# Filebeat new module - missing info

**URL:** <https://discuss.elastic.co/t/filebeat-new-module-missing-info/122462>\
**Category:** Beats\
**Created:** [March 5, 2018, 8:48am UTC](https://discuss.elastic.co/t/filebeat-new-module-missing-info/122462 "2018-03-05T08:48:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Asher\_Shoshan](https://avatars.discourse-cdn.com/v4/letter/a/eada6e/32.png) [@Asher\_Shoshan](https://discuss.elastic.co/u/Asher_Shoshan)\
**Post date:** [March 5, 2018, 8:49am UTC](https://discuss.elastic.co/t/filebeat-new-module-missing-info/122462/1 "2018-03-05T08:49:00Z")

</div>

Trying to add a new module to filebeat (parsing some application access log); In documentation, last steps are missing...(after running build create- fileset) how to wrap the new module, recompile filebaet?

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [March 9, 2018, 2:05pm UTC](https://discuss.elastic.co/t/filebeat-new-module-missing-info/122462/2 "2018-03-09T14:05:29Z")

</div>

Is this the guide that you have been following? [https://www.elastic.co/guide/en/beats/devguide/current/filebeat-modules-devguide.html](https://www.elastic.co/guide/en/beats/devguide/current/filebeat-modules-devguide.html)

After you do that, you can run `make update && make` to re-build filebeat, see the general contributor guide: [https://www.elastic.co/guide/en/beats/devguide/current/beats-contributing.html](https://www.elastic.co/guide/en/beats/devguide/current/beats-contributing.html)

What module are you working on?

---

<div class="post-metadata">

**Author:** ![Asher\_Shoshan](https://avatars.discourse-cdn.com/v4/letter/a/eada6e/32.png) [@Asher\_Shoshan](https://discuss.elastic.co/u/Asher_Shoshan)\
**Post date:** [March 11, 2018, 9:00am UTC](https://discuss.elastic.co/t/filebeat-new-module-missing-info/122462/3 "2018-03-11T09:00:08Z")

</div>

Yes, this is the guide. I was trying to add a new module to filebeat (handling my own application log).  
Is that a must? recompiling filebeat?  
What about filebeat docker container? How do I do that inside the container?

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [March 11, 2018, 3:13pm UTC](https://discuss.elastic.co/t/filebeat-new-module-missing-info/122462/4 "2018-03-11T15:13:46Z")

</div>

For you own application logs, it might be a better option at this point to directly PUT the [Ingest node configuration](https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest.html) in Elasticsearch. Or you can consider using Logstash instead of Ingest Node as well.

We do plan to make it possible to create Filebeat modules without any developer tools required, but we're not quite there.

---

<div class="post-metadata">

**Author:** ![Asher\_Shoshan](https://avatars.discourse-cdn.com/v4/letter/a/eada6e/32.png) [@Asher\_Shoshan](https://discuss.elastic.co/u/Asher_Shoshan)\
**Post date:** [March 12, 2018, 7:52am UTC](https://discuss.elastic.co/t/filebeat-new-module-missing-info/122462/5 "2018-03-12T07:52:05Z")

</div>

Afaik adding new module to filebeat is actually using ingest-mode in elastic...  
But I'm asking what are the steps after make module, make fileset, and make fileset-fields.  
Recompile filebeat? what about filebeat in docker - should I just copy the new folder created above to it?  
It's bit vague..  
I tried to put the ingest-mode pipeline directly to ElasticSearch, What to complete in filebeat container?  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 9, 2018, 9:52am UTC](https://discuss.elastic.co/t/filebeat-new-module-missing-info/122462/6 "2018-04-09T09:52:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
