# Data is redundant in filebeat system module

**URL:** <https://discuss.elastic.co/t/data-is-redundant-in-filebeat-system-module/340096>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [August 4, 2023, 5:35am UTC](https://discuss.elastic.co/t/data-is-redundant-in-filebeat-system-module/340096 "2023-08-04T05:35:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![e997cd7e8d9915436150](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/e997cd7e8d9915436150/32/40255_2.png) [@e997cd7e8d9915436150](https://discuss.elastic.co/u/e997cd7e8d9915436150)\
**Post date:** [August 4, 2023, 5:35am UTC](https://discuss.elastic.co/t/data-is-redundant-in-filebeat-system-module/340096/1 "2023-08-04T05:35:11Z")

</div>

Hi, i indexed linux secure log via filebeat system module. And the `user.name` field is duplicated.

 ![filebeat_system_module2](https://us1.discourse-cdn.com/elastic/original/3X/f/7/f7b4a80e7174434494e08f68cf3668c92a3d60fb.png)  
 ![filebeat_system_module3](https://us1.discourse-cdn.com/elastic/original/3X/0/c/0c2d79a0b2c093534436213dee525538abae03a8.png)

Most `user.name` has two versions. The version that start with a blank and the other version that doesn't.

 ![filebeat_system_module4](https://us1.discourse-cdn.com/elastic/original/3X/1/d/1d86135d44b54c602c1a9c5b41efaa157e34aa38.png)

There are no blank strings with `user.name` meaning.

 ![filebeat_system_module5](https://us1.discourse-cdn.com/elastic/original/3X/c/a/ca0a76342420bf2eade5f12300222af24b32eb76.png)

Has anyone experienced the same problem? Thanks in advance.

---

<div class="post-metadata">

**Author:** ![e997cd7e8d9915436150](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/e997cd7e8d9915436150/32/40255_2.png) [@e997cd7e8d9915436150](https://discuss.elastic.co/u/e997cd7e8d9915436150)\
**Post date:** [August 4, 2023, 5:18pm UTC](https://discuss.elastic.co/t/data-is-redundant-in-filebeat-system-module/340096/2 "2023-08-04T17:18:07Z")

</div>

Solved the problem.  
Just modify `/usr/share/filebeat/module/system/auth/ingest/pipeline.yml`.  
Added blank after strings `invalid user`.  
Don't forget to add `filebeat.overwrite_pipeline: true` to `filebeat.yml` before restart filebeat.

Before:

```auto
  - grok:
      description: Grok specific auth messages.
      tag: grok-specific-messages
      field: _temp.message
      ignore_missing: true
      patterns:
        - '^%{DATA:system.auth.ssh.event} %{DATA:system.auth.ssh.method} for (invalid user)?%{DATA:user.name} from %{IPORHOST:source.address} port %{NUMBER:source.port:long} ssh2(: %{GREEDYDATA:system.auth.ssh.signature})?'

```

After:

```auto
  - grok:
      description: Grok specific auth messages.
      tag: grok-specific-messages
      field: _temp.message
      ignore_missing: true
      patterns:
        - '^%{DATA:system.auth.ssh.event} %{DATA:system.auth.ssh.method} for (invalid user )?%{DATA:user.name} from %{IPORHOST:source.address} port %{NUMBER:source.port:long} ssh2(: %{GREEDYDATA:system.auth.ssh.signature})?'

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2023, 7:18pm UTC](https://discuss.elastic.co/t/data-is-redundant-in-filebeat-system-module/340096/3 "2023-09-01T19:18:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
