WARNING: Version 5.4 of Filebeat has passed its EOL date.
This documentation is no longer being maintained and may be removed. If you are running this version, we strongly advise you to upgrade. For the latest information, see the current release documentation.
Log File Content Fields
editLog File Content Fields
editContains log file lines.
source
edittype: keyword
required: True
The file from which the line was read. This field contains the absolute path to the file. For example: /var/log/system.log
.
offset
edittype: long
required: False
The file offset the reported line starts at.
message
edittype: text
required: True
The content of the line read from the log file.
type
editrequired: True
The name of the log event. This field is set to the value specified for the document_type
option in the prospector section of the Filebeat config file.
input_type
editrequired: True
The input type from which the event was generated. This field is set to the value specified for the input_type
option in the prospector section of the Filebeat config file.
error
editIngestion pipeline error message, added in case there are errors reported by the Ingest Node in Elasticsearch.
read_timestamp
editIn case the ingest pipeline parses the timestamp from the log contents, it stores the original @timestamp
(representing the time when the log line was read) in this field.
fileset.module
editThe Filebeat module that generated this event.
fileset.name
editThe Filebeat fileset that generated this event.