# Add custom metadata to events

**URL:** <https://discuss.elastic.co/t/add-custom-metadata-to-events/166695>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [February 1, 2019, 8:53am UTC](https://discuss.elastic.co/t/add-custom-metadata-to-events/166695 "2019-02-01T08:53:40Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![justinw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justinw/32/40277_2.png) [@justinw](https://discuss.elastic.co/u/justinw)\
**Post date:** [February 1, 2019, 8:53am UTC](https://discuss.elastic.co/t/add-custom-metadata-to-events/166695/1 "2019-02-01T08:53:40Z")

</div>

Hi,

Is it possible to add custom metadata to events?

I like the concept of `meta.cloud.*` and would like to add something like ec2 tags to that, nested under `meta.cloud.tags.*` for everything on that instance.

Alternatively, it'd be nice to be able to whitelist environment details, perhaps `meta.env.ENV_VAR_NAME=$value`.

Does support like this exist in metricbeat (or beats lib?).

Currently I'm sending metricbeat events to logstash, and adding the context there, but it'd be nice to only manage the single metricbeat instance.

Best, Justin

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [February 4, 2019, 12:26pm UTC](https://discuss.elastic.co/t/add-custom-metadata-to-events/166695/2 "2019-02-04T12:26:00Z")

</div>

Hi @justinw

You can use [fields](https://www.elastic.co/guide/en/beats/metricbeat/6.6/configuration-general-options.html#libbeat-configuration-fields) and [tags](https://www.elastic.co/guide/en/beats/metricbeat/6.6/configuration-general-options.html#_literal_tags_literal_2) in your modules configuration. Is that what you need?

Regards!

---

<div class="post-metadata">

**Author:** ![justinw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justinw/32/40277_2.png) [@justinw](https://discuss.elastic.co/u/justinw)\
**Post date:** [February 12, 2019, 10:37pm UTC](https://discuss.elastic.co/t/add-custom-metadata-to-events/166695/3 "2019-02-12T22:37:49Z")

</div>

Yes, that'll definitely work. Thanks!

---

<div class="post-metadata">

**Author:** ![justinw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justinw/32/40277_2.png) [@justinw](https://discuss.elastic.co/u/justinw)\
**Post date:** [March 9, 2019, 4:47am UTC](https://discuss.elastic.co/t/add-custom-metadata-to-events/166695/4 "2019-03-09T04:47:25Z")

</div>

Hi @Mario_Castro,

So I finally got around to trying this, and I was able to successfully set a field like `meta.tags.*`

However I'd like to nest it with the cloud block, at `meta.cloud.tags.*`. It seems like the add cloud processor overwrites any fields that might already be there. Is that the case? If so, is there any way to achieve that?

Best, Justin

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 12, 2019, 8:33am UTC](https://discuss.elastic.co/t/add-custom-metadata-to-events/166695/5 "2019-03-12T08:33:46Z")

</div>

The rename processor could help you here: [https://www.elastic.co/guide/en/beats/filebeat/6.6/rename-fields.html](https://www.elastic.co/guide/en/beats/filebeat/6.6/rename-fields.html)

For things like Cloud fields I would recommend to follow ECS long term: [https://github.com/elastic/ecs](https://github.com/elastic/ecs) In 7.0 these fields will be mapped to ECS.

---

<div class="post-metadata">

**Author:** ![justinw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justinw/32/40277_2.png) [@justinw](https://discuss.elastic.co/u/justinw)\
**Post date:** [March 12, 2019, 9:14pm UTC](https://discuss.elastic.co/t/add-custom-metadata-to-events/166695/6 "2019-03-12T21:14:06Z")

</div>

Awesome, thanks @ruflin for the link. I opened a ticket to get a conversation started around standardizing cloud tags/labels in future releases (ref [https://github.com/elastic/ecs/issues/384](https://github.com/elastic/ecs/issues/384)).

For now, I'll keep them where they are since neither is officially a convention yet.

Best, Justin

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 14, 2019, 7:30am UTC](https://discuss.elastic.co/t/add-custom-metadata-to-events/166695/7 "2019-03-14T07:30:30Z")

</div>

Great, thanks for opening the ECS issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 11, 2019, 7:30am UTC](https://discuss.elastic.co/t/add-custom-metadata-to-events/166695/8 "2019-04-11T07:30:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
