# Define custom field on launch

**URL:** <https://discuss.elastic.co/t/define-custom-field-on-launch/211085>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [December 9, 2019, 9:55am UTC](https://discuss.elastic.co/t/define-custom-field-on-launch/211085 "2019-12-09T09:55:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [December 9, 2019, 9:55am UTC](https://discuss.elastic.co/t/define-custom-field-on-launch/211085/1 "2019-12-09T09:55:52Z")

</div>

Added two metadata fields under 'host' to our index template and preloaded this into our elastic cluster like this:

```
    "metadata": {
      "properties": {
        "id1": {
          "type": "long"
        },
        "id2": {
          "type": "long"
        }
      }
    },

```

Hoped we could define these values when launching the winlogbeat service by adding -E metadata.idX=valX arguments (X=1|2) and then in the YML file do this:

```
processors:
  - add_cloud_metadata: ~
  - add_docker_metadata: ~
  - add_host_metadata:
      netinfo.enabled: true
  - add_fields:
      target: host.metadata
      fields:
        id1: ${metadata.id1?You need to set the metadata.id1 environment variable}
        id2: ${metadata.id2?You need to set the metadata.id2 environment variable}

```

But we get this error when attempting to launch service:

```
2019-12-09T10:50:11.266+0100	ERROR	instance/beat.go:916	Exiting: error initializing processors: fail to unpack the add_fields configuration: missing field accessing 'processors.3.add_fields.fields.assetid' (source:'C:\Program Files\WinlogBeat\winlogbeat.yml')

```

Why?

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [December 9, 2019, 1:18pm UTC](https://discuss.elastic.co/t/define-custom-field-on-launch/211085/2 "2019-12-09T13:18:43Z")

</div>

Wonder how define a dictionary for the add\_fields processor, doc says:

"The `add_fields` processor adds additional fields to the event. Fields can be scalar values, arrays, dictionaries, or any nested combination of these."

```
  - add_fields:
      target: host
      fields:
        metadata: {
          id1: ${metadata.id1?You need to set the metadata.id1 environment variable},
          id2: ${metadata.id2?You need to set the metadata.id2 environment variable}
       }

```

Just gives me:

```
Exiting: error loading config file: yaml: line 131: did not find expected ',' or '}'

```

Need I define environment variables or can I parse as -E metadata.idX=valX arguments?

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [December 9, 2019, 1:53pm UTC](https://discuss.elastic.co/t/define-custom-field-on-launch/211085/3 "2019-12-09T13:53:43Z")

</div>

🙂 Seems what failed was the env.var expansion:

```
${metadata.id1?You need to set the metadata.id1 environment variable}

```

This works as expected:

```
  - add_fields:
      target: host
      fields:
        metadata.id1: ${metadata.id1:def.value1}
        metadata.id2: ${metadata.id2:def.value2}

```

giving me:

```
host.metadata.id1: env.var.value1
host.metadata.id2: env.var.value2
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 6, 2020, 1:53pm UTC](https://discuss.elastic.co/t/define-custom-field-on-launch/211085/4 "2020-01-06T13:53:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
