# Missing tags and extra fields

**URL:** <https://discuss.elastic.co/t/missing-tags-and-extra-fields/217992>\
**Category:** Logstash\
**Created:** [February 5, 2020, 12:52pm UTC](https://discuss.elastic.co/t/missing-tags-and-extra-fields/217992 "2020-02-05T12:52:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ben240489](https://avatars.discourse-cdn.com/v4/letter/b/71e660/32.png) [@Ben240489](https://discuss.elastic.co/u/Ben240489)\
**Post date:** [February 5, 2020, 12:52pm UTC](https://discuss.elastic.co/t/missing-tags-and-extra-fields/217992/1 "2020-02-05T12:52:19Z")

</div>

Hi guys,

Once again I have an issue trying out the ELK. In general, in Kibana I cannot see any tags I set and also my extra fields (e.g. number/date) displayed which I parsed. The message itself is seen in Kibana, line by line as a message but "tags" stay empty and also the parsed fields are not displayed.  
And the index itself is just displayed as "[@metadata][index]".

Can you please advise? I am running version 6.2.4 if it is needed to know.

The log file looks like this:  
22.01.2020 ! 08.39.55 ! 78 ! This is a text ! 0 #  
22.01.2020 ! 08.39.55 ! 78 ! This as well ! 0 #  
22.01.2020 ! 08.39.55 ! 78 ! And finally this ! 0 #

My part for filebeat.yml looks like this:  
fields:  
filebeat\_type: abc-def  
filebeat\_base\_path: "/path/to/our/log/"

```
filebeat_suffix_path: "with/suffix"
ignore_older: 24h
close_inactivhe: 5m
close_removed: true
close_eof: false
clean_removed: true
clean_inactive: 36h

```

And also, my logstash looks like this:  
filter {

```
        if [@metadata][logtype] == "abc-def"{
        # see: https://www.elastic.co/blog/logstash-metadata or https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html
        mutate {
            add_field => {
        "[@metadata][index]" => "my-test}"
            }
        }

                grok {
                        match => {
                                "message" => "%{DATE_EU:date} ! %{DATA:time} ! %{INT:number} ! %{DATA:category} ! %{INT:occurence} #\n"}

      tags => ["my_tag"]

                mutate {
                        add_field => {"date" => "%{date}"}
                        add_field => {"time" => "%{time}"}
                        add_field => {"plant" => "%{number}"}
                        add_field => {"category" => "%{category}"}
                        add_field => {"occurence" => "%{occurence}"}
                }
        }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 5, 2020, 5:30pm UTC](https://discuss.elastic.co/t/missing-tags-and-extra-fields/217992/2 "2020-02-05T17:30:10Z")

</div>

> [@Ben240489](#):
>
> if [@metadata][logtype] == "abc-def"{

I do not see where you are setting [@metadata][logtype]. Are you sure it is equal to that value? Also, remove the \n from the grok pattern. The event will not include a newline.

---

<div class="post-metadata">

**Author:** ![Ben240489](https://avatars.discourse-cdn.com/v4/letter/b/71e660/32.png) [@Ben240489](https://discuss.elastic.co/u/Ben240489)\
**Post date:** [February 6, 2020, 7:01am UTC](https://discuss.elastic.co/t/missing-tags-and-extra-fields/217992/3 "2020-02-06T07:01:09Z")

</div>

Hi Badger,

I thought through this here in Filebeat:  
`filebeat_type: abc-def`

I set that parameter? Should I just leave it out or how do I set it?

---

<div class="post-metadata">

**Author:** ![Ben240489](https://avatars.discourse-cdn.com/v4/letter/b/71e660/32.png) [@Ben240489](https://discuss.elastic.co/u/Ben240489)\
**Post date:** [February 6, 2020, 12:11pm UTC](https://discuss.elastic.co/t/missing-tags-and-extra-fields/217992/4 "2020-02-06T12:11:14Z")

</div>

Hi Badger,  
I found my mistake, a nice little bracket was missing and therefore none of my parsing or setting the tag etc. was recognized. Thank you for your help 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 5, 2020, 12:11pm UTC](https://discuss.elastic.co/t/missing-tags-and-extra-fields/217992/5 "2020-03-05T12:11:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
