic.co/u/ccampbell)\
**Post date:** [July 5, 2017, 5:10pm UTC](https://discuss.elastic.co/t/unable-to-use-sub-fields-of-event-data/91480/3 "2017-07-05T17:10:43Z")

</div>

I've used the solution of putting all of the individual expressions together in the search box -- I can do that in both Discover and Visualize, to create a table (for instance, by **computer\_name** ). However, in Visaulize I can't figure out how to break data out by subfields under event\_data (for instance, **event\_data.SubjectUserName** or **event\_data.LogonType** ). If I use "Terms" or "Significant Terms" to split rows of a Data Table, event\_data is not a selectable option (and there is not way to add my own terms).

I want to be able to display charts that show that critical information on a Dashboard and in reports, right now I seem strictly limited in my choice of Terms.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 5, 2017, 6:12pm UTC](https://discuss.elastic.co/t/unable-to-use-sub-fields-of-event-data/91480/4 "2017-07-05T18:12:44Z")

</div>

Can you try refreshing the index pattern. The event\_data.\* fields are dynamic since we don't know them all in advance. Once you refresh the index pattern those fields will then be known to Kibana.

In Kibana, Management -\> Index Patterns -\> Click on winlogbeat-\* -\> Find the refresh button and click it.

(That probably explains why there was an error when you tried to import the dashboards from the JSON files.)

---

<div class="post-metadata">

**Author:** ![ccampbell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ccampbell/32/15320_2.png) [@ccampbell](https://discuss.elastic.co/u/ccampbell)\
**Post date:** [July 5, 2017, 6:37pm UTC](https://discuss.elastic.co/t/unable-to-use-sub-fields-of-event-data/91480/5 "2017-07-05T18:37:14Z")

</div>

Thank you!

Refreshing the index pattern exposed a long list of event\_data fields that I can now search / filter on. I'm going to test out a bunch of visualization settings, but this seems to have solved the problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2017, 6:37pm UTC](https://discuss.elastic.co/t/unable-to-use-sub-fields-of-event-data/91480/6 "2017-08-02T18:37:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
