# How to use filebeat fields name value in logstash config

**URL:** <https://discuss.elastic.co/t/how-to-use-filebeat-fields-name-value-in-logstash-config/79791>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 23, 2017, 6:02pm UTC](https://discuss.elastic.co/t/how-to-use-filebeat-fields-name-value-in-logstash-config/79791 "2017-03-23T18:02:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jayanna\_Hallur](https://avatars.discourse-cdn.com/v4/letter/j/a4c791/32.png) [@Jayanna\_Hallur](https://discuss.elastic.co/u/Jayanna_Hallur)\
**Post date:** [March 23, 2017, 6:02pm UTC](https://discuss.elastic.co/t/how-to-use-filebeat-fields-name-value-in-logstash-config/79791/1 "2017-03-23T18:02:48Z")

</div>

Hi All

Below are my config files for 2 filebeats & logstash.. I set the fields index=my\_data\_1 in filebeat config. & send to logstash.. in the logstash i want use the value passed in fields.index from filebeat to use it for indexing when sent to elastic search.. so that both filebeat agents using the same logstash can send data to different index names.

But, [fields][index] is not working.. im unable to get the value set in filebeat..

With the below configuration the index name in created in ES cluster is [fields][index]-2017.03.23

"[@metadata][index]" =\> "[fields][index]" ==\> not working

Logstash configs:

````auto
```
input {
  beats {
     port => "9997"
  }
}

filter {
  mutate {
    replace => {
      "[@metadata][index]" => "[fields][index]" ===> This is not working..
    }
  }
}

output {
  elasticsearch {
     hosts => ["10.205.233.191:8089","10.205.236.248:8089","10.205.235.211:8089"]
     index => "%{[@metadata][index]}-%{+YYYY.MM.dd}"
     #document_type => "%{[@metadata][type]}"
  }
}
```

File beat -1 config:

````

```auto
filebeat.prospectors:
- input_type: log
  paths:
    - <path to file>

  fields:
     index: my_data

output.logstash:
  # The Logstash hosts
  hosts: ["localhost:9997"]

```

File beat -2 config:

````auto
```
filebeat.prospectors:
- input_type: log
  paths:
    - <path to file>

  fields:
     index: my_data_2

output.logstash:
  # The Logstash hosts
  hosts: ["localhost:9997"]
```
````

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 27, 2017, 6:46am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-fields-name-value-in-logstash-config/79791/2 "2017-03-27T06:46:34Z")

</div>

- Could you use file output to verify that the field is set on the filebeat side? (should be the case)
- Could you to use fields index directly for the fields?

```auto
index => "%{[fields][index]}-%{+YYYY.MM.dd}"

```

---

<div class="post-metadata">

**Author:** ![Jayanna\_Hallur](https://avatars.discourse-cdn.com/v4/letter/j/a4c791/32.png) [@Jayanna\_Hallur](https://discuss.elastic.co/u/Jayanna_Hallur)\
**Post date:** [March 28, 2017, 4:40pm UTC](https://discuss.elastic.co/t/how-to-use-filebeat-fields-name-value-in-logstash-config/79791/3 "2017-03-28T16:40:24Z")

</div>

Thanks for the reply.. But I need to put in filter as highlighted above.. When I put in the filter section, it didn't work.

But if work for if condition in the filter section..it works fine.. but not when I used it assign  
e.g:  
if [fields][index] == "abc" { #### ==\> Works  
"[@metadata][index]" =\> "[fields][index]" ===\> This is not working..  
}

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [March 29, 2017, 8:49am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-fields-name-value-in-logstash-config/79791/4 "2017-03-29T08:49:16Z")

</div>

check the syntax. I think the right hand side must be a format-string, that is `"%{[field][index]}"`.

---

<div class="post-metadata">

**Author:** ![Jayanna\_Hallur](https://avatars.discourse-cdn.com/v4/letter/j/a4c791/32.png) [@Jayanna\_Hallur](https://discuss.elastic.co/u/Jayanna_Hallur)\
**Post date:** [April 4, 2017, 6:37pm UTC](https://discuss.elastic.co/t/how-to-use-filebeat-fields-name-value-in-logstash-config/79791/6 "2017-04-04T18:37:36Z")

</div>

Worked. Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2017, 6:37pm UTC](https://discuss.elastic.co/t/how-to-use-filebeat-fields-name-value-in-logstash-config/79791/7 "2017-05-02T18:37:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
