# Env variables in not working in custom fields in filebeat

**URL:** <https://discuss.elastic.co/t/env-variables-in-not-working-in-custom-fields-in-filebeat/101374>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 21, 2017, 5:19pm UTC](https://discuss.elastic.co/t/env-variables-in-not-working-in-custom-fields-in-filebeat/101374 "2017-09-21T17:19:27Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rohit\_Singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohit_singh/32/46630_2.png) [@Rohit\_Singh](https://discuss.elastic.co/u/Rohit_Singh)\
**Post date:** [September 21, 2017, 5:19pm UTC](https://discuss.elastic.co/t/env-variables-in-not-working-in-custom-fields-in-filebeat/101374/1 "2017-09-21T17:19:27Z")

</div>

Filebeat version 5.6  
centos 7.0

I am using env variable like this  
fields\_under\_root: true  
fields:  
clustername: ${CLUSTER\_NAME}

output of # env  
[HOSTNAME=gsljumphost.cisco.com](http://HOSTNAME=gsljumphost.cisco.com)  
SHELL=/bin/bash  
TERM=xterm  
HISTSIZE=1000  
CLUSTER\_NAME=lokitest

however inspite of setting it as env variable getting following error  
CRIT Exiting: error loading states for prospector 0: missing field accessing 'filebeat.prospectors.0.fields.clustername' (source:'/home/cloud-user/rohsing2/testfilebeat/filebeat-5.6.1-linux-x86\_64/prospectors/audit-filebeat.yml')

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 21, 2017, 6:14pm UTC](https://discuss.elastic.co/t/env-variables-in-not-working-in-custom-fields-in-filebeat/101374/2 "2017-09-21T18:14:19Z")

</div>

Can you please be more detailed in describing how you have things setup and what commands you are running. Based on what you have described, I was not able to reproduce the issue. See below.

```auto
# cat /etc/redhat-release 
CentOS Linux release 7.2.1511 (Core)

# rpm -qa | grep filebeat
filebeat-5.6.1-1.x86_64

# env | grep CLUSTER_NAME
CLUSTER_NAME=lokitest

# cat /etc/filebeat/filebeat.yml
filebeat.prospectors:
- paths: ['/var/log/messages']
  fields:
    clustername: ${CLUSTER_NAME}

output.console.enabled: true

# filebeat.sh 
{"@timestamp":"2017-09-21T18:10:25.298Z","beat":{"hostname":"beat","name":"beat","version":"5.6.1"},"fields":{"clustername":"lokitest"},"input_type":"log","message":"Sep 21 18:09:19 beat systemd: Removed slice user-0.slice.","offset":54426,"source":"/var/log/messages","type":"log"}

```

---

<div class="post-metadata">

**Author:** ![Rohit\_Singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohit_singh/32/46630_2.png) [@Rohit\_Singh](https://discuss.elastic.co/u/Rohit_Singh)\
**Post date:** [September 22, 2017, 6:06am UTC](https://discuss.elastic.co/t/env-variables-in-not-working-in-custom-fields-in-filebeat/101374/3 "2017-09-22T06:06:21Z")

</div>

Thanks, I am getting the same error, I am using LINUX 64-BIT 5.6.1 version for filebeat,

I have followed the same steps as above following is the output

```
 #cat /etc/redhat-release
     CentOS Linux release 7.3.1611 (Core)
#env | grep CLUSTER_NAME
     CLUSTER_NAME=lokitest
#cat filebeat.yml
filebeat.prospectors:
- paths: ['/var/log/messages']
  fields:
    clustername: ${CLUSTER_NAME}

output.console.enabled: true

#command
# sudo ./filebeat -v -c filebeat.yml
Exiting: error loading states for prospector 2639214862234946428: missing field accessing 
'filebeat.prospectors.0.fields.clustername' (source:'filebeat.yml')
```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 22, 2017, 1:24pm UTC](https://discuss.elastic.co/t/env-variables-in-not-working-in-custom-fields-in-filebeat/101374/4 "2017-09-22T13:24:40Z")

</div>

> [@Rohit\_Singh](#):
>
> I have followed the same steps as above following is the output

It's not the same. You used `sudo` which does not preserve the environment for security purposes.

When you get to the point of running Filebeat as a service you will be using systemd. When a service starts it receives a clean environment (just like when you used sudo). For systemd you need to configure an override file with the environment data for the service. You can let systemd create the override file for you by running:

`systemctl edit filebeat.service`

Then configure the overrides for the service.

```auto
[Service]
Environment=CLUSTER_NAME=lokitest

```

You can use `EnvironmentFile=` if you want to point to a file with the environment variables.

---

<div class="post-metadata">

**Author:** ![Rohit\_Singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohit_singh/32/46630_2.png) [@Rohit\_Singh](https://discuss.elastic.co/u/Rohit_Singh)\
**Post date:** [September 26, 2017, 9:58am UTC](https://discuss.elastic.co/t/env-variables-in-not-working-in-custom-fields-in-filebeat/101374/5 "2017-09-26T09:58:28Z")

</div>

Thanks Andrew, for nice explanation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 24, 2017, 9:58am UTC](https://discuss.elastic.co/t/env-variables-in-not-working-in-custom-fields-in-filebeat/101374/6 "2017-10-24T09:58:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
