# How to add other \_types to the /etc/fields.yml in beats

**URL:** <https://discuss.elastic.co/t/how-to-add-other--types-to-the-etc-fields-yml-in-beats/70241>\
**Category:** Beats\
**Created:** [December 29, 2016, 11:42pm UTC](https://discuss.elastic.co/t/how-to-add-other--types-to-the-etc-fields-yml-in-beats/70241 "2016-12-29T23:42:13Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![blacktop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blacktop/32/14155_2.png) [@blacktop](https://discuss.elastic.co/u/blacktop)\
**Post date:** [December 29, 2016, 11:42pm UTC](https://discuss.elastic.co/t/how-to-add-other--types-to-the-etc-fields-yml-in-beats/70241/1 "2016-12-29T23:42:13Z")

</div>

I have a beat that will have MANY different \_types.

`beats/libbeat/scripts/generate_template.py` doesn't seem to support that?

Any help greatly appreciated.

It looks like you can add more \_types with filebeat modles ect, that looks like what I want to do.

Thanks!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [December 29, 2016, 11:46pm UTC](https://discuss.elastic.co/t/how-to-add-other--types-to-the-etc-fields-yml-in-beats/70241/2 "2016-12-29T23:46:03Z")

</div>

Packetbeat uses a different type for each protocol. Have a look at its [fields.yml](https://github.com/elastic/beats/blob/master/packetbeat/_meta/fields.yml).

---

<div class="post-metadata">

**Author:** ![blacktop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blacktop/32/14155_2.png) [@blacktop](https://discuss.elastic.co/u/blacktop)\
**Post date:** [December 29, 2016, 11:48pm UTC](https://discuss.elastic.co/t/how-to-add-other--types-to-the-etc-fields-yml-in-beats/70241/3 "2016-12-29T23:48:27Z")

</div>

So I tried using multiple keys, but after running `make update` I believe that `beats/libbeat/scripts/generate_template.py` did not parse it correctly. I will try again.

---

<div class="post-metadata">

**Author:** ![blacktop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blacktop/32/14155_2.png) [@blacktop](https://discuss.elastic.co/u/blacktop)\
**Post date:** [December 30, 2016, 12:02am UTC](https://discuss.elastic.co/t/how-to-add-other--types-to-the-etc-fields-yml-in-beats/70241/4 "2016-12-30T00:02:59Z")

</div>

I tried again and again it didn't seem to parse out he addtional `_types` with the `key` field

[https://github.com/blacktop/brobeat/blob/master/etc/fields.yml](https://github.com/blacktop/brobeat/blob/master/etc/fields.yml)

> <https://github.com/blacktop/brobeat/blob/master/brobeat.template.json>

@andrewkroh is it because I am using the `/etc/fields.yml` and not the `_meta` folder?

I did a cookiecutter to init the beat, but maybe that was an older version?

Thanks

---

<div class="post-metadata">

**Author:** ![blacktop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blacktop/32/14155_2.png) [@blacktop](https://discuss.elastic.co/u/blacktop)\
**Post date:** [December 30, 2016, 1:29am UTC](https://discuss.elastic.co/t/how-to-add-other--types-to-the-etc-fields-yml-in-beats/70241/5 "2016-12-30T01:29:54Z")

</div>

I blew my beat away and started from scratch and `make update` didn't pick up the extra `-key` \_types 😢

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [December 30, 2016, 2:37pm UTC](https://discuss.elastic.co/t/how-to-add-other--types-to-the-etc-fields-yml-in-beats/70241/6 "2016-12-30T14:37:15Z")

</div>

The vendored version of the script you have [appears](https://github.com/blacktop/brobeat/blob/master/vendor/github.com/elastic/beats/libbeat/scripts/generate_template.py#L4-L9) to be looking at `_meta/fields.yml`.

---

<div class="post-metadata">

**Author:** ![blacktop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blacktop/32/14155_2.png) [@blacktop](https://discuss.elastic.co/u/blacktop)\
**Post date:** [December 30, 2016, 4:10pm UTC](https://discuss.elastic.co/t/how-to-add-other--types-to-the-etc-fields-yml-in-beats/70241/7 "2016-12-30T16:10:48Z")

</div>

So I was able to figure out how to add more `sub-fields` except that the way that it works is it creates nested fields under the `_default` mapping.

I usually like to use document `_types` to pull apart.. well document types. Is there a reason you have designed it this way? I can see that you are going to start using the concept of modules. For example an **nginx** filebeat module that I assume would create fields like this:

```auto
_index: filebeat-*
_type: filebeat
nginx.access.request.method: GET

```

To me it makes sense to have it be like:

```auto
_index: filebeat-*
_type: nginx-access
request.method: GET

```

I just think more deeply nested field names are harder to query?

Thoughts?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 3, 2017, 9:15am UTC](https://discuss.elastic.co/t/how-to-add-other--types-to-the-etc-fields-yml-in-beats/70241/8 "2017-01-03T09:15:54Z")

</div>

This blog post should share some insights on types vs index: [https://www.elastic.co/blog/index-vs-type](https://www.elastic.co/blog/index-vs-type) In our case it didn't bring an advantage.

---

<div class="post-metadata">

**Author:** ![blacktop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blacktop/32/14155_2.png) [@blacktop](https://discuss.elastic.co/u/blacktop)\
**Post date:** [January 4, 2017, 7:10pm UTC](https://discuss.elastic.co/t/how-to-add-other--types-to-the-etc-fields-yml-in-beats/70241/9 "2017-01-04T19:10:56Z")

</div>

thank you @ruflin!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 19, 2017, 11:42pm UTC](https://discuss.elastic.co/t/how-to-add-other--types-to-the-etc-fields-yml-in-beats/70241/10 "2017-01-19T23:42:21Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
