# Creating a filebeat module

**URL:** <https://discuss.elastic.co/t/creating-a-filebeat-module/287413>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [October 22, 2021, 8:51am UTC](https://discuss.elastic.co/t/creating-a-filebeat-module/287413 "2021-10-22T08:51:45Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticfran](https://avatars.discourse-cdn.com/v4/letter/e/e47c2d/32.png) [@elasticfran](https://discuss.elastic.co/u/elasticfran)\
**Post date:** [October 22, 2021, 8:51am UTC](https://discuss.elastic.co/t/creating-a-filebeat-module/287413/1 "2021-10-22T08:51:45Z")

</div>

Hey there!

I am trying to write a custom filebeat module, which are the proper guidelines to follow ?

Found [Creating a New Beat | Beats Developer Guide [7.12] | Elastic](https://www.elastic.co/guide/en/beats/devguide/7.12/new-beat.html) which i find pretty comprehensive but i wonder whether there s another way to do it coz i cant use golang.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![bertr](https://avatars.discourse-cdn.com/v4/letter/b/e495f1/32.png) [@bertr](https://discuss.elastic.co/u/bertr)\
**Post date:** [October 22, 2021, 9:21am UTC](https://discuss.elastic.co/t/creating-a-filebeat-module/287413/2 "2021-10-22T09:21:27Z")

</div>

As far as I know you have to use golang unless you really want to mimic everything that you get 'for free' (e.g. config file processing, output processing, parallel processing etc etc) in another comprehensive language. My advice: don't even think about it, learning golang is a lot easier than you think (it's just another programming language) and definitely a lot easier then rewriting everything in any other language.

Just my two cents

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [October 22, 2021, 12:12pm UTC](https://discuss.elastic.co/t/creating-a-filebeat-module/287413/3 "2021-10-22T12:12:03Z")

</div>

If u just want to create a new module for filebeat, u don't need to know any Golang. Just yaml files in the correct location. If u want to make a custom Beat, then yes it's all Golang.

---

<div class="post-metadata">

**Author:** ![elasticfran](https://avatars.discourse-cdn.com/v4/letter/e/e47c2d/32.png) [@elasticfran](https://discuss.elastic.co/u/elasticfran)\
**Post date:** [October 22, 2021, 12:44pm UTC](https://discuss.elastic.co/t/creating-a-filebeat-module/287413/4 "2021-10-22T12:44:22Z")

</div>

Yes, would be a new module for filebeat ! Is there an official procedure for the yaml files? THANKS

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [October 22, 2021, 1:44pm UTC](https://discuss.elastic.co/t/creating-a-filebeat-module/287413/5 "2021-10-22T13:44:29Z")

</div>

See [Creating a New Filebeat Module | Beats Developer Guide [master] | Elastic](https://www.elastic.co/guide/en/beats/devguide/current/filebeat-modules-devguide.html)

---

<div class="post-metadata">

**Author:** ![elasticfran](https://avatars.discourse-cdn.com/v4/letter/e/e47c2d/32.png) [@elasticfran](https://discuss.elastic.co/u/elasticfran)\
**Post date:** [October 22, 2021, 1:52pm UTC](https://discuss.elastic.co/t/creating-a-filebeat-module/287413/6 "2021-10-22T13:52:49Z")

</div>

Thanks.

If i run the command make create-module MODULE=xyz i get:

![image](https://us1.discourse-cdn.com/elastic/original/3X/8/5/85b667658e022af3d5cad52f1a31803021c0a34c.png)

Assume it s related to Go which i dont have and can t have on my system ☹

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [October 22, 2021, 2:14pm UTC](https://discuss.elastic.co/t/creating-a-filebeat-module/287413/7 "2021-10-22T14:14:25Z")

</div>

If u can't have Golang installed on your system, if u have Filebeat installed already u can manually add the Yaml files for the module/filesets in like `/usr/lib/filebeat...` or something like that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 19, 2021, 4:14pm UTC](https://discuss.elastic.co/t/creating-a-filebeat-module/287413/8 "2021-11-19T16:14:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
