# Attempting to add backward compatible field metricset.module

**URL:** <https://discuss.elastic.co/t/attempting-to-add-backward-compatible-field-metricset-module/200317>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [September 19, 2019, 11:32pm UTC](https://discuss.elastic.co/t/attempting-to-add-backward-compatible-field-metricset-module/200317 "2019-09-19T23:32:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![justinw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justinw/32/40277_2.png) [@justinw](https://discuss.elastic.co/u/justinw)\
**Post date:** [September 19, 2019, 11:32pm UTC](https://discuss.elastic.co/t/attempting-to-add-backward-compatible-field-metricset-module/200317/1 "2019-09-19T23:32:50Z")

</div>

Hi,

I am using metricbeat 7.3.2, with `migration.6_to_7.enabled: true` set to get backward compatible fields.

One field that still isn't showing up is `metricset.module`. Many of our dashboards and alerts depend on this field, so I'd like to add it back via a processor.

However, I'm noticing some weird behavior. Without the following two blocks, other processors work fine (adding, removing, dissecting fields). However when I add either of these, metrics cease to be stored in ES. Is there some block on the `metricset` target?

Thanks, Justin

```auto
      - add_fields:
          target: metricset
          fields:
            module: kubernetes	

```

```auto
      - dissect:
          when:
            has_fields: ['event.module']
          tokenizer: "%{module}"
          field: "event.module"
          target_prefix: "metricset"

```

---

<div class="post-metadata">

**Author:** ![justinw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justinw/32/40277_2.png) [@justinw](https://discuss.elastic.co/u/justinw)\
**Post date:** [September 23, 2019, 6:27pm UTC](https://discuss.elastic.co/t/attempting-to-add-backward-compatible-field-metricset-module/200317/2 "2019-09-23T18:27:28Z")

</div>

Figured it out, posting the resolution for those who find this --

Turns out that there is an [alias field](https://www.elastic.co/blog/introducing-field-aliases-in-elasticsearch) for newer versions of metricbeat to handle compatibility.

Even though you won't see the field in the document, if you query for it, it'll return.

The relevant part of the index template for metricbeat 7.3.2

```auto
    "metricset": {
      "properties": {
        "module": {
          "type": "alias",
          "path": "event.module"
        },
        "name": {
          "type": "keyword",
          "ignore_above": 1024
        }
      }
    },

```

-- Justin

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 21, 2019, 6:27pm UTC](https://discuss.elastic.co/t/attempting-to-add-backward-compatible-field-metricset-module/200317/3 "2019-10-21T18:27:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
