# Squid proxy logs directly to ELasticSearch via filebeat!

**URL:** <https://discuss.elastic.co/t/squid-proxy-logs-directly-to-elasticsearch-via-filebeat/197949>\
**Category:** Beats\
**Tags:** ecs-elastic-common-schema, filebeat\
**Created:** [September 3, 2019, 9:01pm UTC](https://discuss.elastic.co/t/squid-proxy-logs-directly-to-elasticsearch-via-filebeat/197949 "2019-09-03T21:01:12Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![Randy-312](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/randy-312/32/19451_2.png) [@Randy-312](https://discuss.elastic.co/u/Randy-312)\
**Post date:** [September 6, 2019, 9:04pm UTC](https://discuss.elastic.co/t/squid-proxy-logs-directly-to-elasticsearch-via-filebeat/197949/6 "2019-09-06T21:04:31Z")

</div>

I'm reviewing the links from: [ECS - Squid proxy log normalization](https://discuss.elastic.co/t/ecs-squid-proxy-log-normalization/190777/2)

While we're looking to map it in.

This is also interesting: [https://github.com/molu8bits/squid-filebeat-kibana/blob/master/filebeat/etc/filebeat/squid-fields.yml](https://github.com/molu8bits/squid-filebeat-kibana/blob/master/filebeat/etc/filebeat/squid-fields.yml) which is ONLY the CLF, and not the full Squid format (10 fields).

This work will require us to map the squid. fields into a corresponding ECS one. I believe we'll do similar work to what was done for nginx, and the use of aliases. [https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-nginx.html](https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-nginx.html)

---

_[View the full topic](https://discuss.elastic.co/t/squid-proxy-logs-directly-to-elasticsearch-via-filebeat/197949)._
