I have tried some variations with setting the source field like with or without fields_under_root set to true, setting it as a top-level prospector field and so forth, but it doesn't work. How to override it? Maybe that's a graylog issue?
I think the problem is with the name source. This field is already used for the filename source. But if you use it under fields without fields_under_root it should work.
Can you run filebeat with -e -d "publish" and check if the fields.source shows up? If yes, it is probably graylog specifc.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.