# Filebeat not sending fileset meta data to logstash

**URL:** https://discuss.elastic.co/t/filebeat-not-sending-fileset-meta-data-to-logstash/201466
**Category:** Beats
**Tags:** filebeat
**Created:** [September 27, 2019, 8:55pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-fileset-meta-data-to-logstash/201466 "2019-09-27T20:55:54Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![562uned](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/562uned/32/59775_2.png) [@562uned](https://discuss.elastic.co/u/562uned)
#### Post date: [September 27, 2019, 8:55pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-fileset-meta-data-to-logstash/201466/1 "2019-09-27T20:55:54Z")

</div>

Hey guys,

New to ELK and trying to get this working. I have successfully installed 6.8.3, and it worked i was getting the correct fields from filebeat including the fileset.module information. but i ended up upgrading to 7.3.2 and now im unable to get this data from filebeat, its just hitting logstash and going to elasticsearch as syslog data (completely bypassing the stock filter since its not showing the fileset.module field)

I've been beating my head on this and have completely wiped out all the instances of filebeat, recreated, tried removing and re creating templates, etc. nothing seems to be changing out this data is being sent. I have another filter that is working file (for a fortinet firewall) it seems that all of my issues are specifically because filebeat isnt sending the correct metadata. is there somewhere to enable or disable this??

Thanks!

---

<div class="post-metadata">

### Author: ![MarianaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marianad/32/42687_2.png) [@MarianaD](https://discuss.elastic.co/u/MarianaD)
#### Post date: [September 30, 2019, 11:54am UTC](https://discuss.elastic.co/t/filebeat-not-sending-fileset-meta-data-to-logstash/201466/2 "2019-09-30T11:54:51Z")

</div>

hi @562uned, the `fileset` object has been removed starting v7.0 it seems, you can have a further look here [https://github.com/elastic/beats/pull/8879](https://github.com/elastic/beats/pull/8879) and [https://www.elastic.co/guide/en/beats/libbeat/current/release-notes-7.0.0.html](https://www.elastic.co/guide/en/beats/libbeat/current/release-notes-7.0.0.html)). Can you try to find the event.module and event.dataset properties instead?

---

<div class="post-metadata">

### Author: ![562uned](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/562uned/32/59775_2.png) [@562uned](https://discuss.elastic.co/u/562uned)
#### Post date: [September 30, 2019, 4:34pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-fileset-meta-data-to-logstash/201466/3 "2019-09-30T16:34:44Z")

</div>

That was what i was thinking... but then i found the official documentation still uses this in the 7.3 logstash pipeline guide..  
[https://www.elastic.co/guide/en/logstash/current/logstash-config-for-filebeat-modules.html](https://www.elastic.co/guide/en/logstash/current/logstash-config-for-filebeat-modules.html)  
Guess that got missed on the update..

Thanks for the help! at least i know im not going crazy now!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 28, 2019, 4:34pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-fileset-meta-data-to-logstash/201466/4 "2019-10-28T16:34:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
