Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic!
1. Describe your incident:
i collected log from my window DC by sidecar latest version (before winlogbeat)
but in input, message only display hyphens “-” , and message extend aslo display full content of message.
Ok I see your using Windows Forwarded events. So I assume that this windows device is the middle man for transporting logs files. If this is correct, Check the log/s for a message body. When you see "-" in a field, Elasticsearch could not identify it to place data in that field OR it was remove by other means configured in Graylog.
Example in this picture below, this shows Cut is enabled. What is does is remove data from the field, but since you stated you don’t have extractors or pipelines we probably can rule that out.
Next Question, The Windows Event Forwarding (WEF) reads any operational or administrative event log on a device in your organization and forwards the events you choose to a Windows Event Collector (WEC) server, in this case Its Graylog. Since I have not used this type of configuration, I would imagine that the logs are formatted in such a way that Elasticsearch cant find a “message” field " in those message. So it places "-"
EDIT: After reading over Microsoft (WEF) Have you tried using Graylog-Sidecar to pull the events you want instead of using Windows Forwarding?