WARNING: Version 5.6 of Filebeat has passed its EOL date.
This documentation is no longer being maintained and may be removed. If you are running this version, we strongly advise you to upgrade. For the latest information, see the current release documentation.
Contains log file lines.
The file from which the line was read. This field contains the absolute path to the file. For example:
The file offset the reported line starts at.
The content of the line read from the log file.
The name of the log event. This field is set to the value specified for the
document_type option in the prospector section of the Filebeat config file.
The input type from which the event was generated. This field is set to the value specified for the
input_type option in the prospector section of the Filebeat config file.
Ingestion pipeline error message, added in case there are errors reported by the Ingest Node in Elasticsearch.
In case the ingest pipeline parses the timestamp from the log contents, it stores the original
@timestamp (representing the time when the log line was read) in this field.
The Filebeat module that generated this event.
The Filebeat fileset that generated this event.