# How to add field for logs from specific file

**URL:** <https://discuss.elastic.co/t/how-to-add-field-for-logs-from-specific-file/224567>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 22, 2020, 4:51pm UTC](https://discuss.elastic.co/t/how-to-add-field-for-logs-from-specific-file/224567 "2020-03-22T16:51:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![pedro.1234](https://avatars.discourse-cdn.com/v4/letter/p/8dc957/32.png) [@pedro.1234](https://discuss.elastic.co/u/pedro.1234)\
**Post date:** [March 22, 2020, 4:51pm UTC](https://discuss.elastic.co/t/how-to-add-field-for-logs-from-specific-file/224567/1 "2020-03-22T16:51:50Z")

</div>

Hello,

I'm fresh user of ELK, i would like to read logs from different files and use grok's filter only for certain log/file. My setup looks like this:  
firewall logs -\> rsyslog -\> file -\> filebeat -\> logstash -\> Elastic/Kibana

If i understand correctly i should add field in filebeat configuration and afterwards in logstash statemant # if [type] == "firewall" then .. and filter configuration  
I couldn't find filebeat.yml config for that, i was trying like this:

```
- type: log
  enabled: true
  paths:
    - /var/log/fw/*.log
    fields:
    type: firewall

- type: log
  enabled: true
  paths:
   - /var/log/sw/*.log
   - /var/log/pxy/*.log
   - /var/log/srv/*.log

 processors:
      - add_host_metadata: ~
      - add_cloud_metadata: ~
      - add_docker_metadata: ~
      - add_kubernetes_metadata: ~
     - add_fields:
       target: ''
       fields:
         name: type
         id: '999999999'

```

but it doesn't work. thanks for any help

Pedro

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [March 23, 2020, 5:23pm UTC](https://discuss.elastic.co/t/how-to-add-field-for-logs-from-specific-file/224567/2 "2020-03-23T17:23:51Z")

</div>

I think you are mostly there! Based on what you already have, you could solve this in one of two ways:

1. You could move your `add_fields` processor section under the first input's configuration. Processors can be defined globally (like you have) but also per-input. See [https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#where-valid](https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#where-valid).

2. You could leave your `add_fields` processor section where it is (in the global list of processors) but then you probably want to add a conditional configuration section under it, so only `type: firewall` events are processed by that processor. See [https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#defining-processors](https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#defining-processors) and [https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#conditions](https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#conditions).

Hope that helps,

Shaunak

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2020, 5:23pm UTC](https://discuss.elastic.co/t/how-to-add-field-for-logs-from-specific-file/224567/3 "2020-04-20T17:23:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
