# Adding fields to data read by the file plugin

**URL:** <https://discuss.elastic.co/t/adding-fields-to-data-read-by-the-file-plugin/40302>\
**Category:** Logstash\
**Created:** [January 27, 2016, 11:39pm UTC](https://discuss.elastic.co/t/adding-fields-to-data-read-by-the-file-plugin/40302 "2016-01-27T23:39:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Post date:** [January 27, 2016, 11:39pm UTC](https://discuss.elastic.co/t/adding-fields-to-data-read-by-the-file-plugin/40302/1 "2016-01-27T23:39:06Z")

</div>

Using Filebeat, I can add a field that ends up looking like:

```
"fields": {
  "fieldname": "value"
},

```

So far I can't figure out how to do the same with Logstash's file input plugin.

I can't do:

```
add_field => { "fields.fieldname" => "value" }

```

Because of the '.'.

I tried:

```
add_field => { "fields" => { "fieldname" => "value" } }

```

And logstash threw errors at me.

So, how do I get the File plugin to give me the same output as Filebeat gives me?

From [the docs](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-add_field) I'm wondering if the plugin just doesn't have the ability to do what I want. Is that true?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 28, 2016, 7:03am UTC](https://discuss.elastic.co/t/adding-fields-to-data-read-by-the-file-plugin/40302/2 "2016-01-28T07:03:32Z")

</div>

Quoting [the documentation](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references):

> The syntax to access a field is [fieldname]. If you are referring to a top-level field, you can omit the and simply use fieldname. To refer to a nested field, you specify the full path to that field: [top-level field][nested field].

---

<div class="post-metadata">

**Author:** ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Post date:** [February 3, 2016, 10:08pm UTC](https://discuss.elastic.co/t/adding-fields-to-data-read-by-the-file-plugin/40302/3 "2016-02-03T22:08:52Z")

</div>

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:13am UTC](https://discuss.elastic.co/t/adding-fields-to-data-read-by-the-file-plugin/40302/4 "2017-07-06T05:13:09Z")

</div>


