Unindex fields - how to index this fields

I use grok filtering to parse Cisco syslog file. Has you see in the capture screen i create new field with the end "_dan" . But thoses fiels are not index. I cannot find the way to index these fields.

Need help how to do it .


What does the mapping for the index look like?

I use filebeat to read a syslog file and transfer to logstash.
In logstash, i use grok for filtering and a pattern file for my *_dan fields.

HI found my problem
Everything is o.k.

need this in logstash conf file "output section"

output {
elasticsearch {
hosts => [""]
manage_template => false
index => "filebeat-%{+YYYY.MM.dd}"
document_type => "log"
stdout { codec => rubydebug }

and create the filebeat index :
curl -XPUT '' -d@/etc/filebeat/filebeat.template.json


