# Add\_tags processor in Filebeat panw module

**URL:** <https://discuss.elastic.co/t/add-tags-processor-in-filebeat-panw-module/238745>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [June 25, 2020, 6:40pm UTC](https://discuss.elastic.co/t/add-tags-processor-in-filebeat-panw-module/238745 "2020-06-25T18:40:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![zombiebrak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zombiebrak/32/71189_2.png) [@zombiebrak](https://discuss.elastic.co/u/zombiebrak)\
**Post date:** [June 25, 2020, 6:40pm UTC](https://discuss.elastic.co/t/add-tags-processor-in-filebeat-panw-module/238745/1 "2020-06-25T18:40:56Z")

</div>

I am trying to implement the add\_tags processor within the panw Filebeat module, but Filebeat fails with the error:

Exiting: each processor must have exactly one action, but found 2 actions (add\_locale,add\_tags)

add\_locale isn't implemented within any other modules or filebeat.yml. I am able to get the add\_tags processor to work in other modules.

```auto
#Module: panw
# Docs: https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-module-panw.html

- module: panw
  panos:
    enabled: true

    # Set which input to use between syslog (default) or file.
    var.input: "file"

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    var.paths: ["/var/log/logname.log"]

    input:
      processors:
        - add_tags:
            tags: [panw]

```

Is there something I'm doing wrong or is there a potential issue with the panw Filebeat module?

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [June 26, 2020, 9:13am UTC](https://discuss.elastic.co/t/add-tags-processor-in-filebeat-panw-module/238745/2 "2020-06-26T09:13:35Z")

</div>

Did you try to use single `processors` field instead of `input.processors`?

---

<div class="post-metadata">

**Author:** ![zombiebrak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zombiebrak/32/71189_2.png) [@zombiebrak](https://discuss.elastic.co/u/zombiebrak)\
**Post date:** [June 26, 2020, 3:06pm UTC](https://discuss.elastic.co/t/add-tags-processor-in-filebeat-panw-module/238745/3 "2020-06-26T15:06:42Z")

</div>

I did try that (assuming I did it correctly), which did not throw an error, however, the panw documents do not get tagged.

```auto
#Module: panw
# Docs: https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-module-panw.html

- module: panw
  panos:
    enabled: true

    # Set which input to use between syslog (default) or file.
    var.input: "file"

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    var.paths: ["/var/log/logname.log"]

    processors:
      - add_tags:
          tags: [panw]

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2020, 5:07pm UTC](https://discuss.elastic.co/t/add-tags-processor-in-filebeat-panw-module/238745/4 "2020-07-24T17:07:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
