# How do I add a Custom Field to FileBeat with a Module?

**URL:** <https://discuss.elastic.co/t/how-do-i-add-a-custom-field-to-filebeat-with-a-module/257909>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 7, 2020, 8:54pm UTC](https://discuss.elastic.co/t/how-do-i-add-a-custom-field-to-filebeat-with-a-module/257909 "2020-12-07T20:54:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mstacy](https://avatars.discourse-cdn.com/v4/letter/m/b4bc9f/32.png) [@mstacy](https://discuss.elastic.co/u/mstacy)\
**Post date:** [December 7, 2020, 8:54pm UTC](https://discuss.elastic.co/t/how-do-i-add-a-custom-field-to-filebeat-with-a-module/257909/1 "2020-12-07T20:54:50Z")

</div>

Below is the top portion of my filebeat yaml.

This configuration works adequately.  
However I would like to append additional data to the events in order to better distinguish the source of the logs.  
I have gone through all the documentation regarding "field" and "add\_fields" and "processors" and "filebeat.inputs:" I cannot seem to get the custom meta data to appear in the logs when I view them in Kibana.  
Below is my regular yaml without any custom fields.  
I would like to be able to add something like:

```
 processors:
  - add_fields:
    target: ''
    fields:
      Customer: Customer123
    fields_under_root: true

```

Or

```
 filebeat.inputs:
- type: log
  fields:
    Customer: Customer123
  fields_under_root: true

```

Is it possible to append additional custom fields to logs while also using a module?  
If so how would I configure my yaml to do that?

_ **CURRENT YAML** _

```auto
---
apiVersion: v1
kind: ConfigMap
metadata:
  name: XXXXXXXXXXXXX
  namespace: XXXXXXXXXXX
  labels:
    k8s-app: filebeat
data:
  filebeat.yml: |-
    filebeat.modules:
    - module: okta
      system:
        var.url: https://XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
        var.api_key: 'XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX'
      
    output.elasticsearch:
      hosts: ['https://${ELASTICSEARCH_HOST:elasticsearch}:${ELASTICSEARCH_PORT:9200}']
      username: ${ELASTICSEARCH_USERNAME}
      password: ${ELASTICSEARCH_PASSWORD}
      ssl.certificate_authorities:
      - /mnt/elastic/tls.crt`

```

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [December 8, 2020, 6:34pm UTC](https://discuss.elastic.co/t/how-do-i-add-a-custom-field-to-filebeat-with-a-module/257909/2 "2020-12-08T18:34:23Z")

</div>

Hey @mstacy,

Something like the configuration for processors you tried should work, but take into account that indentation is important, settings of `add_field` should have one more indentation level.

Something like this should work:

```auto
---
apiVersion: v1
kind: ConfigMap
metadata:
  name: XXXXXXXXXXXXX
  namespace: XXXXXXXXXXX
  labels:
    k8s-app: filebeat
data:
  filebeat.yml: |-
    filebeat.modules:
    - module: okta
      system:
        var.url: https://XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
        var.api_key: 'XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX'

    processors:
    - add_fields:
        target: ''
        fields:
          Customer: Customer123

    output.elasticsearch:
      hosts: ['https://${ELASTICSEARCH_HOST:elasticsearch}:${ELASTICSEARCH_PORT:9200}']
      username: ${ELASTICSEARCH_USERNAME}
      password: ${ELASTICSEARCH_PASSWORD}
      ssl.certificate_authorities:
      - /mnt/elastic/tls.crt`

```

If this doesn't work, could you check for any error in filebeat logs?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 5, 2021, 8:34pm UTC](https://discuss.elastic.co/t/how-do-i-add-a-custom-field-to-filebeat-with-a-module/257909/3 "2021-01-05T20:34:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
