# Field names not parsing in Auditbeat

**URL:** <https://discuss.elastic.co/t/field-names-not-parsing-in-auditbeat/320914>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [December 9, 2022, 6:12pm UTC](https://discuss.elastic.co/t/field-names-not-parsing-in-auditbeat/320914 "2022-12-09T18:12:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kossde](https://avatars.discourse-cdn.com/v4/letter/k/f19dbf/32.png) [@kossde](https://discuss.elastic.co/u/kossde)\
**Post date:** [December 9, 2022, 6:12pm UTC](https://discuss.elastic.co/t/field-names-not-parsing-in-auditbeat/320914/1 "2022-12-09T18:12:54Z")

</div>

I feel like I'm missing something here. Auditbeat is up and running on an ubunutu server and I'm getting auditd, system, and file integrity logs but some fields referenced by the Elasticsearch prebuilt linux rules aren't getting parsed: file.name is one example.

So, I feel like I'm missing something. Is there any specific additional step that needs to take place to get all of the fields parsed or do I just need to create my own ingest pipeline and parse them manually?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 10, 2022, 2:59am UTC](https://discuss.elastic.co/t/field-names-not-parsing-in-auditbeat/320914/2 "2022-12-10T02:59:05Z")

</div>

Did you run setup first before starting auditbeat per the docs [here](https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-installation-configuration.html#setup-assets)

---

<div class="post-metadata">

**Author:** ![kossde](https://avatars.discourse-cdn.com/v4/letter/k/f19dbf/32.png) [@kossde](https://discuss.elastic.co/u/kossde)\
**Post date:** [December 10, 2022, 3:17am UTC](https://discuss.elastic.co/t/field-names-not-parsing-in-auditbeat/320914/3 "2022-12-10T03:17:56Z")

</div>

I did not. I did, however, run it afterwards and reindex the existing index to comply with the new index template.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 7, 2023, 5:17am UTC](https://discuss.elastic.co/t/field-names-not-parsing-in-auditbeat/320914/4 "2023-01-07T05:17:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
