# Osquery module logs not prefixed with osquery.result

**URL:** <https://discuss.elastic.co/t/osquery-module-logs-not-prefixed-with-osquery-result/146315>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 28, 2018, 9:58am UTC](https://discuss.elastic.co/t/osquery-module-logs-not-prefixed-with-osquery-result/146315 "2018-08-28T09:58:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![wojtas](https://avatars.discourse-cdn.com/v4/letter/w/edb3f5/32.png) [@wojtas](https://discuss.elastic.co/u/wojtas)\
**Post date:** [August 28, 2018, 9:58am UTC](https://discuss.elastic.co/t/osquery-module-logs-not-prefixed-with-osquery-result/146315/1 "2018-08-28T09:58:24Z")

</div>

Hello,

I am using 6.3.0 elastic stack on RHEL7, sending filebeat osquery logs to logstash (with osquery filebeat module enabled).  
As per the documentation [https://www.elastic.co/guide/en/beats/filebeat/6.3/filebeat-module-osquery.html](https://www.elastic.co/guide/en/beats/filebeat/6.3/filebeat-module-osquery.html) the logs should be prefixed with 'osquery.result' however I am not seeing this in elasticsearch. All fields start with 'json.columns.'.

My osquery module config is pretty basic:

```
- module: osquery
  result:
    input:
      tags: ["osquery_events"]

```

I tried to set `var.use_namespace` to true but it didn't help. Right know I am doing the mutate stuff in logstash but it would be nice not to do so.

Any help appreciated ! Thanks

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 28, 2018, 2:21pm UTC](https://discuss.elastic.co/t/osquery-module-logs-not-prefixed-with-osquery-result/146315/2 "2018-08-28T14:21:30Z")

</div>

Filebeat normally does not parse the raw logs. Filebeat modules normally setup the ingest node pipeline in Elasticsearch, so to offload parsing. If you put Logstash before Elasticsearch, then the event will not be parsed yet. Have a look at the [Working with Filebeat modules](https://www.elastic.co/guide/en/logstash/current/filebeat-modules.html) section in the Logstash documentation for more background.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 25, 2018, 2:21pm UTC](https://discuss.elastic.co/t/osquery-module-logs-not-prefixed-with-osquery-result/146315/3 "2018-09-25T14:21:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
