# How to configure processor in autodiscover mode?

**URL:** <https://discuss.elastic.co/t/how-to-configure-processor-in-autodiscover-mode/286757>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [October 14, 2021, 4:35pm UTC](https://discuss.elastic.co/t/how-to-configure-processor-in-autodiscover-mode/286757 "2021-10-14T16:35:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jfree](https://avatars.discourse-cdn.com/v4/letter/j/b9e5f3/32.png) [@Jfree](https://discuss.elastic.co/u/Jfree)\
**Post date:** [October 14, 2021, 4:35pm UTC](https://discuss.elastic.co/t/how-to-configure-processor-in-autodiscover-mode/286757/1 "2021-10-14T16:35:27Z")

</div>

Hi,  
We have k8s cluster with filebeat configured in autodiscover mode with hints:

```auto
filebeat.yml: |
  logging.level: debug
  filebeat.autodiscover:
    providers:
      - type: kubernetes
        node: ${NODE_NAME}
        hints.enabled: true
        hints.default_config:
          enabled: false
          type: docker
          containers.ids:
            - ${data.kubernetes.container.id}
  output.elasticsearch:
    host: '${NODE_NAME}'
    hosts: 'x.x.x.x:xxxx'

```

To enable nginx module the following annotations were added to appropriate pods:

```auto
  podAnnotations:
    co.elastic.logs/enabled: "true"
    co.elastic.logs/fileset.stderr: error
    co.elastic.logs/fileset.stdout: ingress_controller
    co.elastic.logs/module: nginx

```

It has been working great and convenient until we needed to convert some fields from nginx. I've tried to reach that by something like that:

```auto
filebeat.yml: |
  logging.level: debug
  filebeat.autodiscover:
    providers:
      - type: kubernetes
        node: ${NODE_NAME}
        hints.enabled: true
        hints.default_config:
          enabled: false
          type: docker
          containers.ids:
            - ${data.kubernetes.container.id}
  processors:
    - add_labels:
        labels:
          test_label: tested
    - copy_fields:
        fields:
          - from: "nginx.ingress_controller.upstream.ip"
            to: "nginx.ingress_controller.upstream.ip_test"
        fail_on_error: false
        ignore_missing: true
    - script:
        lang: javascript
        source: >
          function process(event) {
            var value = event.Get("nginx.ingress_controller.upstream.ip")
            event.Put("my_test_value", value);
            }
  output.elasticsearch:
    host: '${NODE_NAME}'
    hosts: 'x.x.x.x:xxxx'

```

Unfortunately the only labels.test\_label - field was added as expected, nginx.ingress\_controller.upstream.ip\_test - doesn't appear at all and my\_test\_value is empty. Looks like processors run before nginx module does it job and have no access to appropriate fields. Is it any way to process nginx module fields without using logstash (we are not using it at the moment) and Ingest Node Pipelines?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 11, 2021, 6:35pm UTC](https://discuss.elastic.co/t/how-to-configure-processor-in-autodiscover-mode/286757/2 "2021-11-11T18:35:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
