# Importing index field

**URL:** <https://discuss.elastic.co/t/importing-index-field/323155>\
**Category:** Kibana\
**Created:** [January 13, 2023, 6:41pm UTC](https://discuss.elastic.co/t/importing-index-field/323155 "2023-01-13T18:41:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zay\_Lin\_Htun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zay_lin_htun/32/102063_2.png) [@Zay\_Lin\_Htun](https://discuss.elastic.co/u/Zay_Lin_Htun)\
**Post date:** [January 13, 2023, 6:41pm UTC](https://discuss.elastic.co/t/importing-index-field/323155/1 "2023-01-13T18:41:16Z")

</div>

Hi folks,

I have issues on lacking field on index in elk of beats (filebeat, auditbeat and winlogbeat). current my log flows is  
log source hosts \>\> kafka \>\> logstash \>\> elastic cloud (elk).  
according to my understanding, I need to load manually index templates and ingest pipeline if I am not ship the logs directly to elk from beats. So I am thinking to use separate two machines (linux and windows) to ship the logs to elk directly (only to load index templates).

so I want to know if I do ingest the logs like this, can I get more field on elk before doing manual on other machines which installed beats.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 17, 2023, 1:22am UTC](https://discuss.elastic.co/t/importing-index-field/323155/2 "2023-01-17T01:22:17Z")

</div>

Hi @Zay_Lin_Htun

It is a pretty common pattern when you have a complex/multi-step ingest architecture to have a "setup" VM where you install the beats, configure them, point them at Kibana and Elasticsearch and then run setup. That way all the beats assets (Templates, Ingest pipelines, Dashboards etc) are loaded into Kibana and Elasticssearch. That VM does not even need real log sources just connectivity to Kibana and Elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2023, 1:22am UTC](https://discuss.elastic.co/t/importing-index-field/323155/3 "2023-02-14T01:22:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
