# Winlogbeat and User sessions (parsing fields from message)

**URL:** <https://discuss.elastic.co/t/winlogbeat-and-user-sessions-parsing-fields-from-message/43003>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [February 29, 2016, 1:14pm UTC](https://discuss.elastic.co/t/winlogbeat-and-user-sessions-parsing-fields-from-message/43003 "2016-02-29T13:14:29Z")\
**Posts on this page:** 1\
**Showing post:** 10

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 21, 2016, 2:47pm UTC](https://discuss.elastic.co/t/winlogbeat-and-user-sessions-parsing-fields-from-message/43003/10 "2016-03-21T14:47:04Z")

</div>

@matthieurobin, @dloyd,

An update on this... Winlogbeat has been [enhanced](https://github.com/elastic/beats/pull/1153) to report this data as a field so you will no longer need to grok the message. You can try the feature by using the [development build](https://beats-nightlies.s3.amazonaws.com/winlogbeat/winlogbeat-5.0.0-nightlylatest-windows-32.zip). It will be released with [v5](https://www.elastic.co/v5). Screenshot here: [Reporting Windows Security Events in Kibana](https://discuss.elastic.co/t/reporting-windows-security-events-in-kibana/44748/3)

---

_[View the full topic](https://discuss.elastic.co/t/winlogbeat-and-user-sessions-parsing-fields-from-message/43003)._
