# Auditbeat javascript processor error with v9.2.3

**URL:** <https://discuss.elastic.co/t/auditbeat-javascript-processor-error-with-v9-2-3/384188>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [December 18, 2025, 11:37pm UTC](https://discuss.elastic.co/t/auditbeat-javascript-processor-error-with-v9-2-3/384188 "2025-12-18T23:37:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![grants](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grants/32/117040_2.png) [@grants](https://discuss.elastic.co/u/grants)\
**Post date:** [December 18, 2025, 11:37pm UTC](https://discuss.elastic.co/t/auditbeat-javascript-processor-error-with-v9-2-3/384188/1 "2025-12-18T23:37:37Z")

</div>

Any idea what could be wrong with my processor?

- Version: 9.2.3
- Operating System: ubuntu 22.04 LTS
- Steps to Reproduce: Processor listed below

Setting up auditbeat on a new host encountered an error with a config I know works. Went to a host running 9.2.2 with the same config running and everything was working fine, ran apt upgrade to version 9.2.3 and it fails to start with the same error.

Next I started removing custom parts of my config and ended up finding this single processor that worked in 9.2.2 but throws this error in 9.2.3

```auto
  - script:
      when.and:
        - equals.auditd.message_type: syscall
        - has_fields: ['event.original']
      type: javascript
      lang: javascript
      id: parse_syscall_kvs
      source: >
        function process(event) {
          var original = event.Get("event.original");
          if (!original) return;

          for (var i = 0; i < original.length; i++) {
            var line = original[i];
            if (line.indexOf("type=SYSCALL") === 0) {
              var parts = line.split(":", 3);
              if (parts.length < 3) return;

              var kvString = parts[2].replace(/^\s+/, '');
              var pairs = kvString.split(" ");
              var result = {};
              for (var j = 0; j < pairs.length; j++) {
                var kv = pairs[j].split("=");
                if (kv.length == 2) {
                  var key = kv[0];
                  var value = kv[1].replace(/^"|"$/g, ""); // Remove surrounding quotes
                  result[key] = value;
                }
              }
              event.Put("auditd.syscall", result);
              break;
            }
          }
        }

```

```auto
{
  "log.level": "error",
  "@timestamp": "2025-12-18T17:17:23.744-0600",
  "log.origin": {
    "function": "github.com/elastic/beats/v7/libbeat/cmd/instance.handleError",
    "file.name": "instance/beat.go",
    "file.line": 1364
  },
  "message": "Exiting: failed setting paths for global processors: attempt to set paths twice",
  "service.name": "auditbeat",
  "ecs.version": "1.6.0"
}

```

Version:

```auto
auditbeat version 9.2.3 (amd64), libbeat 9.2.3 [b95cc76490c9bb4184f98e0094be4af14b5d7bd2 built 2025-12-16 08:47:58 +0000 UTC] (FIPS-distribution: false)

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [December 19, 2025, 12:30am UTC](https://discuss.elastic.co/t/auditbeat-javascript-processor-error-with-v9-2-3/384188/2 "2025-12-19T00:30:24Z")

</div>

This sounds like a bug. I checked the source code and looked at the git history, and I see there was a recent change to this code.

> <https://github.com/elastic/beats/pull/47870>
>
> \## Proposed commit message
> Changes:
> \- Add SetPaths(path \*paths.Path) method to… jsProcessor that accepts a per-beat paths configuration
> \- Defer file-based source initialization until SetPaths is called
> \- For inline sources, initialization still happens immediately in NewFromConfig
> \- loadSources now takes a \*paths.Path parameter and uses pathConfig.Resolve() instead of the global paths.Resolve()
> 
> Fixes https://github.com/elastic/beats/issues/46988
> 
> \## Checklist
> \- \[x\] My code follows the style guidelines of this project
> \- \[x\] I have commented my code, particularly in hard-to-understand areas
> \- \[\] ~~I have made corresponding changes to the documentation~~
> \- \[\] ~~I have made corresponding change to the default configuration files~~
> \- \[x\] I have added tests that prove my fix is effective or that my feature works. Where relevant, I have used the \[\`stresstest.sh\`\](https://github.com/elastic/beats/blob/main/script/stresstest.sh) script to run them under stress conditions and race detector to verify their stability.
> \- \[\] ~~I have added an entry in \`./changelog/fragments\` using the \[changelog tool\](https://github.com/elastic/elastic-agent-changelog-tool/blob/main/docs/usage.md).~~
> 
> \## How to test this PR locally
> 
> Run filebeat with:
> 
> \`\`\`yaml
> path.config: myconfig/
> 
> filebeat.inputs:
> - type: filestream
> id: input-a
> paths:
> - /tmp/logs/a.log
> 
> processors:
> - script:
> lang: javascript
> file: test\_processor.js
> tag: test-js-processor
> 
> output.console:
> enabled: true
> \`\`\`
> 
> \`myconfig/test\_processor.js\`:
> \`\`\`js
> function process(event) {
> event.Put("js\_processor.processed", true);
> event.Put("js\_processor.timestamp", new Date().toISOString());
> 
> var msg = event.Get("message");
> if (msg) {
> event.Put("message\_upper", msg.toUpperCase());
> }
> 
> return event;
> }
> \`\`\`
> 
> write some logs:
> \`\`\`sh
> yes 'some log' | head -n 10000 \> /tmp/logs/a.log
> \`\`\`
> 
> See output:
> \`\`\`json
> {
> "@timestamp": "2025-12-02T18:09:36.488Z",
> "@metadata": {
> "beat": "filebeat",
> "type": "\_doc",
> "version": "9.3.0"
> },
> "ecs": {
> "version": "8.0.0"
> },
> "log": {
> "offset": 89586,
> "file": {
> "path": "/tmp/logs/a.log",
> "device\_id": "38",
> "inode": "73159",
> "fingerprint": "83016ba24a8d31ccb16d2230eabcb1f043fa4c65914339eb954619b5c13fd55a"
> }
> },
> "message": "some log",
> "input": {
> "type": "filestream"
> },
> "js\_processor": {
> "processed": true,
> "timestamp": "2025-12-02T18:09:36.488Z"
> },
> "message\_upper": "SOME LOG",
> "host": {
> "name": "laptop"
> },
> "agent": {
> "version": "9.3.0",
> "ephemeral\_id": "f6bb5c64-d2d1-4dad-a0e1-bbc553b617ec",
> "id": "40aef7d0-efcb-4613-a1df-d9bc42ff36b9",
> "name": "laptop",
> "type": "filebeat"
> }
> }
> \`\`\`
> 
> \## Related issues
> 
> \- Closes #46988
> \- Relates #47353

Can you please open a new bug issue in the [GitHub - elastic/beats: 🐠 Beats - Lightweight shippers for Elasticsearch & Logstash](http://GitHub.com/Elastic/Beats) repo?

---

<div class="post-metadata">

**Author:** ![grants](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grants/32/117040_2.png) [@grants](https://discuss.elastic.co/u/grants)\
**Post date:** [December 19, 2025, 12:48am UTC](https://discuss.elastic.co/t/auditbeat-javascript-processor-error-with-v9-2-3/384188/3 "2025-12-19T00:48:04Z")

</div>

Sure:

> <https://github.com/elastic/beats/issues/48193>
>
> Please post all questions and issues on https://discuss.elastic.co/c/beats
> befor…e opening a Github Issue. Your questions will reach a wider audience there,
> and if we confirm that there is a bug, then you can open a new issue.
> 
> For security vulnerabilities please only send reports to security@elastic.co.
> See https://www.elastic.co/community/security for more information.
> 
> Please include configurations and logs if available.
> 
> For confirmed bugs, please report:
> \- Version: 9.2.3
> \- Operating System: ubuntu 22.04 LTS
> \- Discuss Forum URL: https://discuss.elastic.co/t/auditbeat-javascript-processor-error-with-v9-2-3/384188
> \- Steps to Reproduce: Processor listed below
> 
> Setting up auditbeat on a new host encountered an error with a config I know works. Went to a host running 9.2.2 with the same config running and everything was working fine, ran apt upgrade to version 9.2.3 and it fails to start with the same error. 
> 
> Next I started removing custom parts of my config and ended up finding this single processor that worked in 9.2.2 but throws this error in 9.2.3
> 
> \`\`\`
> - script:
> when.and:
> - equals.auditd.message\_type: syscall
> - has\_fields: \['event.original'\]
> type: javascript
> lang: javascript
> id: parse\_syscall\_kvs
> source: \>
> function process(event) {
> var original = event.Get("event.original");
> if (!original) return;
> 
> for (var i = 0; i \< original.length; i++) {
> var line = original\[i\];
> if (line.indexOf("type=SYSCALL") === 0) {
> var parts = line.split(":", 3);
> if (parts.length \< 3) return;
> 
> var kvString = parts\[2\].replace(/^\\s+/, '');
> var pairs = kvString.split(" ");
> var result = {};
> for (var j = 0; j \< pairs.length; j++) {
> var kv = pairs\[j\].split("=");
> if (kv.length == 2) {
> var key = kv\[0\];
> var value = kv\[1\].replace(/^"|"$/g, ""); // Remove surrounding quotes
> result\[key\] = value;
> }
> }
> event.Put("auditd.syscall", result);
> break;
> }
> }
> }
> \`\`\`
> 
> \`\`\`
> {
> "log.level": "error",
> "@timestamp": "2025-12-18T17:17:23.744-0600",
> "log.origin": {
> "function": "github.com/elastic/beats/v7/libbeat/cmd/instance.handleError",
> "file.name": "instance/beat.go",
> "file.line": 1364
> },
> "message": "Exiting: failed setting paths for global processors: attempt to set paths twice",
> "service.name": "auditbeat",
> "ecs.version": "1.6.0"
> }
> \`\`\`
> Version:
> \`\`\`
> auditbeat version 9.2.3 (amd64), libbeat 9.2.3 \[b95cc76490c9bb4184f98e0094be4af14b5d7bd2 built 2025-12-16 08:47:58 +0000 UTC\] (FIPS-distribution: false)
> \`\`\`
