# Modify the message outpout

**URL:** <https://discuss.elastic.co/t/modify-the-message-outpout/224574>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 22, 2020, 7:43pm UTC](https://discuss.elastic.co/t/modify-the-message-outpout/224574 "2020-03-22T19:43:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![geoffreydjof](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/geoffreydjof/32/61581_2.png) [@geoffreydjof](https://discuss.elastic.co/u/geoffreydjof)\
**Post date:** [March 22, 2020, 7:43pm UTC](https://discuss.elastic.co/t/modify-the-message-outpout/224574/1 "2020-03-22T19:43:14Z")

</div>

Hi,

I have installed Filebeat on my servers to collect json logs. It works great !

I have one question : I would like to know if it's possible to modify the content of a message ?

Let me be more explicit :

In Kiban, there is the source filed, which comes from my filebeat configuration :

```auto
filebeat.prospectors:
- paths: "/appl/wasbivh1/*/data/log/json.log"
  input_type: log
  json.keys_under_root: true

```

So, in Kibana, I have a filed name "source" which prints the path , ie here /appl/wasbivh1/SERVICE/data/log/json.log

What I would like is to be able not to print all the path, but only SERVICE in my kibana.  
So the "source" field would print only "SERVICE" (and not all path) in Kibana.

Is there a prospector which could do the job ?

Thanks in advance !

Best regards,

Geoffrey

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [March 23, 2020, 5:15pm UTC](https://discuss.elastic.co/t/modify-the-message-outpout/224574/2 "2020-03-23T17:15:25Z")

</div>

What version of Filebeat are you using?

I ask because recent versions of Filebeat have a [`dissect` processor](https://www.elastic.co/guide/en/beats/filebeat/current/dissect.html) that might be effective here.

However, the fact that you are using `filebeat.prospectors` (not `filebeat.inputs`) tells me that you might be on a version of Filebeat that's too old to have the `dissect` processor in it. In that case you may be able to setup an Elasticsearch Ingest Node pipeline with a `dissect` or `grok` processor in it and [configure your Filebeat to use it](https://www.elastic.co/guide/en/beats/filebeat/6.8/configuring-ingest-node.html).

Shaunak

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2020, 5:17pm UTC](https://discuss.elastic.co/t/modify-the-message-outpout/224574/3 "2020-04-20T17:17:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
