# Filebeat nginx include custom log field

**URL:** <https://discuss.elastic.co/t/filebeat-nginx-include-custom-log-field/206172>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 1, 2019, 1:25pm UTC](https://discuss.elastic.co/t/filebeat-nginx-include-custom-log-field/206172 "2019-11-01T13:25:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![George\_Jetson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/george_jetson/32/29663_2.png) [@George\_Jetson](https://discuss.elastic.co/u/George_Jetson)\
**Post date:** [November 1, 2019, 1:25pm UTC](https://discuss.elastic.co/t/filebeat-nginx-include-custom-log-field/206172/1 "2019-11-01T13:25:09Z")

</div>

Nginx: Running latest nginx on Ubuntu. We have added some custom fields to the access log (e.g. server\_name).

Filebeat: Just setup 7.4.1 and trying to use the filebeat nginx module to send the log files to our version 7.4.1 ELK. I have it all setup and it is working - kibana dashboard and all. However I do not know how to include the custom log fields?

How can I tweak the filebeat.yml to include the custom log field "server\_name" above?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [November 1, 2019, 2:26pm UTC](https://discuss.elastic.co/t/filebeat-nginx-include-custom-log-field/206172/2 "2019-11-01T14:26:16Z")

</div>

I think the new field should be in the message now, it's just not extracted. You could tcpdump some sample traffic to verify.

Look at the elasticsearch ingest pipelines that were loaded by the nginx module. I think you just add your new field to the grok patterns and add any additional processing you might need.

You can remove the

> "remove": { "field": "message" } }

while you are developing the change so the entire message field will be kept, I've found that handy at times.

---

<div class="post-metadata">

**Author:** ![George\_Jetson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/george_jetson/32/29663_2.png) [@George\_Jetson](https://discuss.elastic.co/u/George_Jetson)\
**Post date:** [November 1, 2019, 4:21pm UTC](https://discuss.elastic.co/t/filebeat-nginx-include-custom-log-field/206172/3 "2019-11-01T16:21:51Z")

</div>

Great, got it, thanks for the reply!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2019, 4:21pm UTC](https://discuss.elastic.co/t/filebeat-nginx-include-custom-log-field/206172/4 "2019-11-29T16:21:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
