# Missing field

**URL:** <https://discuss.elastic.co/t/missing-field/230760>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [May 1, 2020, 7:47pm UTC](https://discuss.elastic.co/t/missing-field/230760 "2020-05-01T19:47:08Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![edvrfn](https://avatars.discourse-cdn.com/v4/letter/e/4bbf92/32.png) [@edvrfn](https://discuss.elastic.co/u/edvrfn)\
**Post date:** [May 1, 2020, 7:47pm UTC](https://discuss.elastic.co/t/missing-field/230760/1 "2020-05-01T19:47:09Z")

</div>

I am using filebeats panos module. In the index i don't see the source.geo.name or destination.geo.name if i select the event.category as network\_traffic. Although it shows as country ISO\_code but not by name. Actual syslog is below which shows the countries name. How can i get name also in the index.

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/4/4/4452abe1fd590d36b8da27d9808f7a235c1b317e.png)

source/destination geo.name field is there in even.category : security\_threat

below is the event.category : network\_traffic raw log

1,2020/05/01 12:20:21,011101011111,TRAFFIC,drop,2323,2020/05/01 12:20:21,87.251.74.46,3.3.3.3,0.0.0.0,0.0.0.0,DBL-IN,,,not-applicable,vsys1,OUT,OUT,fa1,,syslog-server,2020/05/01 12:20:21,0,1,51515,20202,0,0,0x0,tcp,drop,64,64,0,1,2020/05/01 12:20:19,0,any,0,671547036560625252,0x8000000000000000,Russian Federation,United States,0,1,0,policy-deny,1111,0,0,0,vsys1,BR437PANV1,from-policy,,,0,,0,,N/A,0,0,0,0

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 29, 2020, 7:47pm UTC](https://discuss.elastic.co/t/missing-field/230760/2 "2020-05-29T19:47:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
