# Configuring analyser for field inside filbeat configuration file

**URL:** <https://discuss.elastic.co/t/configuring-analyser-for-field-inside-filbeat-configuration-file/270232>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 15, 2021, 12:31pm UTC](https://discuss.elastic.co/t/configuring-analyser-for-field-inside-filbeat-configuration-file/270232 "2021-04-15T12:31:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bbtl](https://avatars.discourse-cdn.com/v4/letter/b/e36b37/32.png) [@bbtl](https://discuss.elastic.co/u/bbtl)\
**Post date:** [April 15, 2021, 12:31pm UTC](https://discuss.elastic.co/t/configuring-analyser-for-field-inside-filbeat-configuration-file/270232/1 "2021-04-15T12:31:11Z")

</div>

Hi

I am currently using filbeat to send logs to ELK stack. However, one of the fields has a syslog structure and I would like to force filbeat to use a whitespace analyser and I would also like to have the .raw version of the field for regex search.

I have searched the documents and the closest I can see to this is: **`setup.template.settings`** on: [Configure Elasticsearch index template loading | Filebeat Reference [7.12] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-template.html)

However, I don't really know how to use this field to configure the mappings as I see on: [Update index settings API | Elasticsearch Guide [7.12] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-update-settings.html).

Would someone be so kind to help me with this. I cannot seem to find any online examples for this.

Thanks ind advance

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [May 10, 2021, 4:44pm UTC](https://discuss.elastic.co/t/configuring-analyser-for-field-inside-filbeat-configuration-file/270232/2 "2021-05-10T16:44:13Z")

</div>

Hey @bbtl, welcome to discuss 🙂

Are you using any of the Filebeat modules, or you are using the syslog input directly?

Would be an option for this to use [processors](https://www.elastic.co/guide/en/beats/filebeat/7.12/defining-processors.html)? They would allow to move your original field to some field like `.raw`, and then use processors such as `dissect` or `script` to extract the information you need.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2021, 6:44pm UTC](https://discuss.elastic.co/t/configuring-analyser-for-field-inside-filbeat-configuration-file/270232/3 "2021-06-07T18:44:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
