# How to receive ack of publish in 6.0 libbeat

**URL:** <https://discuss.elastic.co/t/how-to-receive-ack-of-publish-in-6-0-libbeat/107964>\
**Category:** Beats\
**Tags:** beats-development\
**Created:** [November 16, 2017, 3:03pm UTC](https://discuss.elastic.co/t/how-to-receive-ack-of-publish-in-6-0-libbeat/107964 "2017-11-16T15:03:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![JamesB](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesb/32/24343_2.png) [@JamesB](https://discuss.elastic.co/u/JamesB)\
**Post date:** [November 16, 2017, 3:03pm UTC](https://discuss.elastic.co/t/how-to-receive-ack-of-publish-in-6-0-libbeat/107964/1 "2017-11-16T15:03:57Z")

</div>

Hi,

I've just started looking at creating a custom beat using the 6.0 branch. I want to guarantee delivery of events and also be notified when an event has been published. What is the best way to do this?

I've found the `ClientConfig` which can be passed into `Publisher.ConnectWith` and the option `GuaranteedSend` seems the correct one. When looking at acknowledgements there is a property `ACKEvents`which takes a function but the documentation says:

`ACKEvents reports the events private data of recently acknowledged events.`

What does this mean? I've tried passing in a function to this and printing out the contents received but they are empty. I've noticed the `Private` property on `Event` but the code says `// for beats private use`. Can I use the `Private` property to track ids for events?

Is there an existing beat that I could look at that deals with acknowledging success to the system being read from?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 16, 2017, 10:47pm UTC](https://discuss.elastic.co/t/how-to-receive-ack-of-publish-in-6-0-libbeat/107964/2 "2017-11-16T22:47:41Z")

</div>

Hi,

which callback you want to use somehow depends on your Beat and how you want to store the last state in order to continue sending. The `ACKEvents` handler is somewhat correct, but in the new publisher pipeline in 6.0 a total of 4 (slightly different) ACK callbacks do exists.

The doc comment on `Private` is maybe a little misleading. `for beats private usage` means your own beat, not libbeat internal. Libbeat will only process `Timestamp`, `Fields` and `Meta`. The contents in `Private` is asynchronously passed to the ACK handler.

All ACK handlers report acked events in the same order events have been published to the pipeline. Even if events are ACKed out of order (e.g. due to load-balancing).

First of all you have to choose if you want the ACK handling local to the `beat.Client` instance (each worker acquiring new events should have it's own instance) or globally. If the `beat.Client` is closed, you will receive no more ACKs, even if events are currently processed and ackeded by an output. You can still mix this using the `WaitClose` setting to block on the `beat.Client` close operation until all events published have been either acked or the timedout occurs.

For local ACK handling you have to configure the ACK handler via `ClientConfig`. For global ACK handling use `SetACKHandler` on the `Publisher` being passed to your beat. This must be done before the first call to `Connect` or `ConnectWith`.

Beats outputs process events in batches. The event acks are batched up into fewer calls to the ACK handlers (which are called asynchronously to the publisher). If the state to be persistent is some kind of sequential (ever increasing) ID (e.g. timestamp, counter, offset), you might not be interested in processing all events ever published. In this case use the `ACKLastEvent(s)` callback. This will report the `Private` field of the most recent published and ACKed event. The global callback reports an array of `Private` fields, each entry representing another `beat.Client` instance whose most recent event has been ACKed.

In beats we currently use the global ACK handlers only (filebeat and winlogbeat). These are still active when all `beat.Client` instances have been closed. As winlogbeat is somewhat simpler, rather have a look at winlogbeat:

- When creating the `beat.Event` winlogbeat sets the `Private` field to the [next checkpoint](https://github.com/elastic/beats/blob/0cacffef95674632cc2b1039376210716733b2c2/winlogbeat/eventlog/eventlog.go#L115) value.
- the [ACK handler](https://github.com/elastic/beats/blob/master/winlogbeat/beater/winlogbeat.go#L123) finally persists the states already being ACKed
- also note how winlogbeat uses the [local counting ACK handler](https://github.com/elastic/beats/blob/master/winlogbeat/beater/eventlogger.go#L54) to report events being ACKed for particular workers

Filebeat uses the same interfaces as Winlogbeat.

Currently filebeat and winlogbeat have different ways of persisting and reading the state (also gc'ing old state not required anymore). For the future we hope to introduce unified interfaces in libbeat, so to help with implementing logic for storing, reloading, and gc'ing checkpoints.

As you want to pass the ACK back to the source system, you might be interested in the local ACK handlers. Depending on how ack is reported back to the source system, you might be even good using the ACKCount handler only.

---

<div class="post-metadata">

**Author:** ![JamesB](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesb/32/24343_2.png) [@JamesB](https://discuss.elastic.co/u/JamesB)\
**Post date:** [November 17, 2017, 9:08am UTC](https://discuss.elastic.co/t/how-to-receive-ack-of-publish-in-6-0-libbeat/107964/3 "2017-11-17T09:08:39Z")

</div>

Thank you, that's really helpful. I'll have a look at those options and Winlogbeat and try them out.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2017, 9:09am UTC](https://discuss.elastic.co/t/how-to-receive-ack-of-publish-in-6-0-libbeat/107964/4 "2017-12-15T09:09:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
