# Can't get app\_process\_metadata to work in Filebeat

**URL:** <https://discuss.elastic.co/t/cant-get-app-process-metadata-to-work-in-filebeat/158106>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 26, 2018, 12:28am UTC](https://discuss.elastic.co/t/cant-get-app-process-metadata-to-work-in-filebeat/158106 "2018-11-26T00:28:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![DPattee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dpattee/32/37772_2.png) [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Post date:** [November 26, 2018, 12:28am UTC](https://discuss.elastic.co/t/cant-get-app-process-metadata-to-work-in-filebeat/158106/1 "2018-11-26T00:28:41Z")

</div>

I use two add\_process\_metadata directives in my metric beat config to get the parent process info and extra details on the specific process. Now I'm trying to add extra process information to syslog messages pulled in via filebeat.

```
- add_process_metadata:
    match_pids: [system.syslog.pid]
    target: system.process.details

```

This doesn't ever seem to execute on syslog entries though - entries that do have a system.syslog.pid don't get any additional fields added, unlike how it works in metricbeat.

One thing I noticed was that compared to all other pid fields, the system.syslog.pid gets indexed as text instead of number.

I tried changing that by deleting the indexes and adding

```
setup.template.enabled: true
setup.template.fields: "${path.config}/fields.yml"
setup.template.overwrite: true
setup.template.append_fields:
  - name: system.syslog.pid
    type: long

```

to my config but that just throws warnings that 'append fields contains field that is already in use' since syslog.pid gets defined in the fields.yml. I tried making it a 'long' in fields.yml and that didn't work either.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [November 26, 2018, 8:10am UTC](https://discuss.elastic.co/t/cant-get-app-process-metadata-to-work-in-filebeat/158106/2 "2018-11-26T08:10:03Z")

</div>

Are you using the `system/syslog` module?  
If yes, the problem is that the field `system.syslog.pid` is only added by Elasticsearch. When Filebeat encounters syslog events, none of them has that field. Thus, process metadata is never added.  
If not, could you please share your whole config formatted using `</>`?

---

<div class="post-metadata">

**Author:** ![DPattee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dpattee/32/37772_2.png) [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Post date:** [November 26, 2018, 4:26pm UTC](https://discuss.elastic.co/t/cant-get-app-process-metadata-to-work-in-filebeat/158106/3 "2018-11-26T16:26:42Z")

</div>

Yea, I've switched to using the modules for metric & filebeats with these latest release instead of making the base metricbeat.yml/filebeat.yml huge.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2018, 4:26pm UTC](https://discuss.elastic.co/t/cant-get-app-process-metadata-to-work-in-filebeat/158106/4 "2018-12-24T16:26:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
