# Easier acces to information regarding the default fields sent by all the Beats

**URL:** <https://discuss.elastic.co/t/easier-acces-to-information-regarding-the-default-fields-sent-by-all-the-beats/383290>\
**Category:** Beats\
**Tags:** beats-development\
**Created:** [November 7, 2025, 12:33pm UTC](https://discuss.elastic.co/t/easier-acces-to-information-regarding-the-default-fields-sent-by-all-the-beats/383290 "2025-11-07T12:33:52Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jose\_E](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jose_e/32/47012_2.png) [@Jose\_E](https://discuss.elastic.co/u/Jose_E)\
**Post date:** [November 7, 2025, 12:33pm UTC](https://discuss.elastic.co/t/easier-acces-to-information-regarding-the-default-fields-sent-by-all-the-beats/383290/1 "2025-11-07T12:33:53Z")

</div>

Hi there,

I have a quick suggestion to improve the documentation of all the beats. Why don’t you add a section explaining the default fields that are expected of the beats, in the documentation?

I don’t have to work often with filebeat or metricbeat, just once in a while to make a new integration or some sort of modification, and when the time comes, I always find myself with the same problems: what parameters is my filebeat sending to logstash? And sadly, I never find a place in the documentation that shows a list of the parameters you should be expecting, which makes creating new pipelines even slower, since you are never sure whether you can count on having a hostname field or a log.file.path field. I can be certain of the parameters I am sending using the modules, but not the default ones.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 7, 2025, 5:08pm UTC](https://discuss.elastic.co/t/easier-acces-to-information-regarding-the-default-fields-sent-by-all-the-beats/383290/2 "2025-11-07T17:08:19Z")

</div>

Wouldn't these documentation have this information?

For Filebeat: [Exported fields | Beats](https://www.elastic.co/docs/reference/beats/metricbeat/exported-fields)

and

For Metricbeat: [Exported fields | Beats](https://www.elastic.co/docs/reference/beats/filebeat/exported-fields)

The fields will depend on which module is being used and also if you have any metadata processor enabled.

For example, if you add the `add_host_metadata` processor, you should expect host fields like these: [Add Host metadata | Beats](https://www.elastic.co/docs/reference/beats/metricbeat/add-host-metadata)
