# Enrich (or manipulate) filebeat data

**URL:** <https://discuss.elastic.co/t/enrich-or-manipulate-filebeat-data/168250>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 13, 2019, 3:18pm UTC](https://discuss.elastic.co/t/enrich-or-manipulate-filebeat-data/168250 "2019-02-13T15:18:23Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ooii](https://avatars.discourse-cdn.com/v4/letter/o/b38774/32.png) [@ooii](https://discuss.elastic.co/u/ooii)\
**Post date:** [February 13, 2019, 3:18pm UTC](https://discuss.elastic.co/t/enrich-or-manipulate-filebeat-data/168250/1 "2019-02-13T15:18:23Z")

</div>

I'm new to the ELK stack and I'm trying to have my Nginx stats in Kibana. For that purpose, I use Filebeat and its Nginx module to send data directly to Elasticseach. I then use Kibana to visualise them. However, I'd like to have stats per sub-domain name ([sub1.mydomain.com](http://sub1.mydomain.com), [sub2.mydomain.com](http://sub2.mydomain.com), etc) whatever the remaining part of the url.  
I googled about that and did not find anything that can help. I know I can send the output of Filebeat to Logstash and do it myself. But I assume other people have the same needs and a robust solution already exists. Thanks for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 13, 2019, 3:18pm UTC](https://discuss.elastic.co/t/enrich-or-manipulate-filebeat-data/168250/2 "2019-03-13T15:18:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
