I am using latest (6.7) ES, Kibana, and Filebeat.
The grok patterns in pipeline.json for http log format contain
and my log files seem to match OK, but this field is not being logged into my ES? is this intended? I see the field as searchable string field in filebeat-* index-patterns.
I am running filebeat on saved log files piping straight into ES, no logstash.
I have many haproxy instances and it's important to be able to distinguish them somehow in visualisations.