Logstash - Match metadata from filebeat


I've noticed filebeat sends some additional metadata for each generated event such as:
host.hostname, log.file.path and host.os.family.

Can I access them in logstash and create additional fields to my event, based on the metadata values?

In logstash I use a grok filter to parse my IIS logs.

Thanks in advance.

Yes, but in logstash you refer to nested fields as [host][hostname] or [log][file][path].

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.