# Filebeat rename processor with conditions

**URL:** <https://discuss.elastic.co/t/filebeat-rename-processor-with-conditions/153371>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 22, 2018, 10:20am UTC](https://discuss.elastic.co/t/filebeat-rename-processor-with-conditions/153371 "2018-10-22T10:20:23Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![havlan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/havlan/32/32379_2.png) [@havlan](https://discuss.elastic.co/u/havlan)\
**Post date:** [October 22, 2018, 10:20am UTC](https://discuss.elastic.co/t/filebeat-rename-processor-with-conditions/153371/1 "2018-10-22T10:20:24Z")

</div>

Hi! I'm trying to rename some fields from kubernetes annotations based on an when conditions, due to not finding any good resources, I was wondering if someone of you could help me with this.

My goal is to rename events which contain kubernetes.annotations.myapp/sidecar = 'true' and when kubernetes.annotations.myapp/sidecar.type = kubernetes.container.name. If none of these conditions go through, I want to rename as a default (in the other when).

Is this possible? I did not find any good examples on how to do, if possible more than one condition under one processor (global).

```auto
- rename:
          when:
              equals: kubernetes.annotations.myapp/sidecar.source: kubernetes.container.type 
                fields:
                  - from: "kubernetes.labels.myapp-service"
                    to: "_service"
                  - from: "kubernetes.labels.myapp-token"
                    to: "_token"
                  - from: "kubernetes.annotations.myapp/sidecar.type"
                    to: "type"
          when:
            or:
              - not.has_fields: ['kubernetes.annotations.myapp/sidecar']
              - not.equals:
                  kubernetes.annotations.myapp/sidecar: 'true'
                 - from: "kubernetes.labels.myapp-service"
                    to: "_service"
                  - from: "kubernetes.labels.myapp-token"
                    to: "_token"
                  - from: "kubernetes.labels.myapp-type"
                    to: "type"

```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 22, 2018, 3:17pm UTC](https://discuss.elastic.co/t/filebeat-rename-processor-with-conditions/153371/2 "2018-10-22T15:17:06Z")

</div>

I guess you are using auto-discovery? Instead of global filter per event, you might consider to use [hints](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover-hints.html#configuration-autodiscover-hints) or [templates](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html#_kubernetes) to configure the required processor on container startup and save some CPU.

The syntax of processors in filebeat goes like this:

```auto
processors:
- <name>:
    <processor settings>
    when:
      <conditional>

```

That is, you have to switch order.

Right now you can not compare 2 event fields using equal. The right hand side of equals must be string/numeric/boolean constant. If `kubernetes.container.type` is an event value, then the condition is not supported (feel free to open a [feature request](https://github.com/elastic/beats/issues)).

Anyways, more correct solution is:

```auto
processors:
- rename:
    fields:
      - from: "kubernetes.labels.myapp-service"
        to: "_service"
      - from: "kubernetes.labels.myapp-token"
        to: "_token"
      - from: "kubernetes.annotations.myapp/sidecar.type"
        to: "type"
    when:
      equals:
        'kubernetes.annotations.myapp/sidecar.source': ... # <- must be some constant value

- rename:
    fields:
      - from: "kubernetes.labels.myapp-service"
        to: "_service"
      - from: "kubernetes.labels.myapp-token"
        to: "_token"
      - from: "kubernetes.labels.myapp-type"
        to: "type"
    when:
      or:
        - not.has_fields: ['kubernetes.annotations.myapp/sidecar']
        - not.equals:
          kubernetes.annotations.myapp/sidecar: true

```

---

<div class="post-metadata">

**Author:** ![havlan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/havlan/32/32379_2.png) [@havlan](https://discuss.elastic.co/u/havlan)\
**Post date:** [October 22, 2018, 3:37pm UTC](https://discuss.elastic.co/t/filebeat-rename-processor-with-conditions/153371/3 "2018-10-22T15:37:38Z")

</div>

Thanks alot for your feedback. Yes I am using autodiscover in Kubernetes (should have included that.. ), I should also mention that this is steps that we are doing in order to get it functional with a logstash pipeline down the road (k8s-\>filebeat-\>logstash-\>elasticsearch). This scenario is meant for sidecar containers. I know the parsing itself could be done through hints/annotations, my issue is more related to extracting and performing logic based upon annotations. In my mind every pod which has more than one running container would specify sidecar configurations so that down the line it would work with a logstash pipeline dependent on the type(thats why i rename/extract it) being added to the log event.

As for `kubernetes.container.type` I meant `kubernetes.container.name`, I think that should be added to every event.

Thanks.

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [October 22, 2018, 4:31pm UTC](https://discuss.elastic.co/t/filebeat-rename-processor-with-conditions/153371/4 "2018-10-22T16:31:25Z")

</div>

Hi @havlan,

As far as I know autodiscover should be reporting the container name, please open a new thread if that's not the case for you

---

<div class="post-metadata">

**Author:** ![havlan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/havlan/32/32379_2.png) [@havlan](https://discuss.elastic.co/u/havlan)\
**Post date:** [October 22, 2018, 4:54pm UTC](https://discuss.elastic.co/t/filebeat-rename-processor-with-conditions/153371/5 "2018-10-22T16:54:39Z")

</div>

It does (it was just a typo from me), I was just wondering whether the if/else approach would work. I'll try @steffens approach and report back if I have any issues.

Thank you both for your quick answers.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 23, 2018, 10:11am UTC](https://discuss.elastic.co/t/filebeat-rename-processor-with-conditions/153371/6 "2018-10-23T10:11:43Z")

</div>

You can not compare an event field with another event field. That is, this condition is not supported:

```auto
equals:
  'kubernetes.annotations.myapp/sidecar.source': 'kubernetes.container.name'

```

You will have to find some other method (constant value/flag) to filter upon.

---

<div class="post-metadata">

**Author:** ![havlan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/havlan/32/32379_2.png) [@havlan](https://discuss.elastic.co/u/havlan)\
**Post date:** [October 23, 2018, 10:34am UTC](https://discuss.elastic.co/t/filebeat-rename-processor-with-conditions/153371/7 "2018-10-23T10:34:06Z")

</div>

I see. Thanks for the clarification. It's hard to inject a value or something into a container from a pod manifest, but I'll look more into it.  
This sidecar use case with annotation logic might not be possible then.

---

<div class="post-metadata">

**Author:** ![havlan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/havlan/32/32379_2.png) [@havlan](https://discuss.elastic.co/u/havlan)\
**Post date:** [October 26, 2018, 1:33pm UTC](https://discuss.elastic.co/t/filebeat-rename-processor-with-conditions/153371/8 "2018-10-26T13:33:28Z")

</div>

Github feature request/issue open [https://github.com/elastic/beats/issues/8764](https://github.com/elastic/beats/issues/8764)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 23, 2018, 1:45pm UTC](https://discuss.elastic.co/t/filebeat-rename-processor-with-conditions/153371/9 "2018-11-23T13:45:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
