# Graylog message has display hyphen "-"

**URL:** <https://community.graylog.org/t/graylog-message-has-display-hyphen/26257>\
**Category:** Graylog Central (peer support)\
**Created:** [October 22, 2022, 4:24am UTC](https://community.graylog.org/t/graylog-message-has-display-hyphen/26257 "2022-10-22T04:24:05Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![ducna09](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/ducna09/32/13270_2.png) [@ducna09](https://community.graylog.org/u/ducna09)\
**Post date:** [October 22, 2022, 4:24am UTC](https://community.graylog.org/t/graylog-message-has-display-hyphen/26257/1 "2022-10-22T04:24:05Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question.  
**Don’t forget to select tags to help index your topic!**

**1. Describe your incident:**  
i collected log from my window DC by sidecar latest version (before winlogbeat)  
but in input, message only display hyphens “-” , and message extend aslo display full content of message.  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/3/39a3bee3095ffd824c68774d85b3cd83412e4732.png)

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/8/84a099304441da26317f2840aec69f573cf42ef9.png)

how can i fix this?

**Helpful Posting Tips:** [Tips for Posting Questions that Get Answers](https://community.graylog.org/t/tips-for-posting-questions-that-get-answers/21828) [Hold down CTRL and link on link to open tips documents in a separate tab]

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [October 24, 2022, 10:21pm UTC](https://community.graylog.org/t/graylog-message-has-display-hyphen/26257/2 "2022-10-24T22:21:13Z")

</div>

Hello @ducna09

Thanks for the screen shot.  
I have seen this before when there is an extractor or pipeline being used. This may have something to do with the shipper.

---

<div class="post-metadata">

**Author:** ![ducna09](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/ducna09/32/13270_2.png) [@ducna09](https://community.graylog.org/u/ducna09)\
**Post date:** [October 25, 2022, 7:06am UTC](https://community.graylog.org/t/graylog-message-has-display-hyphen/26257/3 "2022-10-25T07:06:09Z")

</div>

i considering graylog or sidecar, but doesn’t have any log :((

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [October 25, 2022, 9:06pm UTC](https://community.graylog.org/t/graylog-message-has-display-hyphen/26257/4 "2022-10-25T21:06:04Z")

</div>

Hello,

I can help you further but more information is need. If your unsure please post.

> [@How to Post a Question in the Community that Gets Responses](https://community.graylog.org/t/how-to-post-a-question-in-the-community-that-gets-responses/20879):
>
> This platform is made with love for community discussions on the open source tool Graylog, it components and usage. Here’s a Graylog support-inspired template (thank you, @aaronsachs ) that’ll get responses: Description of your problem \<!-- Use this section to describe the problem that you're encountering. Please include any screenshots or recordings of the problem you're running into.--\> Description of steps you’ve taken to attempt to solve the issue \<!-- Use this section to provide detailed…

---

<div class="post-metadata">

**Author:** ![ducna09](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/ducna09/32/13270_2.png) [@ducna09](https://community.graylog.org/u/ducna09)\
**Post date:** [October 26, 2022, 7:37am UTC](https://community.graylog.org/t/graylog-message-has-display-hyphen/26257/5 "2022-10-26T07:37:01Z")

</div>

Hi my friend,  
graylog version: 4.0.6+40b7be5  
sidecar version: latest  
window to log center: window server 2019

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [October 26, 2022, 9:20pm UTC](https://community.graylog.org/t/graylog-message-has-display-hyphen/26257/6 "2022-10-26T21:20:02Z")

</div>

What does your Winlogbeat configuration look like? Or is it default?  
Do you have any extractors or pipeline configuration for this input? If so how are they configured.

---

<div class="post-metadata">

**Author:** ![ducna09](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/ducna09/32/13270_2.png) [@ducna09](https://community.graylog.org/u/ducna09)\
**Post date:** [October 27, 2022, 6:54am UTC](https://community.graylog.org/t/graylog-message-has-display-hyphen/26257/7 "2022-10-27T06:54:59Z")

</div>

here is my config sidecar.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/e/eac16a3acb98616bd940e01f035aeedbb69c344d.png)  
i dont have any exatroctors.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [October 27, 2022, 9:32pm UTC](https://community.graylog.org/t/graylog-message-has-display-hyphen/26257/8 "2022-10-27T21:32:14Z")

</div>

hello,

Ok I see your using Windows Forwarded events. So I assume that this windows device is the middle man for transporting logs files. If this is correct, Check the log/s for a message body. When you see `"-"` in a field, Elasticsearch could not identify it to place data in that field OR it was remove by other means configured in Graylog.

Example in this picture below, this shows Cut is enabled. What is does is remove data from the field, but since you stated you don’t have extractors or pipelines we probably can rule that out.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/3/3cfaf1c67e6aaca33be633aa29e3200a154c06d8.png)

For testing purposes have you tried sending other logs instead of Forwarded events. This would give us a clearer idea what’s going on. Perhaps something like this…

```auto
tags:
 - windows
winlogbeat:
  event_logs:
   - name: Forwarded Events
   - name: System  

```

If you do get data in the **message** field, using that config, Then we can look at the origin from where the logs are being sent. If not then we can look more into Graylog instance.

---

<div class="post-metadata">

**Author:** ![ducna09](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/ducna09/32/13270_2.png) [@ducna09](https://community.graylog.org/u/ducna09)\
**Post date:** [October 31, 2022, 4:45am UTC](https://community.graylog.org/t/graylog-message-has-display-hyphen/26257/9 "2022-10-31T04:45:39Z")

</div>

> [@gsmith](#):
>
> being sent. If not then we can look more into Graylog instance.

when i collect another log , for example: system log, it’s didn’t show hyphens

![image (1)](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/3/309601f63f599bacec446e8bc38b6bc9a3d44c9a.png)  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/c/c815b64a5b1fec71ea2bef5b7f1bea25cf5f42e0.png).  
but message in ForwardedEvent maybe correctly.

 ![photo_2022-10-31_11-43-19](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/8/8972de63d7745b51d4ce077290eb7eb22ea045a8.jpeg)

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [October 31, 2022, 9:54pm UTC](https://community.graylog.org/t/graylog-message-has-display-hyphen/26257/10 "2022-10-31T21:54:46Z")

</div>

Hello,

Ok this is weird, **Windows System Events** seam to work but your **Forwarded Events** do not.  
Thanks for testing that, So this leads use to the messages/logs in Forwarded Events.

So something is funky with the Forwarded Events logs. For example, here is my lab, BUT this is not a Forwarded Events…

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/d/d8819cd60d38592d657a6f87cf8b8a767f170d4e.png)

Next Question, The Windows Event Forwarding (WEF) reads any operational or administrative event log on a device in your organization and forwards the events you choose to a Windows Event Collector (WEC) server, in this case Its Graylog. Since I have not used this type of configuration, I would imagine that the logs are formatted in such a way that **Elasticsearch** cant find a “ **message** ” field " in those message. So it places `"-"`

EDIT: After reading over Microsoft (WEF) Have you tried using Graylog-Sidecar to pull the events you want instead of using Windows Forwarding?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [November 14, 2022, 9:55pm UTC](https://community.graylog.org/t/graylog-message-has-display-hyphen/26257/11 "2022-11-14T21:55:29Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
