# Filebeat is sending additional fields

**URL:** <https://discuss.elastic.co/t/filebeat-is-sending-additional-fields/145672>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 23, 2018, 7:33am UTC](https://discuss.elastic.co/t/filebeat-is-sending-additional-fields/145672 "2018-08-23T07:33:24Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jyothi\_Balla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jyothi_balla/32/34739_2.png) [@Jyothi\_Balla](https://discuss.elastic.co/u/Jyothi_Balla)\
**Post date:** [August 23, 2018, 7:33am UTC](https://discuss.elastic.co/t/filebeat-is-sending-additional-fields/145672/1 "2018-08-23T07:33:24Z")

</div>

```
I have a filebeat configured to send the logs to the kafka then to the logstash->elasticsearch->kibana

```

the filebeat is sending the message as follows:  
"@timestamp": "2018-08-23T07:22:11.390Z",  
"@metadata": {  
"beat": "filebeat",  
"type": "doc",  
"version": "6.2.1"  
},  
"prospector": {  
"type": "log"  
},  
"beat": {  
"version": "6.2.1",  
"name": "perf.manager-16.202.68.51",  
"hostname": "perf.manager-16.202.68.51"  
},  
"source": "/opt/filebeat-log/app1.log",  
"offset": 23,  
"message": "wthb"  
}  
in the kafka it is:  
{"@timestamp":"2018-08-23T07:22:11.390Z","@metadata":{"beat":"filebeat","type":"doc","version":"6.2.1","topic":"test"},"source":"/opt/filebeat-log/app1.log","offset":38,"message":"kvnsfk;v m;ggb","prospector":{"type":"log"},"beat":{"name":"perf.manager-16.202.68.51","hostname":"perf.manager-16.202.68.51","version":"6.2.1"}}

in the kibana:  
t message {"@timestamp":"2018-08-23T07:22:11.389Z","@metadata":{"beat":"filebeat","type":"doc","version":"6.2.1","topic":"test"},"message":"dfvlm","prospector":{"type":"log"},"beat":{"hostname":"perf.manager-16.202.68.51","version":"6.2.1","name":"perf.manager-16.202.68.51"},"source":"/opt/filebeat-log/app1.log","offset":10}

The ask here is i just want the content of the message "message":"dfvlm" to be put into the kibana message field

can someone please help me here?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [August 23, 2018, 3:58pm UTC](https://discuss.elastic.co/t/filebeat-is-sending-additional-fields/145672/2 "2018-08-23T15:58:04Z")

</div>

Hello @Jyothi_Balla are you using Logstash between kafka and Elasticsearch?

---

<div class="post-metadata">

**Author:** ![Jyothi\_Balla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jyothi_balla/32/34739_2.png) [@Jyothi\_Balla](https://discuss.elastic.co/u/Jyothi_Balla)\
**Post date:** [August 23, 2018, 4:09pm UTC](https://discuss.elastic.co/t/filebeat-is-sending-additional-fields/145672/3 "2018-08-23T16:09:41Z")

</div>

Yes there is logstash between Kafka and elasticsearch

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 27, 2018, 1:50pm UTC](https://discuss.elastic.co/t/filebeat-is-sending-additional-fields/145672/4 "2018-08-27T13:50:34Z")

</div>

In filebeat you can drop a few fields (you can't drop at least `@timestamp` and `@metadata`) using the `drop_fields` processor. In logstash you can drop some more fields.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 24, 2018, 1:50pm UTC](https://discuss.elastic.co/t/filebeat-is-sending-additional-fields/145672/5 "2018-09-24T13:50:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
