# Apm for django, filter errors by cusotm field

**URL:** <https://discuss.elastic.co/t/apm-for-django-filter-errors-by-cusotm-field/349762>\
**Category:** Logs\
**Created:** [December 21, 2023, 6:42am UTC](https://discuss.elastic.co/t/apm-for-django-filter-errors-by-cusotm-field/349762 "2023-12-21T06:42:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![k\_cf](https://avatars.discourse-cdn.com/v4/letter/k/ac91a4/32.png) [@k\_cf](https://discuss.elastic.co/u/k_cf)\
**Post date:** [December 21, 2023, 6:42am UTC](https://discuss.elastic.co/t/apm-for-django-filter-errors-by-cusotm-field/349762/1 "2023-12-21T06:42:09Z")

</div>

I have set up elastic apm for a django project with logging (`elasticapm.contrib.django.handlers.LoggingHandler`). Upon logging a message as follows:

```auto
logger.exception(
    custom_logging_message,
    exc_info=True,
    extra={
        'status_code': status_code
    },
)

```

it correctly records the error document, including the extra field `status_code` under `error.custom.status_code`, so far so great.

but i cannot use it in a filter (or DSL query), like `error.custom.status_code >= 500`

is this because the field is not indexed? i tried to find all indexed fields via `GET _my_error_index/_mapping?pretty` and indeed it is not among the `"mappings"`. how can i use my custom logging data in filters or DSL queries? thank you

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [December 21, 2023, 8:03am UTC](https://discuss.elastic.co/t/apm-for-django-filter-errors-by-cusotm-field/349762/2 "2023-12-21T08:03:12Z")

</div>

Hi @k_cf Can you share the output you got from the mapping command? Even though likely status\_code is index as a keyword instead of an integer, I would still expect it to show up. Ideally could you also share a sample document that is indexed?

Two general recommendations:

- For logs, ship your data to the [data stream naming scheme](https://www.elastic.co/blog/an-introduction-to-the-elastic-data-stream-naming-scheme). In your example, this might be `logs-my_error-default`. This gives you all ECS mappings by default
- Taking about ECS, use [ECS fields](https://www.elastic.co/guide/en/ecs/current/ecs-http.html) if possible so you get the correct mapping automatically. In your scenario, it seems to be custom status code. If it is shipped as long, with this template you should still get the right mapping automatically.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 18, 2024, 8:03am UTC](https://discuss.elastic.co/t/apm-for-django-filter-errors-by-cusotm-field/349762/3 "2024-01-18T08:03:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
