# Cannot append\_fields on custom template

**URL:** <https://discuss.elastic.co/t/cannot-append-fields-on-custom-template/327855>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 16, 2023, 1:14pm UTC](https://discuss.elastic.co/t/cannot-append-fields-on-custom-template/327855 "2023-03-16T13:14:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![GeorgeGkinis](https://avatars.discourse-cdn.com/v4/letter/g/ecc23a/32.png) [@GeorgeGkinis](https://discuss.elastic.co/u/GeorgeGkinis)\
**Post date:** [March 16, 2023, 1:14pm UTC](https://discuss.elastic.co/t/cannot-append-fields-on-custom-template/327855/1 "2023-03-16T13:14:59Z")

</div>

Hello!

I am using filebeat 7.17.6 and I am using the nginx module.

I have altered the access log pipeline to include additional fields.  
Everything is grokked fine.

My issue is that when i define the additional fields they are added to the **filebeat-** \* template and not to my custom **nginx-logs** \* template.

my config :

```auto
name: ${BEAT_NAME:default}
filebeat.modules:
  #--------------------------------- Nginx Module ---------------------------------
  - module: nginx
    # Access logs
    access:
      enabled: true
      var.paths: ["/nginx/*access.log"]
    error:
      enabled: true
      var.paths: ["/nginx/error.log"]

setup.template.settings:
  index.number_of_shards: 1

output.elasticsearch:
  # Array of hosts to connect to.
  hosts: ["172.17.0.1:9243"]
  index: "nginx-logs-%{+yyyy.MM.dd}"
  username: "beat_user"
  password: "beat_pass"
  protocol: https
  ssl.verification_mode: none
  headers:
    X-Found-Cluster: ${FILEBEAT_OUTPUT_ES_CLUSTER_ID}

setup:
  ilm:
    enabled: true
    overwrite: true
    rollover_alias: "nginx-logs"
    pattern: "{now/d}-000001"
    policy_file: /usr/share/filebeat/ilm.policy.nginx.json
  template:
    name: "nginx-logs"
    overwrite: true
    pattern: "nginx-logs*"
    append_fields:
        - name: nginx.access.request_time
          type: float
        - name: nginx.access.upstream_header_time
          type: float
        - name: nginx.access.upstream_connect_time
          type: float
        - name: nginx.access.upstream_response_time
          type: float

xpack.monitoring.enabled: true

```

---

<div class="post-metadata">

**Author:** ![GeorgeGkinis](https://avatars.discourse-cdn.com/v4/letter/g/ecc23a/32.png) [@GeorgeGkinis](https://discuss.elastic.co/u/GeorgeGkinis)\
**Post date:** [March 16, 2023, 2:00pm UTC](https://discuss.elastic.co/t/cannot-append-fields-on-custom-template/327855/2 "2023-03-16T14:00:54Z")

</div>

> [@GeorgeGkinis](#):
>
> `upstream_response_time`

I had another filebeat instance running which created the indices anew after deleting them.  
The above solution works.

Closing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2023, 4:01pm UTC](https://discuss.elastic.co/t/cannot-append-fields-on-custom-template/327855/3 "2023-04-13T16:01:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
