# How to use filebeat copy\_fields processor with data computed later (netflow received data and geo computed data)?

**URL:** <https://discuss.elastic.co/t/how-to-use-filebeat-copy-fields-processor-with-data-computed-later-netflow-received-data-and-geo-computed-data/231799>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 8, 2020, 8:33pm UTC](https://discuss.elastic.co/t/how-to-use-filebeat-copy-fields-processor-with-data-computed-later-netflow-received-data-and-geo-computed-data/231799 "2020-05-08T20:33:57Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jorge\_Correa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jorge_correa/32/45613_2.png) [@Jorge\_Correa](https://discuss.elastic.co/u/Jorge_Correa)\
**Post date:** [May 8, 2020, 8:33pm UTC](https://discuss.elastic.co/t/how-to-use-filebeat-copy-fields-processor-with-data-computed-later-netflow-received-data-and-geo-computed-data/231799/1 "2020-05-08T20:33:57Z")

</div>

I'm using filebeat with netflow module, so I'm receiving netflow data and inserting in elasticsearch. All netflow fields are described here:

[https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-netflow.html](https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-netflow.html)

However, when we analyze data in Kibana some other fields are avaiable, like geo.\<other\_fields\> (destination.geo.country\_iso\_code, source.geo.country\_iso\_code etc). When these data are computed and inserted in elasticsearch index? I think they are not in data received.

Continuing ...

In my analisis I need to identify a external address. So I've processors that compare received values with my network addresses ranges and then copy right value to a new field.

```
- copy_fields:
      when:
        network:
           netflow.source_ipv4_address: ['XXX.XXX.XXX.0/24', 'YYY.YYY.YYY.0/24']
      fields:
        - from: netflow.destination_ipv4_address
          to: netflow.external_address
      ignore_missing: true
      fail_on_error: false
      ...

```

I would like to copy too another data like destination.geo.country\_iso\_code, destination.geo.city\_name and destination.as.organization.name.

But, if I try to create a processor like that from netflow.destination\_ipv4\_address the values are never copied.

Netflow is a protocol that do not export info like that (AS name, cities and countries involved). I think that data are computed after flows to be received.

Is there some way to do that, copy that data like that one received by filebeat (addresses, like the processor above)?

Tks!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2020, 8:33pm UTC](https://discuss.elastic.co/t/how-to-use-filebeat-copy-fields-processor-with-data-computed-later-netflow-received-data-and-geo-computed-data/231799/2 "2020-06-05T20:33:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
