# Logstash agent.\* fields

**URL:** <https://discuss.elastic.co/t/logstash-agent-fields/351261>\
**Category:** Logstash\
**Created:** [January 17, 2024, 11:26am UTC](https://discuss.elastic.co/t/logstash-agent-fields/351261 "2024-01-17T11:26:30Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![mwitsas](https://avatars.discourse-cdn.com/v4/letter/m/e47774/32.png) [@mwitsas](https://discuss.elastic.co/u/mwitsas)\
**Post date:** [January 17, 2024, 11:26am UTC](https://discuss.elastic.co/t/logstash-agent-fields/351261/1 "2024-01-17T11:26:30Z")

</div>

Is it possible to configure logstash to populate agent.\* fields in the same way beats agents do this e.g.

agent.type  
agent.version  
...

Many thanks

---

<div class="post-metadata">

**Author:** ![sholzhauer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sholzhauer/32/110282_2.png) [@sholzhauer](https://discuss.elastic.co/u/sholzhauer)\
**Post date:** [January 17, 2024, 11:57am UTC](https://discuss.elastic.co/t/logstash-agent-fields/351261/2 "2024-01-17T11:57:43Z")

</div>

I don't believe there is an option in logstash to do that automatically.  
Which leaves you with the option to add a filter section in your pipelines(s) to do this using a mutate for example.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 17, 2024, 12:41pm UTC](https://discuss.elastic.co/t/logstash-agent-fields/351261/3 "2024-01-17T12:41:01Z")

</div>

You have to add manually. There are similar fields, it depends on the input plugin, LS can add "host", "log"...

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [January 17, 2024, 1:01pm UTC](https://discuss.elastic.co/t/logstash-agent-fields/351261/4 "2024-01-17T13:01:34Z")

</div>

> [@mwitsas](#):
>
> Is it possible to configure logstash to populate agent.\* fields in the same way beats agents do this e.g.
> 
> agent.type  
> agent.version  
> ...
> 
> Many thanks

Hi,

You can use the `add_field` option in your Logstash filter or output plugins to add these fields to your events.

Here is an example of how you can do this in a Logstash filter:

```auto
filter {
  mutate {
    add_field => { 
      "[agent][type]" => "logstash"
      "[agent][version]" => "7.17.0"
    }
  }
}

```

[Mutate filter plugin | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-add_field)

Regards

---

<div class="post-metadata">

**Author:** ![mwitsas](https://avatars.discourse-cdn.com/v4/letter/m/e47774/32.png) [@mwitsas](https://discuss.elastic.co/u/mwitsas)\
**Post date:** [January 17, 2024, 2:41pm UTC](https://discuss.elastic.co/t/logstash-agent-fields/351261/5 "2024-01-17T14:41:19Z")

</div>

Thank you for the reply - can anyone confirm if there a way to configure logstash to output these automatically in the same way beats does? Or is this not possible and the only solution is to use add\_field and populate them myself ..

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 17, 2024, 3:44pm UTC](https://discuss.elastic.co/t/logstash-agent-fields/351261/6 "2024-01-17T15:44:40Z")

</div>

> [@mwitsas](#):
>
> Or is this not possible and the only solution is to use add\_field and populate them myself ..

This is not possible because the `agent` fields are related to Elastic Agent/Beats, logstash is not an agent, so those fields will not be generated by Logstash.

The only way would be to create them using the mutate filter.

But, what you are trying to achieve with that? Can you provide more context?

---

<div class="post-metadata">

**Author:** ![mwitsas](https://avatars.discourse-cdn.com/v4/letter/m/e47774/32.png) [@mwitsas](https://discuss.elastic.co/u/mwitsas)\
**Post date:** [January 17, 2024, 4:35pm UTC](https://discuss.elastic.co/t/logstash-agent-fields/351261/7 "2024-01-17T16:35:08Z")

</div>

Thanks I will populate the fields using the method suggested here

The reason for the question was just to be able to see the source of logs - the agent, version, and host it is running on in the same way I can with beats.

Mainly the host logstatsh is running on as I am populating host.name with a value from the log line

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2024, 4:35pm UTC](https://discuss.elastic.co/t/logstash-agent-fields/351261/8 "2024-02-14T16:35:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
