# Logstash doesn't automatically collect all Zeek fields without grok pattern

**URL:** <https://discuss.elastic.co/t/logstash-doesnt-automatically-collect-all-zeek-fields-without-grok-pattern/269613>\
**Category:** Logstash\
**Created:** [April 8, 2021, 3:00pm UTC](https://discuss.elastic.co/t/logstash-doesnt-automatically-collect-all-zeek-fields-without-grok-pattern/269613 "2021-04-08T15:00:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Automation\_Scripts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/automation_scripts/32/85374_2.png) [@Automation\_Scripts](https://discuss.elastic.co/u/Automation_Scripts)\
**Post date:** [April 8, 2021, 3:00pm UTC](https://discuss.elastic.co/t/logstash-doesnt-automatically-collect-all-zeek-fields-without-grok-pattern/269613/1 "2021-04-08T15:00:06Z")

</div>

Hi,

Is there a setting I need to provide in order to enable the automatically collection of all the Zeek's log fields? I can collect the fields message _only_ through a grok filter.

My assumption is that logstash is smart enough to collect all the fields automatically from all the Zeek log types. Is this right?

PS I don't have any plugin installed or grok pattern provided.  
My pipeline is zeek-filebeat-kafka-logstash

Thank you in advance!

Thank you!

---

<div class="post-metadata">

**Author:** ![rijinmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rijinmp/32/24634_2.png) [@rijinmp](https://discuss.elastic.co/u/rijinmp)\
**Post date:** [April 9, 2021, 7:19am UTC](https://discuss.elastic.co/t/logstash-doesnt-automatically-collect-all-zeek-fields-without-grok-pattern/269613/2 "2021-04-09T07:19:56Z")

</div>

Automatic field detection is only possible with input plugins in Logstash or Beats . But logstash doesn't have a zeek log plugin .

**File Beat have a zeek module . If you are using this , Filebeat will detect zeek fields and create default dashboard also**

> **[Zeek (Bro) Module | Filebeat Reference \[7.12\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-zeek.html)**

**Detecting Zeek Fields**

> **[Zeek fields | Filebeat Reference \[7.12\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-zeek.html)**

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [April 9, 2021, 3:45pm UTC](https://discuss.elastic.co/t/logstash-doesnt-automatically-collect-all-zeek-fields-without-grok-pattern/269613/3 "2021-04-09T15:45:45Z")

</div>

@Automation_Scripts if you have setup Zeek to log in json format, you can easily extract all of the fields in Logstash using the `json` filter. For example:

```json
json {
  skip_on_invalid_json => true
  source => "message"
  target => "zeek"
}

```

---

<div class="post-metadata">

**Author:** ![Automation\_Scripts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/automation_scripts/32/85374_2.png) [@Automation\_Scripts](https://discuss.elastic.co/u/Automation_Scripts)\
**Post date:** [April 13, 2021, 6:01pm UTC](https://discuss.elastic.co/t/logstash-doesnt-automatically-collect-all-zeek-fields-without-grok-pattern/269613/4 "2021-04-13T18:01:49Z")

</div>

Thank you! Seems that my zeek was logging TSV and not Json. Thank your for your hint. Now I have to ser why filebeat doesnt do it’s enrichment of the data ==\> ECS i.e I hve no event.dataset etc.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2021, 6:02pm UTC](https://discuss.elastic.co/t/logstash-doesnt-automatically-collect-all-zeek-fields-without-grok-pattern/269613/5 "2021-05-11T18:02:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
