# Exception: Key 'my\_field' found in event is not documented!

**URL:** <https://discuss.elastic.co/t/exception-key-my-field-found-in-event-is-not-documented/216902>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 28, 2020, 6:57pm UTC](https://discuss.elastic.co/t/exception-key-my-field-found-in-event-is-not-documented/216902 "2020-01-28T18:57:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jim\_Ivey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jim_ivey/32/60991_2.png) [@Jim\_Ivey](https://discuss.elastic.co/u/Jim_Ivey)\
**Post date:** [January 28, 2020, 6:57pm UTC](https://discuss.elastic.co/t/exception-key-my-field-found-in-event-is-not-documented/216902/1 "2020-01-28T18:57:02Z")

</div>

I'm getting this error in testing my module: `Exception: Key 'my_field' found in event is not documented!`

Mr. Google only finds discussion in github about PRs related to this. I don't know what this error means.

Here's an excerpt from `filebeat/module/my_module/_meta/fields.xml`:

```auto
- key: my_module
  title: "Jim's new module"
  description: >
    This is the module Jim is trying to create.
  fields:
    - name: my_fileset
      type: group
      fields:
        - name: my_field
          description: Please add description
          example: Please add example
          type: text
...

```

In addition, I have this in `filebeat/module/my_module/my_fileset/_meta/fields.xml`:

```auto
- name: my_fileset
  description: >
    This is a fileset in Jim's fancy new module.
  example: Please add example
  type: group
  fields:
  - name: my_field
    description: Please add description
    example: Please add example
    type: text
...

```

Shouldn't that be enough to document the field?

For context, I'm testing just this module in the manner described here: [Debugging test.log-expected.json](https://discuss.elastic.co/t/debugging-test-log-expected-json/216738)

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [January 29, 2020, 9:43am UTC](https://discuss.elastic.co/t/exception-key-my-field-found-in-event-is-not-documented/216902/2 "2020-01-29T09:43:37Z")

</div>

Hi @Jim_Ivey!

Most probably you need to run a `make update` command inside filebeat folder. This collects all the fields from the different modules and creates a final `fields.yml` in which tests are looking for the under-test fields. Let me know if this helps.

C.

---

<div class="post-metadata">

**Author:** ![Jim\_Ivey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jim_ivey/32/60991_2.png) [@Jim\_Ivey](https://discuss.elastic.co/u/Jim_Ivey)\
**Post date:** [January 29, 2020, 4:48pm UTC](https://discuss.elastic.co/t/exception-key-my-field-found-in-event-is-not-documented/216902/3 "2020-01-29T16:48:56Z")

</div>

Thanks. I've run `make update` and verified that these fields are in `filebeat/fields.yml` as well as `filebeat/module/my_module/fileset/_meta/fields.yml`. It's not in `filebeat/module/my_module/_meta/fields.yml`. It was there, but that led to duplicate declarations in `filebeat/fields.yml`.

Given that the field is already declared in the places you suggest, I'll assume it's a bug and see if I can fix it. Thanks!

---

<div class="post-metadata">

**Author:** ![Jim\_Ivey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jim_ivey/32/60991_2.png) [@Jim\_Ivey](https://discuss.elastic.co/u/Jim_Ivey)\
**Post date:** [January 29, 2020, 6:09pm UTC](https://discuss.elastic.co/t/exception-key-my-field-found-in-event-is-not-documented/216902/4 "2020-01-29T18:09:49Z")

</div>

I figured it out. My `ingest/pipeline.json` and `test/test.log-expected.json` referred to the fields without the `my_module.my_fileset.` prefix.

Honestly, I still don't completely understand where the module/fileset prefix is needed and where it's inferred. I was looking at the apache module as an example and they seem to prefix only some fields. I don't know why.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2020, 6:24pm UTC](https://discuss.elastic.co/t/exception-key-my-field-found-in-event-is-not-documented/216902/5 "2020-02-26T18:24:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
