# Dynamic Root Field

**URL:** <https://discuss.elastic.co/t/dynamic-root-field/105595>\
**Category:** Beats\
**Tags:** beats-development\
**Created:** [October 27, 2017, 4:50pm UTC](https://discuss.elastic.co/t/dynamic-root-field/105595 "2017-10-27T16:50:17Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![jcatana](https://avatars.discourse-cdn.com/v4/letter/j/9e8a1a/32.png) [@jcatana](https://discuss.elastic.co/u/jcatana)\
**Post date:** [October 27, 2017, 4:50pm UTC](https://discuss.elastic.co/t/dynamic-root-field/105595/1 "2017-10-27T16:50:17Z")

</div>

How could I modify a beat to apply a dynamic root field to all events?

For instance, I want to modify metricbeat and apply a set of tags for changing ongoing events to every metric that is collected so I can correlate on metrics on this data.

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [October 30, 2017, 9:39am UTC](https://discuss.elastic.co/t/dynamic-root-field/105595/2 "2017-10-30T09:39:37Z")

</div>

Hi @jcatana,

That's an interesting use case, we have done things like this in the past, normally through processors. Could you explain a bit on what you are seeking? It may make sense to offer this feature in a generic way so everyone can benefit from it 🙂

---

<div class="post-metadata">

**Author:** ![jcatana](https://avatars.discourse-cdn.com/v4/letter/j/9e8a1a/32.png) [@jcatana](https://discuss.elastic.co/u/jcatana)\
**Post date:** [October 30, 2017, 2:11pm UTC](https://discuss.elastic.co/t/dynamic-root-field/105595/3 "2017-10-30T14:11:15Z")

</div>

I run a large HPC center. I would like to correlate system metrics to jobs. Jobs are transient coming and going from multiple systems during the day.  
I want to easily correlate the metrics recorded to the job that is running or ran.  
Being able to globally tag each event recorded with the job ID or IDs currently running seems like the easiest option to make use of the filter functionality provided in the kibana dashboards.

I've been able to write my own module to gather the data and create events, but I can't figure out how to hook in to make it globally tag all events the are recorded.

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [October 31, 2017, 9:17am UTC](https://discuss.elastic.co/t/dynamic-root-field/105595/4 "2017-10-31T09:17:12Z")

</div>

Would the `fields` setting work for you in this case? Have a look at [https://www.elastic.co/guide/en/beats/metricbeat/5.6/configuring-howto-metricbeat.html](https://www.elastic.co/guide/en/beats/metricbeat/5.6/configuring-howto-metricbeat.html) for details

---

<div class="post-metadata">

**Author:** ![jcatana](https://avatars.discourse-cdn.com/v4/letter/j/9e8a1a/32.png) [@jcatana](https://discuss.elastic.co/u/jcatana)\
**Post date:** [October 31, 2017, 2:21pm UTC](https://discuss.elastic.co/t/dynamic-root-field/105595/5 "2017-10-31T14:21:37Z")

</div>

A field may work, but the documentation in that link is not very informative.

1. I need this to be updated dynamically. Preferably without restarting the service or reloading the config file.

2. I may have multiple jobs on the same system which is why tags were appealing.  
I would need something like  
fields:  
jobid: ["10.job", "11.job", "12.job"]

or  
fields:  
jobid: "10.job"  
jobid: "11.job"  
jobid: "12.job"

I'm guessing we cannot have duplicate keys.

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [November 2, 2017, 12:20pm UTC](https://discuss.elastic.co/t/dynamic-root-field/105595/6 "2017-11-02T12:20:33Z")

</div>

> [@jcatana](#):
>
> I've been able to write my own module to gather the data and create events, but I can't figure out how to hook in to make it globally tag all events the are recorded.

I'm wondering, why don't you add this info to your module events?

---

<div class="post-metadata">

**Author:** ![jcatana](https://avatars.discourse-cdn.com/v4/letter/j/9e8a1a/32.png) [@jcatana](https://discuss.elastic.co/u/jcatana)\
**Post date:** [November 2, 2017, 1:06pm UTC](https://discuss.elastic.co/t/dynamic-root-field/105595/7 "2017-11-02T13:06:23Z")

</div>

I want the field/tag to be in the events for all modules of the beat, not only my module. How would I do that?

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [November 2, 2017, 1:48pm UTC](https://discuss.elastic.co/t/dynamic-root-field/105595/8 "2017-11-02T13:48:39Z")

</div>

Then your best shot is to write a new processor, check [https://github.com/elastic/beats/tree/master/libbeat/processors/add\_locale](https://github.com/elastic/beats/tree/master/libbeat/processors/add_locale) as a simple example 🙂

---

<div class="post-metadata">

**Author:** ![jcatana](https://avatars.discourse-cdn.com/v4/letter/j/9e8a1a/32.png) [@jcatana](https://discuss.elastic.co/u/jcatana)\
**Post date:** [November 2, 2017, 11:50pm UTC](https://discuss.elastic.co/t/dynamic-root-field/105595/9 "2017-11-02T23:50:14Z")

</div>

This appears to be exactly what I'm looking for. I'll look into it and let you know how it turns out.

---

<div class="post-metadata">

**Author:** ![jcatana](https://avatars.discourse-cdn.com/v4/letter/j/9e8a1a/32.png) [@jcatana](https://discuss.elastic.co/u/jcatana)\
**Post date:** [November 3, 2017, 9:54pm UTC](https://discuss.elastic.co/t/dynamic-root-field/105595/10 "2017-11-03T21:54:30Z")

</div>

Yep, it works perfectly. Thanks a ton for helping me locate this and figure this out!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 1, 2017, 9:55pm UTC](https://discuss.elastic.co/t/dynamic-root-field/105595/11 "2017-12-01T21:55:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
