# Unable to use the replace filter on filebeat.yml

**URL:** <https://discuss.elastic.co/t/unable-to-use-the-replace-filter-on-filebeat-yml/321305>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 15, 2022, 12:33pm UTC](https://discuss.elastic.co/t/unable-to-use-the-replace-filter-on-filebeat-yml/321305 "2022-12-15T12:33:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![maviles](https://avatars.discourse-cdn.com/v4/letter/m/ccd318/32.png) [@maviles](https://discuss.elastic.co/u/maviles)\
**Post date:** [December 15, 2022, 12:33pm UTC](https://discuss.elastic.co/t/unable-to-use-the-replace-filter-on-filebeat-yml/321305/1 "2022-12-15T12:33:45Z")

</div>

I cannot replace the value of a field using the "replace" processor on filebeat.yml. The service is running but the field returns a null value. See the configuration below:

- replace:  
fields:  
- field: "decoded.cef.severity"  
pattern: "8"  
replace: "8/Medium"  
ignore\_missing: true  
fail\_on\_error: true

---

<div class="post-metadata">

**Author:** ![dadiasish](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadiasish/32/114221_2.png) [@dadiasish](https://discuss.elastic.co/u/dadiasish)\
**Post date:** [December 15, 2022, 12:52pm UTC](https://discuss.elastic.co/t/unable-to-use-the-replace-filter-on-filebeat-yml/321305/2 "2022-12-15T12:52:47Z")

</div>

I guess you mentioned replace again in the 5th line of your code. It should be replacement instead of replace.

That is what I can see which is given in the Elastic Documentation.

> **[Replace fields from events | Filebeat Reference \[master\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/master/replace-fields.html)**

List of one or more items. Each item contains a `field: field-name`, `pattern: regex-pattern`, and `replacement: replacement-string`, where:

- `field` is the original field name. You can use the `@metadata.` prefix in this field to replace values in the event metadata instead of event fields.
- `pattern` is the regex pattern to match the field’s value
- `replacement` is the replacement string to use to update the field’s value

The following example changes the path from /usr/bin to /usr/local/bin:

```auto
 - replace:
      fields:
        - field: "file.path"
          pattern: "/usr/"
          replacement: "/usr/local/"
      ignore_missing: false
      fail_on_error: true

```

---

<div class="post-metadata">

**Author:** ![maviles](https://avatars.discourse-cdn.com/v4/letter/m/ccd318/32.png) [@maviles](https://discuss.elastic.co/u/maviles)\
**Post date:** [December 15, 2022, 2:18pm UTC](https://discuss.elastic.co/t/unable-to-use-the-replace-filter-on-filebeat-yml/321305/3 "2022-12-15T14:18:10Z")

</div>

Greetings, I made the changes as stated on the previous Reply. I got this message:

"Failed to replace fields in processor: could not fetch value for key: decoded.cef.severity, Error: key not found"

---

<div class="post-metadata">

**Author:** ![dadiasish](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadiasish/32/114221_2.png) [@dadiasish](https://discuss.elastic.co/u/dadiasish)\
**Post date:** [December 15, 2022, 2:23pm UTC](https://discuss.elastic.co/t/unable-to-use-the-replace-filter-on-filebeat-yml/321305/4 "2022-12-15T14:23:07Z")

</div>

Can you send the whole filebeat configuration file to get a better idea?

---

<div class="post-metadata">

**Author:** ![maviles](https://avatars.discourse-cdn.com/v4/letter/m/ccd318/32.png) [@maviles](https://discuss.elastic.co/u/maviles)\
**Post date:** [December 15, 2022, 5:44pm UTC](https://discuss.elastic.co/t/unable-to-use-the-replace-filter-on-filebeat-yml/321305/6 "2022-12-15T17:44:26Z")

</div>

# ============================== Filebeat inputs ===============================

filebeat.inputs:

- type: log  
enabled: true  
paths:
  - "C:/Users/admin/Desktop/Syslog-Watcher-Cortex/\*.txt"

# Paths that should be crawled and fetched. Glob based paths.

scan\_frequency: 20s

# ============================== Filebeat modules ==============================

filebeat.config.modules:

# Glob pattern for configuration loading

path: ${path.config}/modules.d/\*.yml

# Set to true to enable config reloading

reload.enabled: true

# Period on which files under path should be checked for changes

reload.period: 30s

# ======================= Elasticsearch template setting =======================

setup.template.settings:  
index.number\_of\_shards: 1

# ================================== General ===================================

name: XXXX\_CortexProbe2.0  
tags: ["XXXX\_CortexEvents2", "Cortex", "forwarded"]

# =================================== Kibana ===================================

# Starting with Beats version 6.0.0, the dashboards are loaded via the Kibana API.

# This requires a Kibana endpoint configuration.

setup.kibana:

# Kibana Host

# ================================== Outputs ===================================

# Configure what output to use when sending the data collected by the beat.

# ---------------------------- Elasticsearch Output ----------------------------

output.elasticsearch:  
hosts: ["XXXX:9200"]  
protocol: "https"  
username: "XXXX"  
password: XXXX

# ================================= Processors =================================

processors:

- rename:  
fields:

- {from: "message", to: "event.original"}

- decode\_cef:  
field: event.original  
target\_field: decoded.cef  
ignore\_missing: true  
ignore\_failure: true
- timestamp:  
field: decoded.cef.extensions.endTime  
layouts:

- '2006-01-02T15:04:05Z'  
test:
- '2022-12-13T16:52:26.510079Z'

- drop\_fields:  
fields: [decoded.cef.extensions.endTime]
- replace:  
fields:

- field: "decoded.cef.severity"  
pattern: "8"  
replacement: "8/Medium"  
ignore\_missing: false  
fail\_on\_error: true

# ============================= X-Pack Monitoring ==============================

monitoring.enabled: true

# ================================== Logging ===================================

# Sets log level. The default log level is info.

# Available log levels are: error, warning, info, debug

#logging.level: debug

# At debug level, you can selectively enable logging only for some components.

# To enable all selectors use ["\*"]. Examples of other selectors are "beat",

# "publisher", "service".

#logging.selectors: ["\*"]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 12, 2023, 5:44pm UTC](https://discuss.elastic.co/t/unable-to-use-the-replace-filter-on-filebeat-yml/321305/7 "2023-01-12T17:44:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
