# Create Field Winlogbeat

**URL:** <https://discuss.elastic.co/t/create-field-winlogbeat/233563>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 20, 2020, 3:00pm UTC](https://discuss.elastic.co/t/create-field-winlogbeat/233563 "2020-05-20T15:00:25Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![JeanN](https://avatars.discourse-cdn.com/v4/letter/j/b38774/32.png) [@JeanN](https://discuss.elastic.co/u/JeanN)\
**Post date:** [May 20, 2020, 3:00pm UTC](https://discuss.elastic.co/t/create-field-winlogbeat/233563/1 "2020-05-20T15:00:26Z")

</div>

Hello,

I want to create a Field with the value that i want like in Logstash.

For example in my Logstash configuration i set in the fingerprint module:

`add_field => {"key" => "123" }`

On the log (In Kibana), I saw this field ("key") with the value associated("123") from Logstash but i want to do the same field from Winlogbeat.

How can i do that please ?

---

<div class="post-metadata">

**Author:** ![Coinology](https://avatars.discourse-cdn.com/v4/letter/c/3e96dc/32.png) [@Coinology](https://discuss.elastic.co/u/Coinology)\
**Post date:** [May 22, 2020, 10:01pm UTC](https://discuss.elastic.co/t/create-field-winlogbeat/233563/2 "2020-05-22T22:01:03Z")

</div>

@JeanN Use the `add_fields` processor. Check out [this](https://www.elastic.co/guide/en/beats/winlogbeat/master/add-fields.html) section of the docs. Hopefully that helps!

---

<div class="post-metadata">

**Author:** ![JeanN](https://avatars.discourse-cdn.com/v4/letter/j/b38774/32.png) [@JeanN](https://discuss.elastic.co/u/JeanN)\
**Post date:** [May 27, 2020, 7:26am UTC](https://discuss.elastic.co/t/create-field-winlogbeat/233563/3 "2020-05-27T07:26:35Z")

</div>

Thanks for your answer @Coinology .

I'm sorry my ticket wasn't complete, but i already use this field (add\_fields) in winlogbeat configuration, and in Kibana's logs i don't have this "new field" from winlogbeat.

```auto
processors:
  - add_fields:
      fields:
        name: keys
        id: '123'

```

I also want to choose the value of my fields like i did it in logstash, is there a setting to do this in that plugin ?

Thanks.

---

<div class="post-metadata">

**Author:** ![Coinology](https://avatars.discourse-cdn.com/v4/letter/c/3e96dc/32.png) [@Coinology](https://discuss.elastic.co/u/Coinology)\
**Post date:** [May 27, 2020, 11:35pm UTC](https://discuss.elastic.co/t/create-field-winlogbeat/233563/4 "2020-05-27T23:35:57Z")

</div>

@JeanN hmm, that should be working. If you run Winlogbeat manually, are you seeing any errors?

Regarding the value of the fields, I am not sure what you are asking. Can you clarify? If I'm understanding you correctly, then you are already choosing the value with the add\_fields processor.

For example:

> ```
> processors:
> - add_fields:
> fields:
> name: keys
> id: '123'
> 
> ```

This adds two fields. One named _name_ with a value of _keys_ and one named _id_ with a value of _123_. Am I missing something?

---

<div class="post-metadata">

**Author:** ![JeanN](https://avatars.discourse-cdn.com/v4/letter/j/b38774/32.png) [@JeanN](https://discuss.elastic.co/u/JeanN)\
**Post date:** [May 28, 2020, 5:55am UTC](https://discuss.elastic.co/t/create-field-winlogbeat/233563/5 "2020-05-28T05:55:34Z")

</div>

@Coinology Thanks for your answer, i find my error.

It was cause of several "processors" at top-level that i put in my configuration, so the yaml parser can't handle correctly, but now it works.

I didn't understand those plugin settings (add\_fields) like this but now i do, thank you for your time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 25, 2020, 5:56am UTC](https://discuss.elastic.co/t/create-field-winlogbeat/233563/6 "2020-06-25T05:56:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
