# CEF Logging not indexing field "event.original:"

**URL:** <https://discuss.elastic.co/t/cef-logging-not-indexing-field-event-original/299756>\
**Category:** Elastic Security\
**Tags:** fleet, elastic-agent\
**Created:** [March 15, 2022, 3:38pm UTC](https://discuss.elastic.co/t/cef-logging-not-indexing-field-event-original/299756 "2022-03-15T15:38:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![janis.cimins](https://avatars.discourse-cdn.com/v4/letter/j/d2c977/32.png) [@janis.cimins](https://discuss.elastic.co/u/janis.cimins)\
**Post date:** [March 15, 2022, 3:38pm UTC](https://discuss.elastic.co/t/cef-logging-not-indexing-field-event-original/299756/1 "2022-03-15T15:38:11Z")

</div>

I have customer who ingests logs with CEF filebeat module. There is this field:"event.original:" and it does not index so it is not searchable.

They ingest barracuda logs in this way. But I have trouble on setting up barracuda module. It gives me this error when I enable module and run "sudo filebeat setup -e"

2022-03-15T15:32:39.986Z ERROR instance/beat.go:1015 Exiting: 1 error: error loading config file: invalid config: yaml: line 8: did not find expected key  
Exiting: 1 error: error loading config file: invalid config: yaml: line 8: did not find expected key

---

<div class="post-metadata">

**Author:** ![janis.cimins](https://avatars.discourse-cdn.com/v4/letter/j/d2c977/32.png) [@janis.cimins](https://discuss.elastic.co/u/janis.cimins)\
**Post date:** [March 15, 2022, 3:45pm UTC](https://discuss.elastic.co/t/cef-logging-not-indexing-field-event-original/299756/2 "2022-03-15T15:45:27Z")

</div>

It basically points to commented out row in barracuda.yml configration file  
spamfirewall:  
enabled: true

```
# Set which input to use between udp (default), tcp or file.>>> This row
 var.input: udp
 var.syslog_host: 0.0.0.0
 var.syslog_port: 9524
```

---

<div class="post-metadata">

**Author:** ![janis.cimins](https://avatars.discourse-cdn.com/v4/letter/j/d2c977/32.png) [@janis.cimins](https://discuss.elastic.co/u/janis.cimins)\
**Post date:** [March 15, 2022, 3:58pm UTC](https://discuss.elastic.co/t/cef-logging-not-indexing-field-event-original/299756/3 "2022-03-15T15:58:17Z")

</div>

Seems that I get tthis error just as I uncomment fields in barracuda.yml file.  
Should they stay commented out? Asking for a friend 🙂

---

<div class="post-metadata">

**Author:** ![janis.cimins](https://avatars.discourse-cdn.com/v4/letter/j/d2c977/32.png) [@janis.cimins](https://discuss.elastic.co/u/janis.cimins)\
**Post date:** [March 16, 2022, 12:00pm UTC](https://discuss.elastic.co/t/cef-logging-not-indexing-field-event-original/299756/4 "2022-03-16T12:00:12Z")

</div>

Maybe I`m doing something wrong with this configuration? I have set up CEF module and it is good. As well as threatintel and works as well, but for some reason this is not working

---

<div class="post-metadata">

**Author:** ![janis.cimins](https://avatars.discourse-cdn.com/v4/letter/j/d2c977/32.png) [@janis.cimins](https://discuss.elastic.co/u/janis.cimins)\
**Post date:** [March 16, 2022, 1:57pm UTC](https://discuss.elastic.co/t/cef-logging-not-indexing-field-event-original/299756/5 "2022-03-16T13:57:04Z")

</div>

UPDATE:  
I have figured out that when uncommenting these lines it gives error just one line before last uncomment:  
Exiting: 1 error: error loading config file: invalid config: yaml: line 8: did not find expected key

Maybe I`m doing something wrong with configuring this module?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2022, 1:57pm UTC](https://discuss.elastic.co/t/cef-logging-not-indexing-field-event-original/299756/6 "2022-04-13T13:57:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
