# Changed field in filebeat but not working in logstash

**URL:** <https://discuss.elastic.co/t/changed-field-in-filebeat-but-not-working-in-logstash/324925>\
**Category:** Logstash\
**Created:** [February 7, 2023, 5:00pm UTC](https://discuss.elastic.co/t/changed-field-in-filebeat-but-not-working-in-logstash/324925 "2023-02-07T17:00:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![yc99](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yc99/32/116857_2.png) [@yc99](https://discuss.elastic.co/u/yc99)\
**Post date:** [February 7, 2023, 5:00pm UTC](https://discuss.elastic.co/t/changed-field-in-filebeat-but-not-working-in-logstash/324925/1 "2023-02-07T17:00:29Z")

</div>

I changed the source from access to admin and restarted the filebeat service, when I use grok to filter only the admin source, it is empty, but if using grok to filter only the access, it working. It should be source admin not access, if there any other configuration part I missed? I checked the kibana, the log have field.source = admin

```auto
- type: log
  enabled: true
  paths:
    - /etc/nginx/log/admin.log

  fields:
    source: admin

```

It is working while

```auto
if "access" in [source]{

mutate{
remove_field => ["event.original"]

}

 grok {
        match => { "message" => "%{IPORHOST:remote_ip} - %{DATA:user_name} \[%{HTTPDATE:time}\] \"%{WORD:method}%{DATA:url} HTTP/%{NUMBER:http_version}\" %{NUMBER:response_code} %{NUMBER:body_sent:bytes} \"%{DATA:referrer}\" \"%{DATA:agent}\" \"%{NUMBER:request_time}\" \"%{DATA:http_x_forwarded_for}\" %{IPORHOST:http_host} " }
        remove_field => "message"
  
    }
}

```

Not working while

```auto

if "admin" in [source]{

mutate{
remove_field => ["event.original"]

}

 grok {
        match => { "message" => "%{IPORHOST:remote_ip} - %{DATA:user_name} \[%{HTTPDATE:time}\] \"%{WORD:method}%{DATA:url} HTTP/%{NUMBER:http_version}\" %{NUMBER:response_code} %{NUMBER:body_sent:bytes} \"%{DATA:referrer}\" \"%{DATA:agent}\" \"%{NUMBER:request_time}\" \"%{DATA:http_x_forwarded_for}\" %{IPORHOST:http_host} " }
        remove_field => "message"
        remove_field => "event.original"
    }
}

```

 ![Screenshot 2023-02-08 at 12.52.05 AM](https://us1.discourse-cdn.com/elastic/original/3X/0/f/0f323d57d49a1dd64e908f3057ddc93523aa1b93.png)

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [February 8, 2023, 9:16pm UTC](https://discuss.elastic.co/t/changed-field-in-filebeat-but-not-working-in-logstash/324925/2 "2023-02-08T21:16:42Z")

</div>

This is the notation:  
"[event][original]"  
[field][source]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 8, 2023, 9:16pm UTC](https://discuss.elastic.co/t/changed-field-in-filebeat-but-not-working-in-logstash/324925/3 "2023-03-08T21:16:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
