# Indexing simple json at filebeats 7.2

**URL:** <https://discuss.elastic.co/t/indexing-simple-json-at-filebeats-7-2/188613>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 3, 2019, 5:51am UTC](https://discuss.elastic.co/t/indexing-simple-json-at-filebeats-7-2/188613 "2019-07-03T05:51:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![taka-h](https://avatars.discourse-cdn.com/v4/letter/t/e495f1/32.png) [@taka-h](https://discuss.elastic.co/u/taka-h)\
**Post date:** [July 3, 2019, 5:51am UTC](https://discuss.elastic.co/t/indexing-simple-json-at-filebeats-7-2/188613/1 "2019-07-03T05:51:00Z")

</div>

I'd like to store some JSON log file to Elasticsearch and index log easily.

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /var/log/sample/*.log
  json.keys_under_root: true
  json.add_error_key: true

setup.template.name: "sample"
setup.template.fields: "fields.yml"
setup.template.pattern: "sample-*"
setup.template.overwrite: "true"

output.elasticsearch:
  hosts: ["localhost:9200"]
  enabled: true
  index: "sample"

```

example log

```auto
{"time":"2019-07-02T16:52:29.62+0900","remote_addr":"10.0.12.5","uri":"/list_account"}

```

```auto
- key: sample
  title: "sample"
  fields:
    - name: "time"
      type: "date"
    - name: remote_addr
      type: "ip"
    - name: uri
      type: "keyword"

```

I expect that Iog is stored with index, but there are some problems

(1) Index is not created as expected name

```auto
filebeat export template
{
  "index_patterns": [
    "filebeat-7.2.0-*"
  ],
...

```

(2) log is parsed and stored as \_source in the default index(filebeat-7.2.0-\*)

How should I do to store the above simple JSON with index?

---

<div class="post-metadata">

**Author:** ![faec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faec/32/46988_2.png) [@faec](https://discuss.elastic.co/u/faec)\
**Post date:** [July 5, 2019, 8:28pm UTC](https://discuss.elastic.co/t/indexing-simple-json-at-filebeats-7-2/188613/2 "2019-07-05T20:28:10Z")

</div>

Welcome! Sorry, could you clarify -- are you trying to save your logs to `sample` and it's getting put in `filebeat-*` instead, or are you not seeing the right logs at all? It sounds like the former but I wanted to make sure. As for your second question, saving the original input in `_source` is usually the right thing to do, is your problem that you want to remove `_source` or that the fields are not otherwise being indexed?

---

<div class="post-metadata">

**Author:** ![taka-h](https://avatars.discourse-cdn.com/v4/letter/t/e495f1/32.png) [@taka-h](https://discuss.elastic.co/u/taka-h)\
**Post date:** [July 7, 2019, 10:45pm UTC](https://discuss.elastic.co/t/indexing-simple-json-at-filebeats-7-2/188613/3 "2019-07-07T22:45:24Z")

</div>

Thank you for your reply.

> are you trying to save your logs to `sample` and it's getting put in `filebeat-*` instead, or are you not seeing the right logs at all?

I'd like to store logs to `sample`.  
Logs seems to be stored into default index `filebeat-*`

> saving the original input in `_source` is usually the right thing to do, is your problem that you want to remove `_source` or that the fields are not otherwise being indexed?

maybe 'the fields are not otherwise being indexed'  
I'd like to fields get indexed, but I can't understand whether my output index setting is wrong or fields.yml is wrong.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 4, 2019, 10:45pm UTC](https://discuss.elastic.co/t/indexing-simple-json-at-filebeats-7-2/188613/4 "2019-08-04T22:45:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
