# Exported fields for log content which module exports them?

**URL:** <https://discuss.elastic.co/t/exported-fields-for-log-content-which-module-exports-them/190717>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 16, 2019, 11:13am UTC](https://discuss.elastic.co/t/exported-fields-for-log-content-which-module-exports-them/190717 "2019-07-16T11:13:26Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![xtruthx](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xtruthx/32/10435_2.png) [@xtruthx](https://discuss.elastic.co/u/xtruthx)\
**Post date:** [July 16, 2019, 11:13am UTC](https://discuss.elastic.co/t/exported-fields-for-log-content-which-module-exports-them/190717/1 "2019-07-16T11:13:26Z")

</div>

Hello,

i am actually using Filebeat in version 7.2.1  
In the description for the exported fields are fields for log content described:  
[https://www.elastic.co/guide/en/beats/filebeat/master/exported-fields-log.html#exported-fields-log](https://www.elastic.co/guide/en/beats/filebeat/master/exported-fields-log.html#exported-fields-log)

But i cant find any ingest pipelines in the filebeat modules or in the code which produces such fields.  
Question is which module produces the fields priority and severity for log files?

---

<div class="post-metadata">

**Author:** ![Michal\_Pristas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michal_pristas/32/46639_2.png) [@Michal\_Pristas](https://discuss.elastic.co/u/Michal_Pristas)\
**Post date:** [July 16, 2019, 2:03pm UTC](https://discuss.elastic.co/t/exported-fields-for-log-content-which-module-exports-them/190717/2 "2019-07-16T14:03:40Z")

</div>

Hey @xtruthx  
Please check this file: [https://github.com/elastic/beats/blob/master/filebeat/\_meta/fields.common.yml](https://github.com/elastic/beats/blob/master/filebeat/_meta/fields.common.yml)

Let me know if that helps

---

<div class="post-metadata">

**Author:** ![xtruthx](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xtruthx/32/10435_2.png) [@xtruthx](https://discuss.elastic.co/u/xtruthx)\
**Post date:** [July 17, 2019, 6:15am UTC](https://discuss.elastic.co/t/exported-fields-for-log-content-which-module-exports-them/190717/3 "2019-07-17T06:15:29Z")

</div>

Hello @Michal_Pristas,

thx for the link to the information. But this is also only a information that they are a common part of filebeat. But it is still not clear when and how this fields will be exported or created. I am not able to produce them.

---

<div class="post-metadata">

**Author:** ![martinr\_ubi](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@martinr\_ubi](https://discuss.elastic.co/u/martinr_ubi)\
**Post date:** [July 17, 2019, 8:27am UTC](https://discuss.elastic.co/t/exported-fields-for-log-content-which-module-exports-them/190717/4 "2019-07-17T08:27:50Z")

</div>

> [@xtruthx](#):
>
> Question is which module produces the fields priority and severity for log files?

The syslog input:

> **[Syslog input | Filebeat Reference \[7.2\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/7.2/filebeat-input-syslog.html)**

When used correctly and when compatible syslog events are sent to it, will generate those fields from the syslog event that filebeat will parse.

---

<div class="post-metadata">

**Author:** ![xtruthx](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xtruthx/32/10435_2.png) [@xtruthx](https://discuss.elastic.co/u/xtruthx)\
**Post date:** [July 17, 2019, 9:07am UTC](https://discuss.elastic.co/t/exported-fields-for-log-content-which-module-exports-them/190717/5 "2019-07-17T09:07:20Z")

</div>

Thx @martinr_ubi that was my missing link. I was to focused on it to find the module which is exporting the fields. My it should be more prominent in the documentation that that fields are linked to the input syslog.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2019, 9:07am UTC](https://discuss.elastic.co/t/exported-fields-for-log-content-which-module-exports-them/190717/6 "2019-08-14T09:07:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
