# Filebeat 7.2's osquery module not respecting var.use\_namespace: false

**URL:** <https://discuss.elastic.co/t/filebeat-7-2s-osquery-module-not-respecting-var-use-namespace-false/191465>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 20, 2019, 5:06am UTC](https://discuss.elastic.co/t/filebeat-7-2s-osquery-module-not-respecting-var-use-namespace-false/191465 "2019-07-20T05:06:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![DPattee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dpattee/32/37772_2.png) [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Post date:** [July 20, 2019, 5:06am UTC](https://discuss.elastic.co/t/filebeat-7-2s-osquery-module-not-respecting-var-use-namespace-false/191465/1 "2019-07-20T05:06:58Z")

</div>

The documentation at [Osquery module | Filebeat Reference [8.11] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-osquery.html) says:

> **`var.use_namespace`**
> 
> If true, all fields exported by this module are prefixed with `osquery.result` . Set to false to copy the fields in the root of the document. If enabled, this setting also disables the renaming of some fields (e.g. `hostIdentifier` to `host_identifier` ). Note that if you set this to false, the sample dashboards coming with this module won’t work correctly. The default is true.

So I'd expect a config of:

```
- module: osquery
  result:
    enabled: true
    var.use_namespace: false

```

to change the messages I receive. But there is no difference whether that line says true, false, or is deleted so the true default is used.

The documents still are in the form:

```
{
  "_index": "filebeattest6",
  [...],
    "osquery": {
      "result": {
        "columns": {
          "max_rpm": "1836",
          "target_rpm": "790",
          "name": "Main ",
          "min_rpm": "790",
          "actual_rpm": "789",
          "fan_id": "0"
        },

```

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [July 25, 2019, 6:41pm UTC](https://discuss.elastic.co/t/filebeat-7-2s-osquery-module-not-respecting-var-use-namespace-false/191465/2 "2019-07-25T18:41:17Z")

</div>

Hello @DPattee

You after you set that variable you have to reinstall the pipelines, because the conditional is baked at install time.

```auto
./filebeat setup --piplines --modules osquery

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2019, 6:41pm UTC](https://discuss.elastic.co/t/filebeat-7-2s-osquery-module-not-respecting-var-use-namespace-false/191465/3 "2019-08-22T18:41:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
