dgunter / evtxtoelk

A lightweight tool to load Windows Event Log evtx files into Elasticsearch.
MIT License
115 stars 27 forks source link

Script adding body. to every field #1

Closed jasc22 closed 5 years ago

jasc22 commented 5 years ago

Hi, thanks for the tool. When I use the tool to import the data, it's adding "body." to every field. Is it possible to remove this entry?

image

dgunter commented 5 years ago

Let me take a look and get back to you in the next few days. I know this was by design in a past version. Let me see what we ended up getting in with the current version.

RuadhriM commented 5 years ago

Any update on this?

dgunter commented 5 years ago

@RuadhriM and @jasc22 : Should be good to go with the commit a few seconds ago. Let me know if you spot any issues.

Screen Shot 2019-08-02 at 3 14 51 PM