# Filebeat 7.17.6 does not overwrite agent.type and agent.version if they are already present

**URL:** <https://discuss.elastic.co/t/filebeat-7-17-6-does-not-overwrite-agent-type-and-agent-version-if-they-are-already-present/344521>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 6, 2023, 7:18am UTC](https://discuss.elastic.co/t/filebeat-7-17-6-does-not-overwrite-agent-type-and-agent-version-if-they-are-already-present/344521 "2023-10-06T07:18:02Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![andreycha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreycha/32/109183_2.png) [@andreycha](https://discuss.elastic.co/u/andreycha)\
**Post date:** [October 6, 2023, 7:18am UTC](https://discuss.elastic.co/t/filebeat-7-17-6-does-not-overwrite-agent-type-and-agent-version-if-they-are-already-present/344521/1 "2023-10-06T07:18:02Z")

</div>

Hi. We're writing application logs to the files using `Elastic.CommonSchema.Serilog` package and then ship them with Filebeat to Elastic. Here is how `agent` field looks like in log files:

```auto
"agent": {
    "type": "Elastic.CommonSchema.Serilog",
    "version": "8.6.1+88f2bc81a0b7440e4059e323e610bb03df61862c"
}

```

Once log entry is shipped to Elastic, it looks like this:

```auto
"agent": {
  "hostname": "[redacted]",
  "name": "filebeat_C3D",
  "id": "e0c409b0-053f-4911-acf1-486a1734c38c",
  "type": "Elastic.CommonSchema.Serilog",
  "ephemeral_id": "f02c1ec2-ff3c-4e7f-abd2-7c98a5601a58",
  "version": "8.6.1+88f2bc81a0b7440e4059e323e610bb03df61862c"
}

```

So Filebeat does add new subfields including agent.name, but does not overwrite `agent.type` and `agent.version`.

For the log entries written with a different library, where there are no `agent` field in the log files, Filebeat also writes `agent.type` and `agent.version`:

```auto
"agent": {
  "hostname": "[redacted]",
  "name": "filebeat_C3D",
  "id": "ed2bcdea-049b-4db6-99e1-b193bf51fbe6",
  "type": "filebeat",
  "ephemeral_id": "a6fd622d-167a-4242-9ed1-5274b4662714",
  "version": "7.17.6"
}

```

Is it intended behavior? If so, then it leads to inconsistent data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2023, 9:18am UTC](https://discuss.elastic.co/t/filebeat-7-17-6-does-not-overwrite-agent-type-and-agent-version-if-they-are-already-present/344521/2 "2023-11-03T09:18:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
