# Winlogbeat: Problem to get fields from nested winevent message

**URL:** <https://discuss.elastic.co/t/winlogbeat-problem-to-get-fields-from-nested-winevent-message/249712>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [September 23, 2020, 9:40pm UTC](https://discuss.elastic.co/t/winlogbeat-problem-to-get-fields-from-nested-winevent-message/249712 "2020-09-23T21:40:41Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pedro\_77](https://avatars.discourse-cdn.com/v4/letter/p/278dde/32.png) [@Pedro\_77](https://discuss.elastic.co/u/Pedro_77)\
**Post date:** [September 23, 2020, 9:40pm UTC](https://discuss.elastic.co/t/winlogbeat-problem-to-get-fields-from-nested-winevent-message/249712/1 "2020-09-23T21:40:42Z")

</div>

Hello

I have problem with winlogbeat (7.9.1) I'm trying to get fields which are "nested" in message field: for example:

```
"message": Endpoint: xxxyy211\n
                      Endpoint IP: 10.1.1.x\n
                     Domain: Agents\\xxx\\update\\\n
                     Date/Time: 22.09.2020 13:43:16\n
                    Detailed information: 

```

All other "normal" fields can be filtered and indexed without any problem  
Not sure if this is important but this winlog event is from Trendmicro AV system

Thanks for help  
Pedro

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 24, 2020, 3:54am UTC](https://discuss.elastic.co/t/winlogbeat-problem-to-get-fields-from-nested-winevent-message/249712/2 "2020-09-24T03:54:30Z")

</div>

What fields are there in `winlog.event_data.*`?

The data you want might already be in there. For most Windows events that's where you'll find the raw data that contributes to the `message`. But for third-party events you sometime just get a single string. When that happens you have to parse the `message` with tools like dissect or grok processors.

---

<div class="post-metadata">

**Author:** ![Pedro\_77](https://avatars.discourse-cdn.com/v4/letter/p/278dde/32.png) [@Pedro\_77](https://discuss.elastic.co/u/Pedro_77)\
**Post date:** [September 24, 2020, 8:42pm UTC](https://discuss.elastic.co/t/winlogbeat-problem-to-get-fields-from-nested-winevent-message/249712/3 "2020-09-24T20:42:43Z")

</div>

Hello,

In message and in winlog.event\_data.param1 i have exactly the same content. Have You maybe example how to retrieve all these fields as seperate?

**message**  
Endpoint: xxx  
Endpoint IP: 10.10.0.90  
Domain: Agents  
Date/Time: 21.09.2020 09:25:57  
Detailed information:  
[HKTL\_AUTOKMS]  
Location = D:\Recovered data 02-10 14\_07\_13\Lost Partition\Users\Public\Documents\SPHE\downloads\Microsoft Office 2016 VL ProPlus English (x86-x64) June 2016\Office\_2016\_ProPlus\_64Bit\_EN\_06.2016\Bonus\Microsoft Toolkit 2.6 BETA 5\Microsoft Toolkit.exe  
Scan Type = File System  
Threat Type = General

**winlog.event\_data.param1**  
Endpoint: xxxx  
Endpoint IP: 10.10.0.90  
Domain: Agents  
Date/Time: 21.09.2020 09:25:57  
Detailed information:  
[HKTL\_AUTOKMS]  
Location = D:\Recovered data 02-10 14\_07\_13\Lost Partition\Users\Public\Documents\SPHE\downloads\Microsoft Office 2016 VL ProPlus English (x86-x64) June 2016\Office\_2016\_ProPlus\_64Bit\_EN\_06.2016\Bonus\Microsoft Toolkit 2.6 BETA 5\Microsoft Toolkit.exe  
Scan Type = File System  
Threat Type = General  
Risk Level = Low  
Action Result = Cleaned  
Location = D:\Recovered data 02-10 14\_07\_13\Lost Partition\KMSCleaner.exe  
Scan Type = File System  
Threat Type = General

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 24, 2020, 9:06pm UTC](https://discuss.elastic.co/t/winlogbeat-problem-to-get-fields-from-nested-winevent-message/249712/4 "2020-09-24T21:06:45Z")

</div>

In that case you'll have to parse it. You can add a [dissect](https://www.elastic.co/guide/en/beats/winlogbeat/current/dissect.html) processor. For example:

```auto
winlogbeat.event_logs:
- name: foo
  processors:
  - dissect:
      when.equals.event.code: 1234
      tokenizer: "Endpoint: %{source.address}\nEndpoint IP: %{source.ip}\nDomain: %{foo}"
      field: "winlog.event_data.param1"

```

---

<div class="post-metadata">

**Author:** ![Pedro\_77](https://avatars.discourse-cdn.com/v4/letter/p/278dde/32.png) [@Pedro\_77](https://discuss.elastic.co/u/Pedro_77)\
**Post date:** [September 24, 2020, 10:47pm UTC](https://discuss.elastic.co/t/winlogbeat-problem-to-get-fields-from-nested-winevent-message/249712/5 "2020-09-24T22:47:00Z")

</div>

I added to winlogbeat.yml config file but with no results. No errors on winlogbeat side. I did config to have the same amount of fields as log have but it didn't help. Also i removed condition for event.code = 500 but also without success. Is anything more which has to be configured?

```
winlogbeat.event_logs: 
  - 
    name: foo
    processors: 
      - 
        dissect: 
          field: message
          tokenizer: |-
              Virus/Malware: %{virus}
              Endpoint: %{source.address}
              Endpoint IP: %{source.ip}
              Domain: %{domain}
              File: %{file}
              Date/Time: %{time.virus}
              Result: %{result}
          when.equals.event.code: 500

```

my test virus in events looks like this:

```
winlog.event_data.param1
Virus/Malware: Eicar_test_file
Endpoint: Sxx01
Endpoint IP: 10.10.10.7
Domain: Server\team\
File: C:\Users\xxx\AppData\Local\Microsoft\Windows\INetCache\IE\T1NL5DXZ\eicarcom2[1].zip (eicar.com)
Date/Time: 25.09.2020 00:23:59
Result: Quarantine
	
winlog.event_id 500
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 23, 2020, 12:47am UTC](https://discuss.elastic.co/t/winlogbeat-problem-to-get-fields-from-nested-winevent-message/249712/6 "2020-10-23T00:47:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
