Log file content fieldsedit

Contains log file lines.

sourceedit

type: keyword

required: True

The file from which the line was read. This field contains the absolute path to the file. For example: /var/log/system.log.

offsetedit

type: long

required: False

The file offset the reported line starts at.

messageedit

type: text

required: True

The content of the line read from the log file.

streamedit

type: keyword

required: False

Log stream when reading container logs, can be stdout or stderr

prospector.typeedit

required: True

The prospector type from which the event was generated. This field is set to the value specified for the type option in the prospector section of the Filebeat config file.

read_timestampedit

In case the ingest pipeline parses the timestamp from the log contents, it stores the original @timestamp (representing the time when the log line was read) in this field.

fileset.moduleedit

The Filebeat module that generated this event.

fileset.nameedit

The Filebeat fileset that generated this event.