# Clarification on logstash configuration

**URL:** <https://discuss.elastic.co/t/clarification-on-logstash-configuration/200619>\
**Category:** Logstash\
**Created:** [September 23, 2019, 3:49am UTC](https://discuss.elastic.co/t/clarification-on-logstash-configuration/200619 "2019-09-23T03:49:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![durgaram](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/durgaram/32/56392_2.png) [@durgaram](https://discuss.elastic.co/u/durgaram)\
**Post date:** [September 23, 2019, 3:49am UTC](https://discuss.elastic.co/t/clarification-on-logstash-configuration/200619/1 "2019-09-23T03:49:49Z")

</div>

I am trying to install ELK stack 7.3.2, I (filebeat included) have used the the following logstash conf., the fieldname logappname is not found in the kibana. Am I missing something?

input {  
beats {  
port =\> "5044"  
}  
}

# The filter part of this file is commented out to indicate that it is

# optional.

filter {  
grok {  
match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:logtimestamp} [%{WORD:thread}] %{LOGLEVEL:loglevel} %{GREEDYDATA:logmessage}"}  
}   
grok {  
match =\> { "path" =\> "%{GREEDYDATA:logappname}"}  
}  
date {   
match =\> ["logtimestamp", "ISO8601"]  
target =\> "@timestamp"  
}

```
mutate {
		remove_field => ["logtimestamp"]
	}

```

}  
output {  
#stdout { codec =\> rubydebug }  
elasticsearch { hosts =\> ["localhost:9200"]}

}

---

<div class="post-metadata">

**Author:** ![TechGeekNZ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/techgeeknz/32/54697_2.png) [@TechGeekNZ](https://discuss.elastic.co/u/TechGeekNZ)\
**Post date:** [September 23, 2019, 4:36am UTC](https://discuss.elastic.co/t/clarification-on-logstash-configuration/200619/2 "2019-09-23T04:36:02Z")

</div>

Can you provide some more context around the logappname value?

What data are you expecting to see in there? Is this the field that you are looking for;  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e0f99e8d954e74ad3864712d1dd401bb06ad51f.png)

---

<div class="post-metadata">

**Author:** ![durgaram](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/durgaram/32/56392_2.png) [@durgaram](https://discuss.elastic.co/u/durgaram)\
**Post date:** [September 23, 2019, 5:09am UTC](https://discuss.elastic.co/t/clarification-on-logstash-configuration/200619/3 "2019-09-23T05:09:11Z")

</div>

Yes, and this is the path details configured in filebeat

- type: log

and the log names under this folder is like TaskGenerator\_20190915.1.log  
and I need to have the value "TaskGenerator" for logappname

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 21, 2019, 5:09am UTC](https://discuss.elastic.co/t/clarification-on-logstash-configuration/200619/4 "2019-10-21T05:09:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
