# "The processor action grok does not exist" in FileBeat. Why ? (Custom Logs Integration)

**URL:** <https://discuss.elastic.co/t/the-processor-action-grok-does-not-exist-in-filebeat-why-custom-logs-integration/332756>\
**Category:** Elasticsearch\
**Created:** [May 7, 2023, 9:27am UTC](https://discuss.elastic.co/t/the-processor-action-grok-does-not-exist-in-filebeat-why-custom-logs-integration/332756 "2023-05-07T09:27:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mehdi-lamrani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehdi-lamrani/32/108993_2.png) [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Post date:** [May 7, 2023, 9:27am UTC](https://discuss.elastic.co/t/the-processor-action-grok-does-not-exist-in-filebeat-why-custom-logs-integration/332756/1 "2023-05-07T09:27:55Z")

</div>

I am a bit confused here.  
Grok is [available](https://www.elastic.co/guide/en/elasticsearch/reference/current/grok-processor.html) in Ingest Processors but [not in](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) Filebeat processors  
May I ask why ? 🤔

I was hoping to do this

 ![Screenshot 2023-05-07 at 11.13.35](https://us1.discourse-cdn.com/elastic/original/3X/c/3/c3b6bc76ccd3976fe8580dcda9f23cd257d7c283.png)

, but it breaks, as I am getting the following error :

```auto
[elastic_agent][error] [...] the processor action grok does not exist. 

```

So,  
1 - Why are the 2 processor families different ? why have two sets of processors and not just one ? (philosophical question)  
2 - Where should I put my grok then ? (I am using custom logs integration)  
My guess is that I need to define an ingest pipeline and add it to custom configurations.  
Am I right ?

Thanks in advance,  
M.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [May 7, 2023, 7:21pm UTC](https://discuss.elastic.co/t/the-processor-action-grok-does-not-exist-in-filebeat-why-custom-logs-integration/332756/2 "2023-05-07T19:21:22Z")

</div>

I think because ingest processor is an ingest pipeline, running on an elasticsearch node. FIlebeat processors are lightweight, limited and run on filebeat. Filebeat processors are good for dropping data before it traverses the network, but could put a lot of load on the agent if not kept simple.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 7, 2023, 10:41pm UTC](https://discuss.elastic.co/t/the-processor-action-grok-does-not-exist-in-filebeat-why-custom-logs-integration/332756/3 "2023-05-07T22:41:28Z")

</div>

Yep that's pretty much the reasoning behind the separation!

---

<div class="post-metadata">

**Author:** ![mehdi-lamrani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehdi-lamrani/32/108993_2.png) [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Post date:** [May 8, 2023, 4:00pm UTC](https://discuss.elastic.co/t/the-processor-action-grok-does-not-exist-in-filebeat-why-custom-logs-integration/332756/4 "2023-05-08T16:00:17Z")

</div>

Ok, makes sense.  
Thanks for the clarification 👌🏾

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2023, 4:00pm UTC](https://discuss.elastic.co/t/the-processor-action-grok-does-not-exist-in-filebeat-why-custom-logs-integration/332756/5 "2023-06-05T16:00:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
