# Custom beat - re-use Filebeat log readers?

**URL:** <https://discuss.elastic.co/t/custom-beat-re-use-filebeat-log-readers/48868>\
**Category:** Beats\
**Tags:** beats-development\
**Created:** [April 30, 2016, 4:36pm UTC](https://discuss.elastic.co/t/custom-beat-re-use-filebeat-log-readers/48868 "2016-04-30T16:36:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jason26](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jason26/32/54948_2.png) [@jason26](https://discuss.elastic.co/u/jason26)\
**Post date:** [April 30, 2016, 4:36pm UTC](https://discuss.elastic.co/t/custom-beat-re-use-filebeat-log-readers/48868/1 "2016-04-30T16:36:39Z")

</div>

I'm creating a new beat application, primarily to remove the logstash requirements for getting this data into Elastic Search. The file being read is new line delimited JSON, and gets rotated by logrotate.

Anyone reusing filebeat code for the "tailing" and "registry" tracking in their custom beat applications? Or should I just roll my own.

Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 30, 2016, 4:39pm UTC](https://discuss.elastic.co/t/custom-beat-re-use-filebeat-log-readers/48868/2 "2016-04-30T16:39:15Z")

</div>

> primarily to remove the logstash requirements for getting this data into Elastic Search.

You are aware of Filebeat's ability to send data directly to ES, right?

---

<div class="post-metadata">

**Author:** ![jason26](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jason26/32/54948_2.png) [@jason26](https://discuss.elastic.co/u/jason26)\
**Post date:** [April 30, 2016, 5:22pm UTC](https://discuss.elastic.co/t/custom-beat-re-use-filebeat-log-readers/48868/3 "2016-04-30T17:22:01Z")

</div>

As JSON? Last I tried it sent to the JSON as text lines. I had to run it through Logstash to be added as JSON. Has this been changed?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 30, 2016, 9:18pm UTC](https://discuss.elastic.co/t/custom-beat-re-use-filebeat-log-readers/48868/4 "2016-04-30T21:18:52Z")

</div>

Filebeat 5.0 alpha1 adds json per line support. The JSON is parsed and send as event to elasticsearch. Try console output with `pretty: true` to check out your events. Even better, Elasticsearch 5.0 will have Ingest-Node adding some filtering/parsing capabilities to Elasticsearch input.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:52pm UTC](https://discuss.elastic.co/t/custom-beat-re-use-filebeat-log-readers/48868/5 "2017-07-05T21:52:39Z")

</div>


