# How to use "exported fields"?

**URL:** <https://discuss.elastic.co/t/how-to-use-exported-fields/192973>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 30, 2019, 7:00pm UTC](https://discuss.elastic.co/t/how-to-use-exported-fields/192973 "2019-07-30T19:00:11Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dmitry1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dmitry1/32/50610_2.png) [@Dmitry1](https://discuss.elastic.co/u/Dmitry1)\
**Post date:** [July 30, 2019, 7:00pm UTC](https://discuss.elastic.co/t/how-to-use-exported-fields/192973/1 "2019-07-30T19:00:11Z")

</div>

Helo, please help. From documentation and googling i can't understand what ["Exported fields"](https://www.elastic.co/guide/en/beats/filebeat/7.2/exported-fields.html) in filebeat is and how to use them. For example i want to add information about logfile's mtime when i send events to logstash.

One of my tries

```auto
filebeat.inputs:
- type: log
  paths:
    - /test.log
processors:
- add_fields:
     fields:
       mtime: "%{file.mtime}"

output.logstash:
  hosts: ["logstash.ip:5044"]

```

but logstash recieved this:

```auto
{
.....
         "input" => {
        "type" => "log"
    },  
        "fields" => {
        "mtime" => "%{file.mtime}"
    },
           "log" => {
          "file" => {
            "path" => "/test.log"
        },
....
}

```

and i want something like this

```auto
    {
    .....
             "input" => {
            "type" => "log"
        },  
            "fields" => {
            "mtime" => "2019-07-26 19:23:21"
        },
               "log" => {
              "file" => {
                "path" => "/test.log"
            },
    ....
    }

```

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2019, 7:00pm UTC](https://discuss.elastic.co/t/how-to-use-exported-fields/192973/2 "2019-08-27T19:00:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
