Extracting message using GROK Patern

Are you using winlogbeats as a log shipper on your windows machines? That extracts a lot of information before sending to the beats input… It’s not clear about how you are working with the message, are you suing extractors, are you working in the pipeline? Here are some tips on how to make your question clearer here and here.