# How to create a filebeat processor?

**URL:** <https://discuss.elastic.co/t/how-to-create-a-filebeat-processor/238417>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 24, 2020, 9:16am UTC](https://discuss.elastic.co/t/how-to-create-a-filebeat-processor/238417 "2020-06-24T09:16:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![xvdy](https://avatars.discourse-cdn.com/v4/letter/x/b5e925/32.png) [@xvdy](https://discuss.elastic.co/u/xvdy)\
**Post date:** [June 24, 2020, 9:16am UTC](https://discuss.elastic.co/t/how-to-create-a-filebeat-processor/238417/1 "2020-06-24T09:16:45Z")

</div>

We want to use filebeat to gather mysql slow log. I want to create a filebeat processor to convert mysql slow log to json format and add a sql fingerprint field.  
I find a related issue here: [https://github.com/elastic/beats/issues/6760](https://github.com/elastic/beats/issues/6760)

I follow up the issue but encounter an error:

```auto
[root@c3-b2c-dba-dbshard17 filebeat-7.4.0]# ./filebeat -e -c filebeat.yml --plugin sql_fingerprint.so
Exiting: plugin.Open("sql_fingerprint"): plugin was built with a different version of package github.com/elastic/beats/libbeat/common/file

```

We use filebeat 7.4.0 version online, I find that this version filebeat is compiled by go 1.12.9.

```auto
[root@c3-b2c-dba-dbshard17 filebeat-7.4.0]# ./filebeat version
filebeat version 7.4.0 (amd64), libbeat 7.4.0 [f940c36884d3749901a9c99bea5463a6030cdd9c built 2019-09-27 07:45:44 +0000 UTC]

git checkout f940c36884d3749901a9c99bea5463a6030cdd9c

[root@sgp2-b2c-b2cop-beta-neo-node01 beats]# cat .go-version
1.12.9

```

The steps I use to create processor:

1. Install go 1.12.9
2. git clone filebeat repo
3. git checout f940c36884d3749901a9c99bea5463a6030cdd9c
4. write code in {go/src}[github.com/elastic/beats/filebeat/processor/sql\_fingerprint](http://github.com/elastic/beats/filebeat/processor/sql_fingerprint)
5. cd {go/src}[github.com/elastic/beats/filebeat/processor/sql\_fingerprint](http://github.com/elastic/beats/filebeat/processor/sql_fingerprint) and build plugin with:  
GO111MODULE=on go build -mod=vendor -buildmode=plugin
6. use the sql\_fingerprint.so generated by step 4 and run:

```auto
[root@c3-b2c-dba-dbshard17 filebeat-7.4.0]# ./filebeat -e -c filebeat.yml --plugin sql_fingerprint.so
Exiting: plugin.Open("sql_fingerprint"): plugin was built with a different version of package github.com/elastic/beats/libbeat/common/file

```

Help.

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [June 25, 2020, 7:11am UTC](https://discuss.elastic.co/t/how-to-create-a-filebeat-processor/238417/2 "2020-06-25T07:11:26Z")

</div>

Actually you don't need to touch Go code, you can always use script processor: [https://www.elastic.co/guide/en/beats/filebeat/master/processor-script.html](https://www.elastic.co/guide/en/beats/filebeat/master/processor-script.html) . Please take a look and tell if it meets your needs.

---

<div class="post-metadata">

**Author:** ![xvdy](https://avatars.discourse-cdn.com/v4/letter/x/b5e925/32.png) [@xvdy](https://discuss.elastic.co/u/xvdy)\
**Post date:** [June 28, 2020, 2:59am UTC](https://discuss.elastic.co/t/how-to-create-a-filebeat-processor/238417/3 "2020-06-28T02:59:47Z")

</div>

I tried. There is another problem, I want to calculate sql fingerprint with another program. Can script processor call local program, such as shell?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2020, 4:59am UTC](https://discuss.elastic.co/t/how-to-create-a-filebeat-processor/238417/4 "2020-07-26T04:59:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
