Sure, please see below an example of a JSON document
{
"_index": "filebeat-7.12.0-2021.03.30-000001",
"_type": "_doc",
"_id": "OT2akXgBrNnms5-qprv7",
"_version": 1,
"_score": null,
"_source": {
"agent": {
"hostname": "domain.com",
"name": "domain.com",
"id": "1f0e7b95-79a1-41f1-9923-ddb2eee399d0",
"type": "filebeat",
"ephemeral_id": "ff5d0cdb-2875-4e65-95b2-3c2b98c96ba4",
"version": "7.12.0"
},
"log": {
"file": {
"path": "/local/notesdata/weblogs/access04022021.log"
},
"offset": 4378390
},
"destination": {
"domain": "domain.com"
},
"source": {
"ip": "10.0.0.5"
},
"fileset": {
"name": "access"
},
"url": {
"original": "/ADB/revenues.nsf/icon11.gif"
},
"input": {
"type": "log"
},
"apache": {
"access": {}
},
"@timestamp": "2021-04-02T09:02:06.000Z",
"ecs": {
"version": "1.8.0"
},
"service": {
"type": "apache"
},
"host": {
"hostname": "domain.com",
"os": {
"kernel": "2.6.32-573.18.1.el6.x86_64",
"codename": "Final",
"name": "CentOS",
"family": "redhat",
"type": "linux",
"version": "6.7 (Final)",
"platform": "centos"
},
"containerized": false,
"ip": [
"192.168.1.60",
"fe80::215:5dff:fe01:3301"
],
"name": "domain.com",
"id": "41d334d3044ca22a1daa6aae00000022",
"mac": [
"00:15:5d:01:33:01"
],
"architecture": "x86_64"
},
"http": {
"request": {
"referrer": "https://domain.com/",
"method": "GET"
},
"response": {
"status_code": 200,
"body": {
"bytes": 1403
}
},
"version": "1.1"
},
"event": {
"ingested": "2021-04-02T08:02:14.846051490Z",
"kind": "event",
"created": "2021-04-02T08:02:13.801Z",
"module": "apache",
"category": "web",
"dataset": "apache.access",
"outcome": "success"
},
"user_agent": {
"original": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36",
"os": {
"name": "Windows",
"version": "10",
"full": "Windows 10"
},
"name": "Chrome",
"device": {
"name": "Other"
},
"version": "89.0.4389.90"
},
"username": "User/O=Domain/C=CZ"
},
"fields": {
"event.ingested": [
"2021-04-02T08:02:14.846Z"
],
"@timestamp": [
"2021-04-02T09:02:06.000Z"
],
"event.created": [
"2021-04-02T08:02:13.801Z"
]
},
"highlight": {
"suricata.eve.http.url": [
"@kibana-highlighted-field@/ADB/revenues.nsf/icon11.gif@/kibana-highlighted-field@"
],
"url.original": [
"@kibana-highlighted-field@/ADB/revenues.nsf/icon11.gif@/kibana-highlighted-field@"
],
"host.hostname": [
"@kibana-highlighted-field@domain.com@/kibana-highlighted-field@"
]
},
"sort": [
1617350534846
]
}