# Zeek Filebeat Module to Logstash JSON

**URL:** <https://discuss.elastic.co/t/zeek-filebeat-module-to-logstash-json/200539>\
**Category:** Logstash\
**Created:** [September 21, 2019, 5:11pm UTC](https://discuss.elastic.co/t/zeek-filebeat-module-to-logstash-json/200539 "2019-09-21T17:11:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![millap](https://avatars.discourse-cdn.com/v4/letter/m/3ec8ea/32.png) [@millap](https://discuss.elastic.co/u/millap)\
**Post date:** [September 21, 2019, 5:11pm UTC](https://discuss.elastic.co/t/zeek-filebeat-module-to-logstash-json/200539/1 "2019-09-21T17:11:54Z")

</div>

Hi All,

I wonder if anyone can offer any assistance. We've recently moved to using the Zeek Filebeat module on some remote sensors, as these integrate nicely with the SIEM feature of Kibana, however, the old function we had was sending CSV separated log data to Logstash and performing a large amount of enrichment on the data (GeoIP, Threat Intel Lookup, MAC OUI Lookup, etc, etc) before writing to an index. With the Zeek Filebeat module, we've lost that, so I'd like to #1 revert to using Logstash for enrichment, but #2 keep the Zeek module enabled.

When we send it to LS via FB, we get this type of warning -

```
[2019-09-21T17:49:54,439][DEBUG][o.e.a.b.TransportShardBulkAction] [es00] [logstash-2019.09.19-000001][0] failed to execute bulk item (index) index {[logstash][_doc][fU66VG0BWPgQZ2342ET9], source[{"@version":"1","fileset":{"name":"files"},"tags":["zeek.files","beats_input_raw_event"],"input":{"type":"log"},"service":{"type":"zeek"},"ecs":{"version":"1.0.1"},"zeek":{"files":{"missing_bytes":0,"duration":0,"timedout":false,"fuid":"FXQTiFzy14jm29p6l","seen_bytes":868,"tx_hosts":["172.16.10.154"],"md5":"82f856eb911b56cda74a076050ab480c","rx_hosts":["10.10.10.12"],"overflow_bytes":0,"mime_type":"application/x-x509-user-cert","depth":0,"sha1":"f7413b5ec1ba603e956cb1d0ebb6c6cf78477c7b","ts":1.569084593217552E9,"is_orig":false,"session_ids":["CSADZt1R3oG5hdSrUe"],"source":"SSL","local_orig":false,"analyzers":["SHA1","X509","MD5"]}},"agent":{"hostname":"0030180d3ce2","id":"6c4646f2-9580-4103-bc9a-4a4177bb9cef","version":"7.3.2","ephemeral_id":"ffad8e9c-b6f0-4a49-959d-8396b68a814f","type":"filebeat"},"log":{"offset":11902874,"file":{"path":"/var/log/bro/current/files.log"}},"host":{"hostname":"0030180d3ce2","os":{"codename":"kali-rolling","platform":"kali","version":"2019.4","kernel":"5.2.0-kali2-amd64","name":"Kali GNU/Linux","family":""},"containerized":false,"id":"ebbd901b30924f1fbbc0e115cb822857","architecture":"x86_64","name":"0030180d3ce2"},"event":{"dataset":"zeek.files","module":"zeek"},"@timestamp":"2019-09-21T16:49:54.240Z"}]}org.elasticsearch.index.mapper.MapperParsingException: failed to parse field [service] of type [text] in document with id 'fU66VG0BWPgQZ2342ET9'. Preview of field's value: '{type=zeek}'

```

Any ideas on how to fix that?

Cheers  
Andy

---

<div class="post-metadata">

**Author:** ![millap](https://avatars.discourse-cdn.com/v4/letter/m/3ec8ea/32.png) [@millap](https://discuss.elastic.co/u/millap)\
**Post date:** [September 24, 2019, 6:43pm UTC](https://discuss.elastic.co/t/zeek-filebeat-module-to-logstash-json/200539/2 "2019-09-24T18:43:09Z")

</div>

Hi All,

Problem fixed. The output was using logstash-\* rather than filebeat-\*.

Andy

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 22, 2019, 6:43pm UTC](https://discuss.elastic.co/t/zeek-filebeat-module-to-logstash-json/200539/3 "2019-10-22T18:43:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
