# Filebeat fields value unable to use it in logstash configuration file

**URL:** <https://discuss.elastic.co/t/filebeat-fields-value-unable-to-use-it-in-logstash-configuration-file/260614>\
**Category:** Logstash\
**Created:** [January 9, 2021, 4:38pm UTC](https://discuss.elastic.co/t/filebeat-fields-value-unable-to-use-it-in-logstash-configuration-file/260614 "2021-01-09T16:38:37Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![navin1093](https://avatars.discourse-cdn.com/v4/letter/n/e47c2d/32.png) [@navin1093](https://discuss.elastic.co/u/navin1093)\
**Post date:** [January 9, 2021, 4:38pm UTC](https://discuss.elastic.co/t/filebeat-fields-value-unable-to-use-it-in-logstash-configuration-file/260614/1 "2021-01-09T16:38:37Z")

</div>

I have set custom name in filebeat input section. However, in logstash configuration file it was unable to be use

Filebeat config file

```auto
- type: log

  enabled: true

  paths:
  ...
  fields:
    - name_of_index: group-1
    - name_of_log: apache

```

Logstash.conf

```auto
input {
  beats {
    port => 5044
    ...
    type => "%{[field][name_of_log]}"
  }
}

filter {
  if "%{[field][name_of_log]}" in ["apache"] {
    ...
  }
}

output {
  elasticsearch {
    hosts => ["localhost:9200"]
    index => "%{[fields][name_of_index]}-%{+YYYY-MM-dd}" 
  }
}

```

output in elasticsearch

```auto
%[fields][name_of_index]-2020-01-05

```

I not sure which parr it is wrong able to help in this?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 9, 2021, 5:25pm UTC](https://discuss.elastic.co/t/filebeat-fields-value-unable-to-use-it-in-logstash-configuration-file/260614/2 "2021-01-09T17:25:11Z")

</div>

looks like you have typos...

In filebeat no `-` See [Here](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-general-options.html#libbeat-configuration-fields)

```auto
  fields:
    name_of_index: group-1
    name_of_log: apache

```

The fields are under `fields` several places you only have the term `field` no `s`.  
Also you could probably simplify perhaps look [here](https://www.elastic.co/guide/en/logstash/current/config-examples.html).

```auto
input {
  beats {
    port => 5044
    ...
    type => "%{[fields][name_of_log]}"
  }
}

filter {
  if [type] == "apache" {
    ...
  }
}

output {
  elasticsearch {
    hosts => ["localhost:9200"]
    index => "%{[fields][name_of_index]}-%{+YYYY-MM-dd}" 
  }
}

```

---

<div class="post-metadata">

**Author:** ![navin1093](https://avatars.discourse-cdn.com/v4/letter/n/e47c2d/32.png) [@navin1093](https://discuss.elastic.co/u/navin1093)\
**Post date:** [January 10, 2021, 2:57am UTC](https://discuss.elastic.co/t/filebeat-fields-value-unable-to-use-it-in-logstash-configuration-file/260614/3 "2021-01-10T02:57:03Z")

</div>

hi can i know if i use type, it means table name right?

another thing would like to know whyc below not combining the idnex rather it giving 2 seperate sets of index?

```auto
- type: log

  enabled: true

  paths: /var/log/apache
  ...
  fields:
    - name_of_index: group-1
    - name_of_log: apache

- type: log

  enabled: true

  paths: /var/log/message
  ...
  fields:
    - name_of_index: group-1
    - name_of_log: message

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 10, 2021, 3:10am UTC](https://discuss.elastic.co/t/filebeat-fields-value-unable-to-use-it-in-logstash-configuration-file/260614/4 "2021-01-10T03:10:09Z")

</div>

No type means in the input type see [here](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#filebeat-input-types) It is not the index name or type in this case it is `log` which means reading a [log](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-log.html) file

I would suggest perhaps referring to the documentation

---

<div class="post-metadata">

**Author:** ![navin1093](https://avatars.discourse-cdn.com/v4/letter/n/e47c2d/32.png) [@navin1093](https://discuss.elastic.co/u/navin1093)\
**Post date:** [January 10, 2021, 10:05am UTC](https://discuss.elastic.co/t/filebeat-fields-value-unable-to-use-it-in-logstash-configuration-file/260614/5 "2021-01-10T10:05:47Z")

</div>

thanks

---

<div class="post-metadata">

**Author:** ![navin1093](https://avatars.discourse-cdn.com/v4/letter/n/e47c2d/32.png) [@navin1093](https://discuss.elastic.co/u/navin1093)\
**Post date:** [January 10, 2021, 12:48pm UTC](https://discuss.elastic.co/t/filebeat-fields-value-unable-to-use-it-in-logstash-configuration-file/260614/6 "2021-01-10T12:48:29Z")

</div>

Hi i check in logstash input

```auto
type => "%{[fields][name_of_log]}"

```

it is printing the string rather than the value in the output section. so in output it is showing as

```auto
 "type" : "%{[fields][name_of_log]}".

```

why there are such behaviour

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 10, 2021, 4:48pm UTC](https://discuss.elastic.co/t/filebeat-fields-value-unable-to-use-it-in-logstash-configuration-file/260614/7 "2021-01-10T16:48:54Z")

</div>

Apologies I was cut and pasting...

At the input you does not appear have access to the fields yet so you can only set static values. (My bad I will need to look closer at that)

So to accomplish what I think you want you would do this..

```auto
input {
  beats {
    port => 5044
  }
}

filter {
  if [fields][name_of_log] == "apache" {
    ...
  } else if [fields][name_of_log] == "nginx" {
   ...
  } else {
    ...
  }

}

output {
  elasticsearch {
    hosts => ["localhost:9200"]
    index => "%{[fields][name_of_index]}-%{+YYYY-MM-dd}" 
  }
}

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 10, 2021, 5:32pm UTC](https://discuss.elastic.co/t/filebeat-fields-value-unable-to-use-it-in-logstash-configuration-file/260614/8 "2021-01-10T17:32:17Z")

</div>

You could also do it like this which might be a little cleaner

```auto
input {
  beats {
    port => 5044
  }
}

filter {

   mutate { 
        add_field => { "type" => "%{[fields][name_of_log]]}" }
    }

  if [type] == "apache" {
    ...
  } else if [type] == "nginx" {
   ...
  } else {
    ...
  }

}

output {
  elasticsearch {
    hosts => ["localhost:9200"]
    index => "%{[fields][name_of_index]}-%{+YYYY-MM-dd}" 
  }
}

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 10, 2021, 11:20pm UTC](https://discuss.elastic.co/t/filebeat-fields-value-unable-to-use-it-in-logstash-configuration-file/260614/9 "2021-01-10T23:20:24Z")

</div>

I see you opened another [thread](https://discuss.elastic.co/t/set-type-in-logstash/260643) ...

Hi @navin1093 I did not realize you were trying to set `_type` as the poster stated that is not longer supported if you just want to set a normal field named `type` you can still do that, but it is just like any other field.

In reality, with the removal of types ( `"_type" : "_doc" ` _ **always** _ ) , You should think of an index as a table not a database...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2021, 11:20pm UTC](https://discuss.elastic.co/t/filebeat-fields-value-unable-to-use-it-in-logstash-configuration-file/260614/10 "2021-02-07T23:20:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
