# Logstash not able to access the custom field from Filebeat

**URL:** <https://discuss.elastic.co/t/logstash-not-able-to-access-the-custom-field-from-filebeat/87553>\
**Category:** Logstash\
**Created:** [May 30, 2017, 10:44am UTC](https://discuss.elastic.co/t/logstash-not-able-to-access-the-custom-field-from-filebeat/87553 "2017-05-30T10:44:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dattatray\_Kulkarni](https://avatars.discourse-cdn.com/v4/letter/d/df705f/32.png) [@Dattatray\_Kulkarni](https://discuss.elastic.co/u/Dattatray_Kulkarni)\
**Post date:** [May 30, 2017, 10:44am UTC](https://discuss.elastic.co/t/logstash-not-able-to-access-the-custom-field-from-filebeat/87553/1 "2017-05-30T10:44:49Z")

</div>

Hi,

I have multiple types of log files from different servers. So I am using multiple filebeat agents.

In the Filebeat configuration, I am adding a custom field - log\_type  
Here is the snippet of the filebeat configuration.

fields:  
log\_type: threadpoolworkerlog

Filebeat is producing the correct output and sending it to Logstash.

In Logstash, based on the value of this field log\_type, I want to add some filters.  
Here is the relevant section of the Logstash config.

filter {  
if [fields][log\_type] == "threadpoolworkerlog" {  
grok {  
add\_tag =\> ["threadpoolworkerlog"]  
add\_field =\> { "log\_type" =\> "threadpoolworkerlog" }  
match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:datetime} %{DATA:thread} %{LOGLEVEL:Loglevel} %{DATA:Classname} %{GREEDYDATA:messagetext}"}   
}  
}  
}

But logstash is not reading the value of the custom field log\_type, so it is not able to execute the statements in the grok block - add tag, add\_field, etc.

Is there anything incorrect in the logstash configuration?

---

<div class="post-metadata">

**Author:** ![batrako](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/batrako/32/17116_2.png) [@batrako](https://discuss.elastic.co/u/batrako)\
**Post date:** [May 30, 2017, 3:25pm UTC](https://discuss.elastic.co/t/logstash-not-able-to-access-the-custom-field-from-filebeat/87553/2 "2017-05-30T15:25:50Z")

</div>

> [@Dattatray\_Kulkarni](#):
>
> fields][log\_type]

in my case with 5.4 i use this option in filebeat :

` fields_under_root: true`

this allow you use filebeat fields at toplevel in logstash.  
With this, in logstash, i can use custom filebeat fields as common variables. For example:  
`index => "myindex-%{[entorno]}-%{+YYYY.MM.dd}"` where `[entorno]` is my custom field in filebeat.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2017, 3:26pm UTC](https://discuss.elastic.co/t/logstash-not-able-to-access-the-custom-field-from-filebeat/87553/3 "2017-06-27T15:26:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
