# Topbeat json event, fieldname when sending to logstash

**URL:** <https://discuss.elastic.co/t/topbeat-json-event-fieldname-when-sending-to-logstash/55836>\
**Category:** Beats\
**Created:** [July 19, 2016, 7:45am UTC](https://discuss.elastic.co/t/topbeat-json-event-fieldname-when-sending-to-logstash/55836 "2016-07-19T07:45:56Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Arjun\_Agarwal](https://avatars.discourse-cdn.com/v4/letter/a/b782af/32.png) [@Arjun\_Agarwal](https://discuss.elastic.co/u/Arjun_Agarwal)\
**Post date:** [July 19, 2016, 7:45am UTC](https://discuss.elastic.co/t/topbeat-json-event-fieldname-when-sending-to-logstash/55836/1 "2016-07-19T07:45:56Z")

</div>

Plzz.. do let me know the name of the field which store the complete json event generated by topbeat when we are sending data from topbeat to logstash ?? or How can we store and get json events generated by topbeat in a field like message or source etc.. while sending them only to logstash??

---

<div class="post-metadata">

**Author:** ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)\
**Post date:** [July 19, 2016, 8:13am UTC](https://discuss.elastic.co/t/topbeat-json-event-fieldname-when-sending-to-logstash/55836/2 "2016-07-19T08:13:17Z")

</div>

Starting with 5.0 release Topbeat is replaced with the system module in Metricbeat. The system module sends the data out already parsed. Here is an example of a JSON object that is sent out by the system module in Metricbeat that is similar with what Topbeat sends:

```auto
{
  "@timestamp": "2016-07-19T08:08:00.713Z",
  "beat": {
    "hostname": "mar.local",
    "name": "mar.local"
  },
  "metricset": {
    "module": "system",
    "name": "process",
    "rtt": 24574
  },
  "system": {
    "process": {
      "cmdline": "/System/Library/CoreServices/loginwindow.app/Contents/MacOS/loginwindow console",
      "cpu": {
        "start_time": "Jul08",
        "total": {
          "pct": 0
        }
      },
      "memory": {
        "rss": {
          "bytes": 21757952,
          "pct": 0.0013
        },
        "share": 0,
        "size": 2688053248
      },
      "name": "loginwindow",
      "pid": 93,
      "ppid": 1,
      "state": "running",
      "username": "monica"
    }
  },
  "type": "metricsets"
}

```

After the JSON object arrives in Elasticsearch, you can simply search for any of the field for example `system.process.cmdline` to get the command line.  
Please let me know if you have any questions.

---

<div class="post-metadata">

**Author:** ![Arjun\_Agarwal](https://avatars.discourse-cdn.com/v4/letter/a/b782af/32.png) [@Arjun\_Agarwal](https://discuss.elastic.co/u/Arjun_Agarwal)\
**Post date:** [July 19, 2016, 8:47am UTC](https://discuss.elastic.co/t/topbeat-json-event-fieldname-when-sending-to-logstash/55836/3 "2016-07-19T08:47:53Z")

</div>

Thanks for metricbeat suggestion. !!!  
I want to know the name of the field(source or something) in which the complete event which you posted above is stored.  
I am sending the data from logstash to some db not to elasticsearch. Is there any way through which i can store this complete event as a json object in any field in logstash??

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 19, 2016, 10:03am UTC](https://discuss.elastic.co/t/topbeat-json-event-fieldname-when-sending-to-logstash/55836/4 "2016-07-19T10:03:39Z")

</div>

Can you share your beats output config and your logstash input config?

If logstash is configured correctly, there is no particular json stored in any field, but logstash will receive and handle the full event as posted by @monica.

---

<div class="post-metadata">

**Author:** ![Arjun\_Agarwal](https://avatars.discourse-cdn.com/v4/letter/a/b782af/32.png) [@Arjun\_Agarwal](https://discuss.elastic.co/u/Arjun_Agarwal)\
**Post date:** [July 19, 2016, 10:31am UTC](https://discuss.elastic.co/t/topbeat-json-event-fieldname-when-sending-to-logstash/55836/5 "2016-07-19T10:31:27Z")

</div>

@steffens logstash does not stores any json in a field. It's my requirement where i want that full event to be stored in any particular field in logstash, similar to what we get in \_source field in elasticsearch. This \_source kind of field i need in logstash where i could get the complete json event sent by beats. So can you help me with the name of that field if exists or any way to store that event in a field.

Thanks

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 19, 2016, 1:57pm UTC](https://discuss.elastic.co/t/topbeat-json-event-fieldname-when-sending-to-logstash/55836/6 "2016-07-19T13:57:38Z")

</div>

have you checked the logstash filter config documentation. Maybe you can use the [ruby filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html) to wrap/munge the event to your likings.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2016, 7:45am UTC](https://discuss.elastic.co/t/topbeat-json-event-fieldname-when-sending-to-logstash/55836/7 "2016-08-09T07:45:59Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
