# Filebeat module's fields in SIEM columns

**URL:** <https://discuss.elastic.co/t/filebeat-modules-fields-in-siem-columns/266090>\
**Category:** SIEM\
**Created:** [March 3, 2021, 11:00am UTC](https://discuss.elastic.co/t/filebeat-modules-fields-in-siem-columns/266090 "2021-03-03T11:00:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![radovan](https://avatars.discourse-cdn.com/v4/letter/r/2acd7d/32.png) [@radovan](https://discuss.elastic.co/u/radovan)\
**Post date:** [March 3, 2021, 11:00am UTC](https://discuss.elastic.co/t/filebeat-modules-fields-in-siem-columns/266090/1 "2021-03-03T11:00:58Z")

</div>

Hi,

after upgrading our cluster from 7.10.2 to 7.11.1 we can no more see values of filebeat module's fields in columns, for example suricata's fields (screenshot below),

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/7/77a24e96a4c4c5f2d938da50aada6a11bc3e25c9.png)

although they are included in the signal's fields.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/c/4ce37aee6b539fbf747abde2709100482142f400.png)

Suricata module is parsed through logstash ingest pipeline and the pipeline and filebeat on the host are upgraded to the latest version. In the suricata index, suricata fields have their appropriate mappings, but the situation is not the same in the signals index, as you can see on the picture above, where suricata fields have question mark instead of field type.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/a/2a9d227a5324a4103cdc5d68f36202abbf277250.png)

What should I do to acquire the same mapping, or something else, that would lead to previous behaviour before upgrade, where I could normally see the fields' values in the columns for non-directly ECS fields?

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [March 5, 2021, 7:42pm UTC](https://discuss.elastic.co/t/filebeat-modules-fields-in-siem-columns/266090/2 "2021-03-05T19:42:34Z")

</div>

We have an issue for it you can watch here. Un-indexed fields aren't being shown in the columns:

> <https://github.com/elastic/kibana/issues/91424>
>
> Describe the bug:
> In timeline when you have an unindexed field after creating an alert and you select it in the details...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 2, 2021, 7:43pm UTC](https://discuss.elastic.co/t/filebeat-modules-fields-in-siem-columns/266090/3 "2021-04-02T19:43:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
