# Adding Custom processors with Elastic-Agent

**URL:** <https://discuss.elastic.co/t/adding-custom-processors-with-elastic-agent/324958>\
**Category:** Elastic Agent\
**Created:** [February 8, 2023, 3:00am UTC](https://discuss.elastic.co/t/adding-custom-processors-with-elastic-agent/324958 "2023-02-08T03:00:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [February 8, 2023, 3:00am UTC](https://discuss.elastic.co/t/adding-custom-processors-with-elastic-agent/324958/1 "2023-02-08T03:00:08Z")

</div>

Hi,

I wrote a custom parser with dissect processor for collecting fail2ban-logs. Those are working fine for the servers where logs are being collected using filebeat however I am not sure how do I add those with where I have Elastic-Agent installed?

Any clue please?

TIA

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 8, 2023, 3:09am UTC](https://discuss.elastic.co/t/adding-custom-processors-with-elastic-agent/324958/2 "2023-02-08T03:09:26Z")

</div>

Are you parsing in the processors in the filebeat or an ingest pipeline?

Are you using the Custom Logs Integration with the Agent?

You can use the Custom Logs Integration -\> Advanced -\> Processors

 ![Screen Shot 2023-02-07 at 7.07.29 PM](https://us1.discourse-cdn.com/elastic/original/3X/c/8/c8532c595d394f9023fb039099fe4c20f49a4b02.png)

 ![Screen Shot 2023-02-07 at 7.07.42 PM](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7eca8b337d9cafecb329468a16dcbde31fb22e6b.png)

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [February 8, 2023, 3:27am UTC](https://discuss.elastic.co/t/adding-custom-processors-with-elastic-agent/324958/3 "2023-02-08T03:27:15Z")

</div>

Nope I am ingesting the logs with filebeat and parsing with processor. I used dissect processor and wondering how do I replicate with servers using elatic-agent?

Since Elastic-Agent is using filebeat in the background wondering if I could modifty that config and pickup and parse the logs using my processor? My logs are being dumped in /var/log/fail2ban.log and here are my dissec\_processor

```auto
filebeat.inputs:
- type: log
  paths:
    - /var/log/fail2ban.log
  processors:
    - drop_event:
       when:
         contains:
           message: INFO
    - dissect:
        tokenizer: '%{timestamp} fail2ban.actions %{process.pid}: NOTICE %{application|string} %{action|string} %{source.ip|ip}'
        field: "message"

```

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [February 8, 2023, 3:47am UTC](https://discuss.elastic.co/t/adding-custom-processors-with-elastic-agent/324958/4 "2023-02-08T03:47:20Z")

</div>

Thanks that resolved the issue 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 8, 2023, 3:47am UTC](https://discuss.elastic.co/t/adding-custom-processors-with-elastic-agent/324958/5 "2023-03-08T03:47:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
