# Set beat.name/any custom field based on source

**URL:** <https://discuss.elastic.co/t/set-beat-name-any-custom-field-based-on-source/64988>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 4, 2016, 6:56am UTC](https://discuss.elastic.co/t/set-beat-name-any-custom-field-based-on-source/64988 "2016-11-04T06:56:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![manojvenkat](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@manojvenkat](https://discuss.elastic.co/u/manojvenkat)\
**Post date:** [November 4, 2016, 6:56am UTC](https://discuss.elastic.co/t/set-beat-name-any-custom-field-based-on-source/64988/1 "2016-11-04T06:56:12Z")

</div>

Hi ,

Is it possible to set the [beat.name](http://beat.name) using if condition based on source field value.

Eg. if source: /user1/logs, then beat.name=USER1\_LOGS  
else if source:/user2/logs, then beat.name=USER2\_LOGS

I need this to differentiate for creating vizualizaton graphs

If not [beat.name](http://beat.name), any other fields also fine.

Thanks.

---

<div class="post-metadata">

**Author:** ![manojvenkat](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@manojvenkat](https://discuss.elastic.co/u/manojvenkat)\
**Post date:** [November 4, 2016, 12:24pm UTC](https://discuss.elastic.co/t/set-beat-name-any-custom-field-based-on-source/64988/2 "2016-11-04T12:24:01Z")

</div>

Hi ,

Could someone please respond.

Thanks,

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 4, 2016, 3:01pm UTC](https://discuss.elastic.co/t/set-beat-name-any-custom-field-based-on-source/64988/3 "2016-11-04T15:01:20Z")

</div>

> [@manojvenkat](#):
>
> Is it possible to set the beat.name using if condition based on source field value.

No.

> [@manojvenkat](#):
>
> Hi ,
> 
> Could someone please respond.
> 
> Thanks,

Elastic offers [support subscriptions](https://www.elastic.co/subscriptions) with guaranteed response times if this is something you need.

> [@manojvenkat](#):
>
> I need this to differentiate for creating vizualizaton graphs
> 
> If not beat.name, any other fields also fine.

The [source](https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-log.html#_source) is populated with the full path of the log file. That might be an option to differentiate things based on your use case.

Another option would be separate the user1 and user2 logs into their own prospectors and assign each of them a [custom field](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#configuration-fields).

```auto
filebeat.prospectors:
- paths: [/user1/logs/*.log]
  fields_under_root: true
  fields: {user: user1}
- paths: [/user2/logs/*.log]
  fields_under_root: true
  fields: {user: user2}

```

---

<div class="post-metadata">

**Author:** ![manojvenkat](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@manojvenkat](https://discuss.elastic.co/u/manojvenkat)\
**Post date:** [November 4, 2016, 4:06pm UTC](https://discuss.elastic.co/t/set-beat-name-any-custom-field-based-on-source/64988/4 "2016-11-04T16:06:17Z")

</div>

Thanks a lot Andrew. I will try out and update the result here.

---

<div class="post-metadata">

**Author:** ![manojvenkat](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@manojvenkat](https://discuss.elastic.co/u/manojvenkat)\
**Post date:** [November 4, 2016, 4:38pm UTC](https://discuss.elastic.co/t/set-beat-name-any-custom-field-based-on-source/64988/5 "2016-11-04T16:38:38Z")

</div>

Hi,

I am not able to make this for Filebeat 1.3 . Could you please suggest compatible solution for version 1.3.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 4, 2016, 4:56pm UTC](https://discuss.elastic.co/t/set-beat-name-any-custom-field-based-on-source/64988/6 "2016-11-04T16:56:00Z")

</div>

For 1.3,

```auto
filebeat:
  prospectors:
  - paths: [/user1/logs/*.log]
    fields_under_root: true
    fields: {user: user1}
  - paths: [/user2/logs/*.log]
    fields_under_root: true
    fields: {user: user2}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 25, 2016, 6:56am UTC](https://discuss.elastic.co/t/set-beat-name-any-custom-field-based-on-source/64988/7 "2016-11-25T06:56:25Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
