# Using processor in Filebeat Nginx module

**URL:** <https://discuss.elastic.co/t/using-processor-in-filebeat-nginx-module/263368>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [February 5, 2021, 10:19am UTC](https://discuss.elastic.co/t/using-processor-in-filebeat-nginx-module/263368 "2021-02-05T10:19:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jz1603](https://avatars.discourse-cdn.com/v4/letter/j/c57346/32.png) [@jz1603](https://discuss.elastic.co/u/jz1603)\
**Post date:** [February 5, 2021, 10:19am UTC](https://discuss.elastic.co/t/using-processor-in-filebeat-nginx-module/263368/1 "2021-02-05T10:19:04Z")

</div>

I am trying to drop some fields on the indices ingested by the filebeat Nginx module.  
I followed the instructions on the thread [How to use processors in filebeat HAproxy's module? - #3 by aventrax](https://discuss.elastic.co/t/how-to-use-processors-in-filebeat-haproxys-module/216256/3), but the fields are not being dropped when I restart filebeat with "filebeat -e".

My config looks like this:

```
- module: nginx
  # Access logs
  access:
    enabled: true

# Set custom paths for the log files. If left empty,
# Filebeat will choose the paths depending on your OS.
#var.paths:

# Input configuration (advanced). Any input configuration option
# can be added under this section.
input:
  processors:
    - drop_fields:
        fields: ["agent", "user_agent"]

```

Am I missing anything? Any help is appreciated!

Thanks,  
Jenna

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [February 5, 2021, 4:12pm UTC](https://discuss.elastic.co/t/using-processor-in-filebeat-nginx-module/263368/2 "2021-02-05T16:12:46Z")

</div>

The indentation seems incorrect. Try this:

```auto
- module: nginx
  # Access logs
  access:
    enabled: true

  input:
    processors:
      - drop_fields:
          fields: ["agent", "user_agent"]

```

---

<div class="post-metadata">

**Author:** ![jz1603](https://avatars.discourse-cdn.com/v4/letter/j/c57346/32.png) [@jz1603](https://discuss.elastic.co/u/jz1603)\
**Post date:** [February 5, 2021, 7:47pm UTC](https://discuss.elastic.co/t/using-processor-in-filebeat-nginx-module/263368/3 "2021-02-05T19:47:02Z")

</div>

Hi Noémi,

Thank you for your response! I tried it and it threw an error: \> "Exiting: Failed to start crawler: creating module reloader failed: fileset nginx/input is configured but doesn't exist

> Exiting: Failed to start crawler: creating module reloader failed: fileset nginx/input is configured but doesn't exist"

I am trying to configure the input for access only which is why the input is indented under the access block, the error log and the ingress\_controller are not enabled. The full config looks like this:  
# Module: nginx  
# Docs: [Nginx module | Filebeat Reference [7.10] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/7.10/filebeat-module-nginx.html)

```
- module: nginx
  # Access logs
  access:
    enabled: true

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    #var.paths:

    # Input configuration (advanced). Any input configuration option
    # can be added under this section.
    input:
      processors:
        - drop_fields:
            fields: ["agent", "user_agent"]

  # Error logs
  error:
    enabled: false

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    #var.paths:

  # Ingress-nginx controller logs. This is disabled by default. It could be used in Kubernetes environments to parse ingress-nginx logs
  ingress_controller:
    enabled: false

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    #var.paths:

```

Best,  
Jenna

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 5, 2021, 9:47pm UTC](https://discuss.elastic.co/t/using-processor-in-filebeat-nginx-module/263368/4 "2021-03-05T21:47:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
