# Generating filebeat dynamic custom fields

**URL:** https://discuss.elastic.co/t/generating-filebeat-dynamic-custom-fields/46749
**Category:** Beats
**Created:** [April 7, 2016, 9:57pm UTC](https://discuss.elastic.co/t/generating-filebeat-dynamic-custom-fields/46749 "2016-04-07T21:57:05Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Shachar\_Ashkenazi](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@Shachar\_Ashkenazi](https://discuss.elastic.co/u/Shachar_Ashkenazi)
#### Post date: [April 7, 2016, 9:57pm UTC](https://discuss.elastic.co/t/generating-filebeat-dynamic-custom-fields/46749/1 "2016-04-07T21:57:05Z")

</div>

I have an elasticsearch cluster (ELK) and some nodes sending logs to the logstash using filebeat. All the servers in my environment are CentOS 6.5.

The filebeat.yml file in each server is enforced by a Puppet module (both my production and test servers got the same configuration).

I want to have a field in each document which tells if it came from a production/test server.

I wanted to generate a dynamic custom field in every document which indicates the environment (production/test) using filebeat.yml file.

In order to work this out i thought of running a command which returns the environment (it is possible to know the environment throught facter) and add it under an "environment" custom field in the filebeat.yml file but I couldn't find any way of doing so.

Is it possible to run a command throught filebeat.yml ?  
Is there any other way to achieve my goal ?  
Thanks 🙂

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [April 11, 2016, 11:29am UTC](https://discuss.elastic.co/t/generating-filebeat-dynamic-custom-fields/46749/2 "2016-04-11T11:29:19Z")

</div>

with most recent filebeat (1.2 I think) you can use environment variables in your filebeat.yml. Environment variables are replaced in filebeat.yml before being parsed by the yaml parser.

you can try:  
`$ export FB_ENV=test`

and in filebeat:

```auto
fields:
    environment: ${FB_ENV}

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 9:53pm UTC](https://discuss.elastic.co/t/generating-filebeat-dynamic-custom-fields/46749/3 "2017-07-05T21:53:31Z")

</div>


