# Logs-azure.eventhub@custom

**URL:** <https://discuss.elastic.co/t/logs-azure-eventhub-custom/356775>\
**Category:** Elastic Agent\
**Tags:** fleet\
**Created:** [April 4, 2024, 1:01pm UTC](https://discuss.elastic.co/t/logs-azure-eventhub-custom/356775 "2024-04-04T13:01:44Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eran\_Hadad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eran_hadad/32/102407_2.png) [@Eran\_Hadad](https://discuss.elastic.co/u/Eran_Hadad)\
**Post date:** [April 4, 2024, 1:01pm UTC](https://discuss.elastic.co/t/logs-azure-eventhub-custom/356775/1 "2024-04-04T13:01:44Z")

</div>

Hi,  
I'm using fleet to insert Azure logs into elasticsearch.  
I want to enrich my index with a new field so I created a new ingest pipeline named: `logs-azure.eventhub@custom` which I see that is been called from the managed pipeline.  
I ran a simulate command to check the pipeline and it seems to work and do as expected:  
`POST _ingest/pipeline/logs-azure.eventhub@custom/_simulate`  
but for some reason I don't see the new field created.  
I tried to add the field manually to the data view but obviously it's not the correct way.  
So I wonder what should I do next as everything is managed by fleet so I'm not sure how to handle it as oppose to an index I create myself.  
Any suggestions would be much appreciated

---

<div class="post-metadata">

**Author:** ![Julia\_Bardi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julia_bardi/32/79463_2.png) [@Julia\_Bardi](https://discuss.elastic.co/u/Julia_Bardi)\
**Post date:** [May 21, 2024, 9:41am UTC](https://discuss.elastic.co/t/logs-azure-eventhub-custom/356775/2 "2024-05-21T09:41:05Z")

</div>

You can add the new field mapping to the `logs-azure.eventhub@custom` component template. You can create it from the UI if it doesn't exist, from the Edit integration policy page.
