# How do I add AWS metadata to Filebeat?

**URL:** <https://discuss.elastic.co/t/how-do-i-add-aws-metadata-to-filebeat/71505>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 13, 2017, 10:13am UTC](https://discuss.elastic.co/t/how-do-i-add-aws-metadata-to-filebeat/71505 "2017-01-13T10:13:32Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tachyon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tachyon/32/14544_2.png) [@tachyon](https://discuss.elastic.co/u/tachyon)\
**Post date:** [January 13, 2017, 10:13am UTC](https://discuss.elastic.co/t/how-do-i-add-aws-metadata-to-filebeat/71505/1 "2017-01-13T10:13:32Z")

</div>

I want to include AWS Instance's tag information in each Filebeat document. I can think of two ways to do this -

1. Modify the log output and include the info in there. This will require tweaking all the services whose log files are being tracked.
2. Run a script at launch that

- modifies the `filebeat.yml` file
- pulls AWS metadata for that instance
- and adds the tag info to `yml` file

It sounds like method `2` is the right approach.  
Is there a better way to do this? Does Filebeat provide a way to dynamically set prospector attributes?

---

<div class="post-metadata">

**Author:** ![maddin2016](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maddin2016/32/16599_2.png) [@maddin2016](https://discuss.elastic.co/u/maddin2016)\
**Post date:** [January 13, 2017, 12:38pm UTC](https://discuss.elastic.co/t/how-do-i-add-aws-metadata-to-filebeat/71505/2 "2017-01-13T12:38:37Z")

</div>

You can also use environment variables. See [here](https://www.elastic.co/guide/en/beats/filebeat/current/using-environ-vars.html) for more infos.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 13, 2017, 12:59pm UTC](https://discuss.elastic.co/t/how-do-i-add-aws-metadata-to-filebeat/71505/3 "2017-01-13T12:59:21Z")

</div>

You just need to add this to your config file if you want instance\_id. For other information you could use environment variables.

```auto
processors:
- add_cloud_metadata:

```

See the [add\_cloud\_metadata](https://www.elastic.co/guide/en/beats/filebeat/current/add-cloud-metadata.html) documentation for more details.

---

<div class="post-metadata">

**Author:** ![tachyon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tachyon/32/14544_2.png) [@tachyon](https://discuss.elastic.co/u/tachyon)\
**Post date:** [January 17, 2017, 5:49am UTC](https://discuss.elastic.co/t/how-do-i-add-aws-metadata-to-filebeat/71505/4 "2017-01-17T05:49:20Z")

</div>

Thanks. This helps.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2017, 5:49am UTC](https://discuss.elastic.co/t/how-do-i-add-aws-metadata-to-filebeat/71505/5 "2017-02-14T05:49:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
