# What is the difference between processor add\_fields and regular "fields:"

**URL:** <https://discuss.elastic.co/t/what-is-the-difference-between-processor-add-fields-and-regular-fields/205662>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 29, 2019, 12:13pm UTC](https://discuss.elastic.co/t/what-is-the-difference-between-processor-add-fields-and-regular-fields/205662 "2019-10-29T12:13:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![john\_eapen](https://avatars.discourse-cdn.com/v4/letter/j/b3f665/32.png) [@john\_eapen](https://discuss.elastic.co/u/john_eapen)\
**Post date:** [October 29, 2019, 12:13pm UTC](https://discuss.elastic.co/t/what-is-the-difference-between-processor-add-fields-and-regular-fields/205662/1 "2019-10-29T12:13:40Z")

</div>

I am using filebeat (docker 7.4.1).

1)What is the difference between processor add\_fields and regular "fields:"

1. Also, I am using autodiscover for nginx/mongo containers AND regular filebeat.input of type container for all other container logs. I do not have a very good inbuilt field/property to differentiate between these two types so that I can exclude autodiscover containers from regular filebeat input of type containers.  
Is there a good way to achieve this? Therefore I was wondering if I could add a custom field to be used in include\_lines.

Appreciate any pointers.  
thx

---

<div class="post-metadata">

**Author:** ![B.M](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/b.m/32/56771_2.png) [@B.M](https://discuss.elastic.co/u/B.M)\
**Post date:** [October 29, 2019, 1:15pm UTC](https://discuss.elastic.co/t/what-is-the-difference-between-processor-add-fields-and-regular-fields/205662/2 "2019-10-29T13:15:29Z")

</div>

Here are 2 links to answer your question [add\_fields](https://www.elastic.co/guide/en/beats/filebeat/current/add-fields.html), [fields](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-general-options.html#libbeat-configuration-fields)

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [October 29, 2019, 3:19pm UTC](https://discuss.elastic.co/t/what-is-the-difference-between-processor-add-fields-and-regular-fields/205662/3 "2019-10-29T15:19:58Z")

</div>

1. When you are defining processors with complex conditionals, you can use `add_fields` processor. However, `fields` are always added to events.

2. You can tag events by input using `fields`. Note that fields are added to events after `include_lines` are applied. So it won't have any impact on your event processing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 26, 2019, 3:20pm UTC](https://discuss.elastic.co/t/what-is-the-difference-between-processor-add-fields-and-regular-fields/205662/4 "2019-11-26T15:20:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
