# FIlebeat Input Type

**URL:** <https://discuss.elastic.co/t/filebeat-input-type/146674>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 30, 2018, 10:22am UTC](https://discuss.elastic.co/t/filebeat-input-type/146674 "2018-08-30T10:22:53Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Post date:** [August 30, 2018, 10:22am UTC](https://discuss.elastic.co/t/filebeat-input-type/146674/1 "2018-08-30T10:22:53Z")

</div>

Could be a stupid question, can we manipulate the input type in the filebeat.yml to be whatever string we want?

I want to uniquely identify logs that come from this server (without having to create a separate index for them or using a normaliser to add a field)

For example - LinuxLogTest as shown below:

```
filebeat.inputs:
- type: LinuxLogTest
  paths:
    - /var/log/messages
    - /var/log/secure
```

---

<div class="post-metadata">

**Author:** ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Post date:** [August 30, 2018, 10:30am UTC](https://discuss.elastic.co/t/filebeat-input-type/146674/2 "2018-08-30T10:30:22Z")

</div>

Example Log:

```
{
  "beat": {
    "ip": "10.0.0.0",
    "version": "6.4.0",
    "hostname": "ip-10.0.0.0",
    "name": "Test"
  },
  "@version": "1",
  "message": "Aug 30 09:02:48 ip-10.0.0.0 dhclient[691]: bound to 172.0.0.0 -- renewal in 1414 seconds.",
  "@timestamp": "2018-08-30T09:02:49.881Z",
  "host": {
    "name": "Test"
  },
  "source": "\/var\/log\/messages",
  "offset": 50334,
  "tags": [
    "beats_input_codec_plain_applied"
  ],
  "input": {
    "type": "log"
  },
  "prospector": {
    "type": "log"
  }
}

```

I'd like to change the input type, or prospector type, or any field inside that log message to be uniquely identifiable to that machine using that filebeat configuration.

p.s. Using the host as a unique identifier would not work with my use case.

---

<div class="post-metadata">

**Author:** ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Post date:** [August 30, 2018, 11:03am UTC](https://discuss.elastic.co/t/filebeat-input-type/146674/3 "2018-08-30T11:03:15Z")

</div>

Just found the ability to add a tags field, will test now.

```
filebeat.inputs:
- type: log
  . . .
  tags: ["json"]
```

---

<div class="post-metadata">

**Author:** ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Post date:** [August 30, 2018, 11:13am UTC](https://discuss.elastic.co/t/filebeat-input-type/146674/4 "2018-08-30T11:13:57Z")

</div>

Ok that works. Dont know how to close it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2018, 11:14am UTC](https://discuss.elastic.co/t/filebeat-input-type/146674/5 "2018-09-27T11:14:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
