# How to add a new filebeat.input tag in filebeat go code repo

**URL:** <https://discuss.elastic.co/t/how-to-add-a-new-filebeat-input-tag-in-filebeat-go-code-repo/233002>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 17, 2020, 4:14pm UTC](https://discuss.elastic.co/t/how-to-add-a-new-filebeat-input-tag-in-filebeat-go-code-repo/233002 "2020-05-17T16:14:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rushabhwadkar](https://avatars.discourse-cdn.com/v4/letter/r/7ea924/32.png) [@rushabhwadkar](https://discuss.elastic.co/u/rushabhwadkar)\
**Post date:** [May 17, 2020, 4:14pm UTC](https://discuss.elastic.co/t/how-to-add-a-new-filebeat-input-tag-in-filebeat-go-code-repo/233002/1 "2020-05-17T16:14:12Z")

</div>

These are the steps I followed -

1. I cloned and copied the log folder ([https://github.com/elastic/beats/tree/master/filebeat/input](https://github.com/elastic/beats/tree/master/filebeat/input)), renamed it to newlog and placed it into that folder only.
2. I changed the package name to newlog for all files inside it
3. I tried to register that input in init() function inside input.go and also registered the input in include.go file.

I faced with duplicate harvester error - `(panic: name harvester already used)` so I tried to change the harvester registry name to filebeat.harvestor.newlog and tried to build it.

It builds successfully with filebeat.input to newlog in filebeat.yml config but as an when I try to run it, it throws error  
`Harvester could not be started on new file: /root/fakeRBOS3253.log, Err: error setting up harvester: Harvester setup failed. Unexpected file opening error: Invalid harvester type`

Can anybody help regarding this on how to add your custom tag input to beats?  
Here, the problem is just not about having a custom tag name but I want to implement some custom logic functionality behind it.  
Please help!

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [May 18, 2020, 7:15am UTC](https://discuss.elastic.co/t/how-to-add-a-new-filebeat-input-tag-in-filebeat-go-code-repo/233002/2 "2020-05-18T07:15:23Z")

</div>

Hi,

I'm not quite sure what you're trying to achieve and if it's really required to build an input for that. Could you describe your use case?

---

<div class="post-metadata">

**Author:** ![rushabhwadkar](https://avatars.discourse-cdn.com/v4/letter/r/7ea924/32.png) [@rushabhwadkar](https://discuss.elastic.co/u/rushabhwadkar)\
**Post date:** [May 18, 2020, 7:31am UTC](https://discuss.elastic.co/t/how-to-add-a-new-filebeat-input-tag-in-filebeat-go-code-repo/233002/3 "2020-05-18T07:31:54Z")

</div>

> [@mtojek](#):
>
> lly required to build an

Hi mtojek,

The use case is quite simple. We want a custom input tag to be included in the filebeat.yml file to monitor the specific files. Now those specific files are not plain text files but custom encrypted binary files so essentially, what we want is, to monitor such files and write custom logic to decrypt and push those logs to output.

So to tell you in brief as an example-  
filename.bin (our binary encoded file) ---\> filebeat -----\> custom tag(decodelog) ----\> decodelog will convert the binary log to plain text log ---\> Send output just like `log` output.

The decode log functionality is a custom wrapper which basically tries to convert the whole binary file to plain text format which each line terminated by line seperator \n.

Basically, we want to extend out and patch our decode functionality into filebeat.

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [May 18, 2020, 7:45am UTC](https://discuss.elastic.co/t/how-to-add-a-new-filebeat-input-tag-in-filebeat-go-code-repo/233002/4 "2020-05-18T07:45:29Z")

</div>

Could you share your `filebeat.yml` file (use code tags)? I think there might be an issue around the `type: log`.

See:

```auto
// open does open the file given under h.Path and assigns the file handler to h.log
func (h *Harvester) open() error {
	switch h.config.Type {
	case harvester.StdinType:
		return h.openStdin()
	case harvester.LogType, harvester.DockerType, harvester.ContainerType:
		return h.openFile()
	default:
		return fmt.Errorf("Invalid harvester type: %+v", h.config)
	}
}

```

You might need to add another entry here.

---

<div class="post-metadata">

**Author:** ![rushabhwadkar](https://avatars.discourse-cdn.com/v4/letter/r/7ea924/32.png) [@rushabhwadkar](https://discuss.elastic.co/u/rushabhwadkar)\
**Post date:** [May 18, 2020, 8:13am UTC](https://discuss.elastic.co/t/how-to-add-a-new-filebeat-input-tag-in-filebeat-go-code-repo/233002/5 "2020-05-18T08:13:05Z")

</div>

Oh yes. It worked.  
I added a case statement for the custom config type.  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2020, 8:13am UTC](https://discuss.elastic.co/t/how-to-add-a-new-filebeat-input-tag-in-filebeat-go-code-repo/233002/6 "2020-06-15T08:13:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
