Hi,
I've noticed filebeat sends some additional metadata for each generated event such as: log.file.path and process.name.
I can access to log.file.path ([log][file][path]) but not to process.name ([process][name]). ??
{
"_index": "filebeat-7.4.0-2019.10.29-000006",
"_type": "_doc",
"_id": "LUdQN24BFAd3xpeubZvm",
"_version": 1,
"_score": null,
"_source": {
"agent": {
"hostname": "http2",
"id": "9ceb38e6-9835-4fd8-9eb0-d741449fbd6b",
"type": "filebeat",
"ephemeral_id": "6edd52a2-a706-4a89-87b1-8a0fb6ce6c12",
"version": "7.4.0"
},
"process": {
"name": "(squid-1)"
},
"log": {
"file": {
"path": "/var/log/messages"
},
"offset": 1333266097
},
"fileset": {
"name": "syslog"
},
"message": "11.12.28.183 - - [04/Nov/2019:17:47:02 +0100] \"CONNECT autodi.fr:443 HTTP/1.1\" 407 3728 101 \"-\" \"-\" TCP_DENIED:HIER_NONE",
"input": {
"type": "log"
},
"@timestamp": "2019-11-04T17:47:02.000+01:00",
"system": {
"syslog": {}
},
"ecs": {
"version": "1.1.0"
},
"service": {
"type": "system"
},
"host": {
"hostname": "http1323",
"os": {
"kernel": "3",
"codename": "Core",
"name": "CentOS Linux",
"family": "redhat",
"version": "7 (Core)",
"platform": "centos"
},
"containerized": false,
"name": "http2",
"id": "a8a5cf55a7ad46e8a2e6ab26a32e8571",
"architecture": "x86_64"
},
"event": {
"timezone": "+01:00",
"module": "system",
"dataset": "system.syslog"
}
},
"fields": {
"suricata.eve.timestamp": [
"2019-11-04T16:47:02.000Z"
],
"@timestamp": [
"2019-11-04T16:47:02.000Z"
]
},
"highlight": {
"process.name": [
"@kibana-highlighted-field@(squid-1)@/kibana-highlighted-field@"
]
},
"sort": [
1572886022000
]
}
Thank you,