# Custom filebeat processor

**URL:** <https://discuss.elastic.co/t/custom-filebeat-processor/248029>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 9, 2020, 2:37pm UTC](https://discuss.elastic.co/t/custom-filebeat-processor/248029 "2020-09-09T14:37:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![yoklmn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yoklmn/32/71255_2.png) [@yoklmn](https://discuss.elastic.co/u/yoklmn)\
**Post date:** [September 9, 2020, 2:37pm UTC](https://discuss.elastic.co/t/custom-filebeat-processor/248029/1 "2020-09-09T14:37:44Z")

</div>

Hello. I hard trying create my own plugin of filebeat's processor. I use filebeat v7.9.1 from official repository on **machine B** , CentOS 7.6.1810, CPU Intel Xeon E-2176G:  
`filebeat version 7.9.1 (amd64), libbeat 7.9.1 [ad823eca4cc74439d1a44351c596c12ab51054f5 built 2020-09-01 19:58:51 +0000 UTC]`

On **machine A,** CentOS 7.5.1804, CPU Intel Core i7-3770 I run these commands:

> yum install -y wget git gcc python python3  
> yum-config-manager --add-repo [https://download.docker.com/linux/centos/docker-ce.repo](https://download.docker.com/linux/centos/docker-ce.repo)  
> yum install -y docker-ce docker-ce-cli [containerd.io](http://containerd.io)  
> wget [https://golang.org/dl/go1.14.7.linux-amd64.tar.gz](https://golang.org/dl/go1.14.7.linux-amd64.tar.gz) #because [here](https://github.com/elastic/beats/blob/ad823eca4cc74439d1a44351c596c12ab51054f5/.go-version) described ver. 1.14.17  
> tar -C /usr/local -xzf go1.14.7.linux-amd64.tar.gz  
> export PATH=$PATH:/usr/local/go/bin  
> export GOPATH=~/go  
> export PATH=$PATH:$GOPATH/bin
> 
> go env  
> _GO111MODULE=""_  
> _GOARCH="amd64"_  
> _GOBIN=""_  
> _GOCACHE="/root/.cache/go-build"_  
> _GOENV="/root/.config/go/env"_  
> _GOEXE=""_  
> _GOFLAGS=""_  
> _GOHOSTARCH="amd64"_  
> _GOHOSTOS="linux"_  
> _GOINSECURE=""_  
> _GONOPROXY=""_  
> _GONOSUMDB=""_  
> _GOOS="linux"_  
> **GOPATH="/root/go"**  
> _GOPRIVATE=""_  
> _GOPROXY="[https://proxy.golang.org](https://proxy.golang.org),direct"_  
> **GOROOT="/usr/local/go"**  
> _GOSUMDB="[sum.golang.org](http://sum.golang.org)"_  
> _GOTMPDIR=""_  
> _GOTOOLDIR="/usr/local/go/pkg/tool/linux\_amd64"_  
> _GCCGO="gccgo"_  
> _AR="ar"_  
> _CC="gcc"_  
> _CXX="g++"_  
> _CGO\_ENABLED="1"_  
> _GOMOD="/root/go/src/github.com/elastic/beats/filebeat/processor/myplugin/go.mod"_  
> _CGO\_CFLAGS="-g -O2"_  
> _CGO\_CPPFLAGS=""_  
> _CGO\_CXXFLAGS="-g -O2"_  
> _CGO\_FFLAGS="-g -O2"_  
> _CGO\_LDFLAGS="-g -O2"_  
> _PKG\_CONFIG="pkg-config"_  
> _GOGCCFLAGS="-fPIC -m64 -pthread -fmessage-length=0 -fdebug-prefix-map=/tmp/go-build129916806=/tmp/go-build -gno-record-gcc-switches"_
> 
> go version  
> _go version go1.14.7 linux/amd64_
> 
> git clone [GitHub - elastic/beats: 🐠 Beats - Lightweight shippers for Elasticsearch & Logstash](https://github.com/elastic/beats) ${GOPATH}/src/github.com/elastic/beats  
> cd $GOPATH/src/github.com/elastic/beats  
> git checkout **ad823eca4cc74439d1a44351c596c12ab51054f5**  
> cd libbeat  
> make

Then I create folder _${GOPATH}/src/github.com/elastic/beats/libbeat/processors/myplugin/_ and put such files there:

_${GOPATH}/src/github.com/elastic/beats/libbeat/processors/myplugin/main.go_:

> package main
> 
> import (  
> "[github.com/elastic/beats/libbeat/plugin](http://github.com/elastic/beats/libbeat/plugin)"  
> "[github.com/elastic/beats/libbeat/processors](http://github.com/elastic/beats/libbeat/processors)"  
> )
> 
> var Bundle = plugin.Bundle(  
> processors.Plugin("myplugin", New),  
> )

and _${GOPATH}/src/github.com/elastic/beats/libbeat/processors/myplugin/myplugin.go_:

> package main
> 
> import (  
> "os"  
> "fmt"
> 
> "[github.com/elastic/beats/libbeat/beat](http://github.com/elastic/beats/libbeat/beat)"  
> "[github.com/elastic/beats/libbeat/common](http://github.com/elastic/beats/libbeat/common)"  
> "[github.com/elastic/beats/libbeat/processors](http://github.com/elastic/beats/libbeat/processors)"  
> )
> 
> type Myplugin struct {  
> }
> 
> func (f Myplugin) String() string {  
> return "Myplugin="  
> }
> 
> func New(c \*common.Config) (processors.Processor, error) {  
> return &Myplugin{  
> }, nil  
> }
> 
> func (f \*Myplugin) Run(event \*beat.Event) (\*beat.Event, error) {  
> l, err := event.GetValue("log.file.path")  
> if err != nil {  
> return nil, fmt.Errorf("fail getting log.file.path", err)  
> }
> 
> logfile := l.(string)
> 
> file, err := os.Stat(logfile)  
> modifiedtime := file.ModTime()
> 
> event.PutValue("event.log.file.timestamp", modifiedtime)  
> return event, nil  
> }

Then I run these commands:

> cp $GOPATH/src/github.com/elastic/beats/go.mod $GOPATH/src/github.com/elastic/beats/libbeat/processors/myplugin/  
> cp $GOPATH/src/github.com/elastic/beats/go.sum $GOPATH/src/github.com/elastic/beats/libbeat/processors/myplugin/  
> go build -buildmode=plugin

Then I copy compiled plugin to **machine B** and run command:

> /usr/bin/filebeat --plugin /etc/filebeat/myplugin.so

But I get these:

> Exiting: plugin.Open("/etc/filebeat/myplugin"): plugin was built with a different version of package [GitHub - pkg/errors: Simple error handling primitives](http://github.com/pkg/errors)

If I compile plugin with any of these commands:

> go build -buildmode=plugin -trimpath  
> go mod vendor  
> GO111MODULE=on go build -mod=vendor -buildmode=plugin -trimpath  
> GO111MODULE=on go build -mod=vendor -buildmode=plugin

I get little different error:

> Exiting: plugin.Open("/etc/filebeat/myplugin"): plugin was built with a different version of package internal/cpu

I tried other versions of Go, other branches of filebeat, even try compile filebeat on **machine A** and run compiled from sources filebeat with my plugin on **machine B** - nothing, same result.

[Here](https://stackoverflow.com/a/59613426/4142997) it says the problem might be in GOPATH environment variable. I have value as **/root/go** , but I don't know, what value have GOPATH variable in official dev environment.

Please, help!

Related topics:

> <https://github.com/elastic/beats/issues/6760>
>
> filebeat verson: 6.2

> **[GitHub - andrewkroh/beats-processor-fingerprint: Fingerprint Plugin for...](https://github.com/andrewkroh/beats-processor-fingerprint)**
>
> Fingerprint Plugin for Elastic Beats. Contribute to andrewkroh/beats-processor-fingerprint development by creating an account on GitHub.

> [@How to create a filebeat processor?](https://discuss.elastic.co/t/how-to-create-a-filebeat-processor/238417):
>
> We want to use filebeat to gather mysql slow log. I want to create a filebeat processor to convert mysql slow log to json format and add a sql fingerprint field. I find a related issue here: [https://github.com/elastic/beats/issues/6760](https://github.com/elastic/beats/issues/6760) I follow up the issue but encounter an error: [root@c3-b2c-dba-dbshard17 filebeat-7.4.0]# ./filebeat -e -c filebeat.yml --plugin sql\_fingerprint.so Exiting: plugin.Open("sql\_fingerprint"): plugin was built with a different version of package github.com/elastic/…

---

<div class="post-metadata">

**Author:** ![yoklmn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yoklmn/32/71255_2.png) [@yoklmn](https://discuss.elastic.co/u/yoklmn)\
**Post date:** [October 5, 2020, 4:01pm UTC](https://discuss.elastic.co/t/custom-filebeat-processor/248029/2 "2020-10-05T16:01:40Z")

</div>

Anyone?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 2, 2020, 6:01pm UTC](https://discuss.elastic.co/t/custom-filebeat-processor/248029/3 "2020-11-02T18:01:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
