# Adding custom field to output

**URL:** <https://discuss.elastic.co/t/adding-custom-field-to-output/220497>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [February 22, 2020, 3:42pm UTC](https://discuss.elastic.co/t/adding-custom-field-to-output/220497 "2020-02-22T15:42:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ethrbunny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethrbunny/32/34603_2.png) [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Post date:** [February 22, 2020, 3:42pm UTC](https://discuss.elastic.co/t/adding-custom-field-to-output/220497/1 "2020-02-22T15:42:28Z")

</div>

Im wondering if [this](https://discuss.elastic.co/t/can-metricbeat-support-run-command/69103) is still accurate. Im attempting to add some fields to 'system.yml' (as a test) as follows:

(note that indents are being lost)

> - add\_fields:  
> target:  
> fields:  
> name: myproject  
> id: '574734885120952459'  
> os: ${os.version:def}

I start metricbeat as so:

```
metricbeat -v -e -E os.version="$(cat /etc/redhat-release)"

```

When I look at the results I see the name, id values but not my additional value. Just 'def'.

If I use just **${os}** per the link above I get an error message at startup:

```
Error creating runner from config: 1 error: fail to unpack the add_fields configuration: 
missing field accessing 'processors.1.add_fields.fields.os' (source:'/etc/metricbeat/modules.d/system.yml')

```

Running 7.6 across the board. Wondering if there are updates to how to do this.

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [February 24, 2020, 9:20am UTC](https://discuss.elastic.co/t/adding-custom-field-to-output/220497/2 "2020-02-24T09:20:07Z")

</div>

Hi!

It seems to work on my end with the latest master branch:

Configuration:

```auto
processors:
  - add_fields:
      target: project
      fields:
        name: myproject42
        id: '574734885120952459'
        os: ${os.version}

```

```auto
master ● cat /tmp/version                                                                           
19.0.1
master ● ./metricbeat -e -d metricbeat -E os.version=$(cat /tmp/version)

```

Result:

```auto
  "project": {
    "name": "myproject42",
    "id": "574734885120952459",
    "os": "19.0.1"
  },

```

The value you are seeing `def` is the default value when the env variable is not present.

---

<div class="post-metadata">

**Author:** ![ethrbunny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethrbunny/32/34603_2.png) [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Post date:** [February 24, 2020, 11:44am UTC](https://discuss.elastic.co/t/adding-custom-field-to-output/220497/3 "2020-02-24T11:44:09Z")

</div>

Interesting. I wonder what Im missing.

If the values for any of those vars changed - would it be reflected in the output? Or is it static?

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [February 24, 2020, 11:48am UTC](https://discuss.elastic.co/t/adding-custom-field-to-output/220497/4 "2020-02-24T11:48:28Z")

</div>

I would say static. They are loaded once during configuration loading.

C.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 23, 2020, 11:57am UTC](https://discuss.elastic.co/t/adding-custom-field-to-output/220497/5 "2020-03-23T11:57:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
