# How to use processors in filebeat HAproxy's module?

**URL:** <https://discuss.elastic.co/t/how-to-use-processors-in-filebeat-haproxys-module/216256>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 23, 2020, 1:52pm UTC](https://discuss.elastic.co/t/how-to-use-processors-in-filebeat-haproxys-module/216256 "2020-01-23T13:52:21Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![aventrax](https://avatars.discourse-cdn.com/v4/letter/a/f05b48/32.png) [@aventrax](https://discuss.elastic.co/u/aventrax)\
**Post date:** [January 23, 2020, 1:52pm UTC](https://discuss.elastic.co/t/how-to-use-processors-in-filebeat-haproxys-module/216256/1 "2020-01-23T13:52:22Z")

</div>

Hello, I'm new with filebeat and I'm in trouble adding a processor to the haproxy module.

To begin, just adding a tag would be enough, I tried with this config without much luck (Filebeat 7.1.1 on Debian stretch):

/etc/filebeat/modules.d/haproxy.yml

```
- module: haproxy
  # All logs
  log:
    enabled: true
    # Set which input to use between syslog (default) or file.
    #var.input:
    var.input: "file"

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    var.paths: ["/var/log/haproxy.log"]

    processors:
      - add_tags:
          tags: [test]

```

The processor is NOT working. If sat globally on /etc/filebeat/filebeat.yml it works.  
Any help would be very appreciated. Many thanks.

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [January 23, 2020, 2:48pm UTC](https://discuss.elastic.co/t/how-to-use-processors-in-filebeat-haproxys-module/216256/2 "2020-01-23T14:48:36Z")

</div>

Hi @aventrax 🙂

Processors can only be used globally on each Filebeat instance (see 3rd paragraph) [https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html)

---

<div class="post-metadata">

**Author:** ![aventrax](https://avatars.discourse-cdn.com/v4/letter/a/f05b48/32.png) [@aventrax](https://discuss.elastic.co/u/aventrax)\
**Post date:** [January 23, 2020, 2:58pm UTC](https://discuss.elastic.co/t/how-to-use-processors-in-filebeat-haproxys-module/216256/3 "2020-01-23T14:58:17Z")

</div>

Hi @Mario_Castro, I don't understand, reading [this](https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html) under **Where are processors valid?** , there is something that seems contraddict your sentence: _Similarly, for Filebeat modules, you can define processors under the `input` section of the module definition._

Moreover, [here](https://discuss.elastic.co/t/help-with-processors-in-filebeat-modules/215711/6) @jsoriano is advising a user that asked a similar question. There is a processor used on apache module, am I wrong?

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [January 23, 2020, 3:23pm UTC](https://discuss.elastic.co/t/how-to-use-processors-in-filebeat-haproxys-module/216256/4 "2020-01-23T15:23:47Z")

</div>

Sorry, some parts of the docs must be definitely updated. Anyways, you cannot do maths in a processor (key or value). Supported conditions are [https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#conditions](https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#conditions)

---

<div class="post-metadata">

**Author:** ![aventrax](https://avatars.discourse-cdn.com/v4/letter/a/f05b48/32.png) [@aventrax](https://discuss.elastic.co/u/aventrax)\
**Post date:** [January 23, 2020, 4:34pm UTC](https://discuss.elastic.co/t/how-to-use-processors-in-filebeat-haproxys-module/216256/5 "2020-01-23T16:34:01Z")

</div>

Sorry but my english is not good enough, which document is incorrect? I'm not trying to do very complicated stuff in processor, now I'm trying adding a tag, the final goal is to add a field only if the _source.ip_ field is in a certain network CIDR. To do so I'll use the network condition and I know that I will need to upgrade to (at least) 7.2. Anyway, at the moment I'm only trying to make the processor working in the haproxy module.

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [January 23, 2020, 6:05pm UTC](https://discuss.elastic.co/t/how-to-use-processors-in-filebeat-haproxys-module/216256/6 "2020-01-23T18:05:49Z")

</div>

EDIT: Checked, this config should work:

```auto
- module: haproxy
  # All logs
  log:
    enabled: true
    # Set which input to use between syslog (default) or file.
    #var.input:
    var.input: "file"

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    var.paths: ["/var/log/haproxy.log"]

    input:
      processors:
        - add_tags:
            tags: [test]

```

The key was the missing **`input`** parent field. The post you mentioned was misleading in this aspect. I have edited already

---

<div class="post-metadata">

**Author:** ![aventrax](https://avatars.discourse-cdn.com/v4/letter/a/f05b48/32.png) [@aventrax](https://discuss.elastic.co/u/aventrax)\
**Post date:** [January 24, 2020, 9:02am UTC](https://discuss.elastic.co/t/how-to-use-processors-in-filebeat-haproxys-module/216256/7 "2020-01-24T09:02:45Z")

</div>

Many thanks @Mario_Castro , it works! I tried any combination, my first try was very close to your solution but I used "var.input:" in place of "input:" and I've got a _duplicated variable error_ or something like that.

Anyway, thank you!

---

<div class="post-metadata">

**Author:** ![aventrax](https://avatars.discourse-cdn.com/v4/letter/a/f05b48/32.png) [@aventrax](https://discuss.elastic.co/u/aventrax)\
**Post date:** [January 26, 2020, 9:15am UTC](https://discuss.elastic.co/t/how-to-use-processors-in-filebeat-haproxys-module/216256/8 "2020-01-26T09:15:53Z")

</div>

Just to complete the post, I finally reached my goal. After the ELK upgrade to version 7.5.2, here's the configuration I ended up with.

```
- module: haproxy
  log:
    enabled: true
    var.input: "file"
    var.paths: ["/var/log/haproxy.log"]
    var.convert_timezone: true

    input:
      processors:

      - decode_csv_fields:
          fields:
            message: decoded.csv
          separator: ":"
          ignore_missing: false
          overwrite_keys: true
          trim_leading_space: true
          fail_on_error: false

      - extract_array:
          field: decoded.csv
          mappings:
            client.ip: 3

      - add_fields:
          when:
            network:
              client.ip: '10.0.9.0/24'
          fields:
            source.site: VPN Network
          target: ''

      - drop_fields:
          fields: ['decoded.csv', 'client.ip']
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 23, 2020, 9:16am UTC](https://discuss.elastic.co/t/how-to-use-processors-in-filebeat-haproxys-module/216256/9 "2020-02-23T09:16:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
