Customize fields in filebeat for graylog

I am able to send the logs in graylog now but all fields are showing filebeat defaults fields as per below screenshot…

I want fields like below screenshot…

image

I have configure it in filebeat.yml but my customize fields and getting updated in Graylog and it is showing all default filebeat fields.

filebeat.yml:

fields_under_root: true
fields.collector_node_id: ip-10-140-126-132.ap-southeast-1.compute.internal
fields.gl2_source_collector: 15709c79-2569-43bc-8679-4166fdd6dcb0


filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /data/logs/changeevent/server.log
  prospectors:
  fields:
     Application: Glassfish
     Buildingblock: changeevent
     Environment: Development
     Source: 10.140.126.132
     input_type: log
     ignore_older: 0
     scan_frequency: 10s
     tail_files: true
output.logstash:
   hosts: ["10.140.127.133:5044"]
path:
  data: /var/lib/graylog-sidecar/collectors/filebeat/data
  logs: /var/lib/graylog-sidecar/collectors/filebeat/log

please check and let me know where i am missing.

It’s at the bottom of your Beats Input.
image

Thank You!!
It is working but their are many fields are there which i do not want like below screenshot…

image

Now Fields is getting appended with my customize fields…

image

Thank you for your help.

https://www.elastic.co/guide/en/beats/filebeat/current/migration-changed-fields.html

Thank You!!!
My second problem is resolved. Now fields prefix is not getting appended.
Still filebeat fields are their which i don’t want. I am trying to find out the way if i can drop these unwanted fields. I checked many article they are suggesting to create the pipeline but pipeline is come into the picture when filebeat send the data. is their any way i can use in filebeat only and do not send filebeat defaults fields to graylog?

here are the unwanted fields…

image

image

Thank You for the help!!!

you could create a processing pipeline that drops messages you do not want to have.

Even the rename could be possible in graylog …

1 Like

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.