# Output.kafka filebeat (possible to add field ?)

**URL:** <https://discuss.elastic.co/t/output-kafka-filebeat-possible-to-add-field/299332>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 10, 2022, 11:55am UTC](https://discuss.elastic.co/t/output-kafka-filebeat-possible-to-add-field/299332 "2022-03-10T11:55:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![alex\_vermex](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_vermex/32/101267_2.png) [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Post date:** [March 10, 2022, 11:55am UTC](https://discuss.elastic.co/t/output-kafka-filebeat-possible-to-add-field/299332/1 "2022-03-10T11:55:55Z")

</div>

Hi,  
I would like to know if it is possible to add a field in the kafka output  
filebeat.yml:

```auto
output.kafka:
  hosts: ["127.0.0.1:9092"]
  topic: '%{[fields.kafka_topic]}'
  codec.format:
    string: '%{[message]}'
  partition.round_robin:
    reachable_only: false
  required_acks: 1
  compression: gzip
  max_message_bytes: 1000000
  close_inactive: 50m
processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~

```

So i want to add field =\> "path" i found a solution but it's a bad solution i think i add this line in output.kafka

```auto
key: '%{[log][file][path]}'

```

It works but it means I change the value of "key" so it's a bad idea  
logstash.conf

```auto
mutate{
    add_field => { "[path]" => "%{[@metadata][kafka][key]}"}
    }

```

Any help would be sincerely appreciate!  
Thanks!

---

<div class="post-metadata">

**Author:** ![Marius\_Iversen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_iversen/32/68988_2.png) [@Marius\_Iversen](https://discuss.elastic.co/u/Marius_Iversen)\
**Post date:** [March 10, 2022, 12:57pm UTC](https://discuss.elastic.co/t/output-kafka-filebeat-possible-to-add-field/299332/2 "2022-03-10T12:57:45Z")

</div>

We have a list of filebeat processors that can modify the data before it is being sent to the output, you can add them after the two processors you already have:

> **[Add fields | Filebeat Reference \[8.1\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/add-fields.html)**

And if you need to copy a value from an existing field:

> **[Copy fields | Filebeat Reference \[8.1\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/copy-fields.html)**

There should be a few yml examples in those docs as well 🙂

---

<div class="post-metadata">

**Author:** ![alex\_vermex](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_vermex/32/101267_2.png) [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Post date:** [March 10, 2022, 1:32pm UTC](https://discuss.elastic.co/t/output-kafka-filebeat-possible-to-add-field/299332/3 "2022-03-10T13:32:16Z")

</div>

Thank you for the reply.  
I have already tried these examples but didn't work i don't know where is the problem.  
i tried this

```auto
processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~
  - add_fields:
      target: pathtest
      fields:
        name: '%{[log][file][path]}'

```

logstash.conf

```auto
mutate{
    add_field => { "[pathtest]" => "%{[pathtest]}"}
    }

```

it gives me  
`"pathtest" => "%{[pathtest]}"`  
and i also tried this:

```auto
processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~
  - add_fields:
      target: '@metadata'
      fields:
        op_type: "%{[log][file][path]}"

```

logstash.conf

```auto
mutate{
    add_field => { "[path]" => "%{[@metadata]}"}
    }

```

It gives me  
`"path" => "{\"kafka\":{\"topic\":\"kafka-topic-test\",\"consumer_group\":\"logstash\",\"partition\":0,\"offset\":72,\"key\":\"null\",\"timestamp\":1720134475223}}"`  
there is no op\_type in metadata... i don't know if i did something wrong ?

Any help would be sincerely appreciate!  
Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 7, 2022, 3:32pm UTC](https://discuss.elastic.co/t/output-kafka-filebeat-possible-to-add-field/299332/4 "2022-04-07T15:32:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
