# WinlogBeat - parsing "message" field

**URL:** <https://discuss.elastic.co/t/winlogbeat-parsing-message-field/272497>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 9, 2021, 11:06am UTC](https://discuss.elastic.co/t/winlogbeat-parsing-message-field/272497 "2021-05-09T11:06:04Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![filip.wozniak](https://avatars.discourse-cdn.com/v4/letter/f/65b543/32.png) [@filip.wozniak](https://discuss.elastic.co/u/filip.wozniak)\
**Post date:** [May 9, 2021, 11:06am UTC](https://discuss.elastic.co/t/winlogbeat-parsing-message-field/272497/1 "2021-05-09T11:06:04Z")

</div>

Greetings!  
I'm using basic setup that uses Winlogbeat with configured sysmon.  
I'm writing some correlation rules and I would like to detect whether powershell command is suspiciously long. The command itself is in "message" field stored using key:value -

 ![obraz](https://us1.discourse-cdn.com/elastic/original/3X/a/b/abbd3062e61b0e1297f9eb6dbb6f12040bee3ff3.png)

What is the easiest way to check "length" of that field? I tried 'between' and 'lenght' functions in EQL (now working, because cannot operate on [text] field). Is there a way to write it in KQL or should I use some kind of grok in logstash or processors in winlogbeat.yml file? Or another way?

Also process.command\_line is empty ☹

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2021, 1:06pm UTC](https://discuss.elastic.co/t/winlogbeat-parsing-message-field/272497/2 "2021-06-06T13:06:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
