# Custom fields posibility

**URL:** <https://discuss.elastic.co/t/custom-fields-posibility/48575>\
**Category:** Beats\
**Tags:** beats-development\
**Created:** [April 27, 2016, 4:47pm UTC](https://discuss.elastic.co/t/custom-fields-posibility/48575 "2016-04-27T16:47:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bruno\_Lavoie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bruno_lavoie/32/8408_2.png) [@Bruno\_Lavoie](https://discuss.elastic.co/u/Bruno_Lavoie)\
**Post date:** [April 27, 2016, 4:47pm UTC](https://discuss.elastic.co/t/custom-fields-posibility/48575/1 "2016-04-27T16:47:47Z")

</div>

Hello,

We're using a lot filebeat to scrape log files and send them to our ELK infrastructure. We're sending logs from many systems, and want them isolated by their own indices.

With filebeat, it's easy: we use the _fields_ config at the prospector level to help us do that.

Example:

```
filebeat:
  prospectors:
    -
      paths:
        - /path/to/log/files/*.log

      [...]
      
      fields:
        elk: 
          client: <client code>
          index: <target index>
          ...

      fields_under_root: true

```

So, I thought that it could be the same method used for all the beats....  
Looking to packetbeat, it doesn't seems... ☹

Is there a way to force custom fields to all beats?  
Can it be easily added?

Also, in filebeat it can be done at a specific prospector level. In our case it's perfect. But would be nice to be able to specify _fields_ at all levels of config:

- beat, default for all events spooled out from the beat
- filebeat - prospector level: be able to be more specific by prospector level
- packetbeat - protocol level: be able to be more specific by defined protocol
- ... and so on ...

If it's not possible, we must create a dedicated input (and opening ports) per originating clients/system to assign them theses values at input level... 😵

Don't know if it's bad because each input generally creates a thread.... ?

Thanks  
Bruno Lavoie

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 27, 2016, 7:34pm UTC](https://discuss.elastic.co/t/custom-fields-posibility/48575/2 "2016-04-27T19:34:08Z")

</div>

In version 5 we added the ability to set fields at the beat level. It's all pretty well explained in this [pull request](https://github.com/elastic/beats/pull/1092). I didn't add it to each protocol in Packetbeat, but it wouldn't be too hard to do if you were interested in contributing.

Docs: [https://www.elastic.co/guide/en/beats/filebeat/master/configuration-shipper.html#libbeat-configuration-fields](https://www.elastic.co/guide/en/beats/filebeat/master/configuration-shipper.html#libbeat-configuration-fields)

---

<div class="post-metadata">

**Author:** ![Bruno\_Lavoie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bruno_lavoie/32/8408_2.png) [@Bruno\_Lavoie](https://discuss.elastic.co/u/Bruno_Lavoie)\
**Post date:** [May 3, 2016, 3:44pm UTC](https://discuss.elastic.co/t/custom-fields-posibility/48575/3 "2016-05-03T15:44:27Z")

</div>

Nice, as our upgrading schedule is sometime slow, is it easy/possible to backport it to a current stable release?  
Thanks  
Bruno Lavoie

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 4, 2016, 2:28am UTC](https://discuss.elastic.co/t/custom-fields-posibility/48575/4 "2016-05-04T02:28:40Z")

</div>

Anything is possible 😏, but it probably would be a bit a work since this feature touched a lot files (see [PR](https://github.com/elastic/beats/pull/1092/files)). Also I don't think there is another point release planned for 1.x at the moment, only releases to fix bugs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:52pm UTC](https://discuss.elastic.co/t/custom-fields-posibility/48575/5 "2017-07-05T21:52:25Z")

</div>


