# Dynamically injecting custom fields to logstash from filebeat

**URL:** <https://discuss.elastic.co/t/dynamically-injecting-custom-fields-to-logstash-from-filebeat/172104>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 13, 2019, 9:47am UTC](https://discuss.elastic.co/t/dynamically-injecting-custom-fields-to-logstash-from-filebeat/172104 "2019-03-13T09:47:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sachhiiiinn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sachhiiiinn/32/47173_2.png) [@sachhiiiinn](https://discuss.elastic.co/u/sachhiiiinn)\
**Post date:** [March 13, 2019, 9:47am UTC](https://discuss.elastic.co/t/dynamically-injecting-custom-fields-to-logstash-from-filebeat/172104/1 "2019-03-13T09:47:09Z")

</div>

I have set up filebeat to send logs from one of our servers to logstash. It's working fine but the message view in Kibana is pretty ugly and hard to debug as the message is pretty big(it's web service message,xml or json, sent and recieved ). So I was wondering if there's a way to extract some fields from the message, for example order Id or processid , and inject them to custom fields so that user can query based on those fields.

Please note that these webservice logs are written by a cots product via out of the box feature. So, pretty printing before writing to log file is not an option.

Somethng like this..

paths:

- /opt/jboss/jboss-eap-7.0/bin/log/webservices.log  
encoding: plain  
multiline.pattern: '^[[:digit:]]{4}-[[:digit:]]{2}-[[:digit:]]{2}'  
multiline.negate: true  
multiline.match: after  
fields:  
application-name: customApp  
#order-Id: value from message?????  
#thread-name: from message???

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [March 13, 2019, 2:32pm UTC](https://discuss.elastic.co/t/dynamically-injecting-custom-fields-to-logstash-from-filebeat/172104/2 "2019-03-13T14:32:20Z")

</div>

You can use the [`dissect`](https://www.elastic.co/guide/en/logstash/current/plugins-filters-dissect.html) or [`grok`](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html) filter in Logstash for parsing your logs.  
Logstash also has a [`json`](https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html) and [`xml`](https://www.elastic.co/guide/en/logstash/current/plugins-filters-xml.html) filter.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2019, 9:47am UTC](https://discuss.elastic.co/t/dynamically-injecting-custom-fields-to-logstash-from-filebeat/172104/3 "2019-04-10T09:47:14Z")

</div>

This topic was automatically closed after 28 days. New replies are no longer allowed.
