---
title: "Filebeat"
description: "report, receive, and optimize events collected by Filebeat forwarders"
source: "https://github.com/log-10x/modules/tree/main/pipelines/run/modules/input/forwarder/filebeat/module.yaml"
icon: "simple/beats"

---
Runs 10x Engine as a [sidecar](https://doc.log10x.com/engine/launcher/sidecar) to Filebeat for reporting, receiving, and optimizing events before they ship to their destination (Elasticsearch, Logstash, Kafka, S3, …). Filebeat's plugin model doesn't expose the Fluent Forward protocol used by other forwarders, so Log10x and Filebeat exchange events through Filebeat's own native extension points instead: a `script` processor on every input emits enriched events to Filebeat's stdout, and a `unix` input loads processed events back over a local socket. Filebeat runs as a child process of the sidecar (`filebeat -e 2>&1 | tenx ...`); works against any stock Filebeat build (Linux/macOS/Windows), and on Kubernetes via the `log10x-elastic/filebeat` chart, which deploys the prebuilt `log10x/filebeat-10x` image.

## Architecture

<div style="text-align: center;">

```mermaid
graph LR
    A["<div style='font-size: 14px;'>📂 Inputs</div><div style='font-size: 10px;'>filestream, container, log</div>"] --> F["<div style='font-size: 14px;'>🧪 script processor</div><div style='font-size: 10px;'>tenx-*.js</div>"]
    F --> B["<div style='font-size: 14px;'>📤 stdout</div><div style='font-size: 10px;'>JSON line per event</div>"]
    B --> E["<div style='font-size: 14px;'>⚡ 10x Engine</div><div style='font-size: 10px;'>Receive/Optimize</div>"]
    E --> C["<div style='font-size: 14px;'>🔌 unix input</div><div style='font-size: 10px;'>/tmp/tenx_filebeat.sock</div>"]
    C --> D["<div style='font-size: 14px;'>📤 Outputs</div><div style='font-size: 10px;'>ES, Logstash, Kafka, S3</div>"]

    classDef input fill:#2563eb,stroke:#1d4ed8,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef filter fill:#ea580c,stroke:#c2410c,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef engine fill:#7c3aed,stroke:#6d28d9,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef socket fill:#0891b2,stroke:#0e7490,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef output fill:#16a34a,stroke:#15803d,color:#ffffff,stroke-width:2px,rx:8,ry:8

    class A input
    class B filter
    class C socket
    class D output
    class E engine
    class F filter
```

</div>

### Data Flow

- 📂 **Inputs**, Your existing Filebeat inputs (`filestream`, `container`, `log`, `journald`, …) collect events and pass them through any processors you've configured on the input (`add_kubernetes_metadata`, `decode_json_fields`, `dissect`, …). Enrichment runs here exactly once before the event is handed off to Log10x.
- 🧪 **script processor**, A small JavaScript processor on each input (`tenx-receive.js` for the Receiver, `tenx-report.js` for the Reporter) marks the event, writes it as a single JSON line to Filebeat's stdout, and cancels it from Filebeat's normal output path. This is what keeps your destinations from seeing the unprocessed event.
- ⚡ **10x Engine**, Filebeat runs as a child process of the sidecar (`filebeat -e 2>&1 | tenx ...`), so its stdout is the engine's stdin. The Receiver app applies rate/policy-based filtering and optionally compacts events for volume reduction. The engine also picks Filebeat's own log lines off the same stream and replays them to Filebeat's configured log destinations (`logging.to_files`, `logging.to_stderr`, `logging.to_syslog`), so enabling the integration doesn't change where Filebeat logs go.
- 🔌 **unix input**, Processed events come back to Filebeat through a `unix` input listening on `/tmp/tenx_filebeat.sock` (loaded via `filebeat.config.inputs` from a bundled snippet, same path on both sides). The input's processors decode the JSON payload and remove the script-processor marker, so the second pass of `tenx-receive.js` lets the event through unmodified.
- 📤 **Outputs**, Your destination output (`elasticsearch`, `logstash`, `kafka`, `file`, …) ships the returned event. `output.console` is **not supported**, it would write to the same stdout pipe that carries events to the engine and corrupt the stream. Use `output.file` for local testing without a real destination.

### What an event looks like on the way back

The record structure of the original Filebeat event is preserved end-to-end, every field comes back to your destination output with the same name and same position. What changes depends on the Receiver app mode:

|Mode|Difference vs the event Filebeat collected|
|---|---|
|Receive (default)|None. Same record.|
|Receive + `symbolMessageHashField <name>`|Adds one new field with the symbol-pattern hash (a stable identifier for the message pattern, usable as a dedup key, metric dimension, or correlation ID).|
|`receiverOptimize true`|The value of the `message` field is replaced with a compact encoded form. A separate `tenx-template` event is emitted carrying the template needed to decode it (Filebeat's `decode_json_fields` processor on the return socket uses the embedded `templateHashDocId` to set the Elasticsearch document ID). All other fields stay verbatim.|
|`receiverOptimize true` + `symbolMessageHashField <name>`|Both of the above.|

`symbolMessageHashField` is unset by default, which is what makes the first row true: the receive path hands the record back exactly as it arrived. The pattern hash is still computed and still rides the event inside the engine as `tenx_hash` for metrics and aggregation, it just does not reach the wire. Naming a field opts in, either as a launch argument (`tenx @run/input/forwarder/filebeat @apps/receiver symbolMessageHashField my_custom_hash`) or as an environment variable of the same name.

Internally, Log10x's Filebeat input module reads the message text from the event's `message` field and surfaces the input source (`log.file.path`, container, etc.) for use in rate-based grouping. When the Receiver app is configured with `k8sExtractorName: filebeatK8s`, the `kubernetes.*` sub-object stamped by `add_kubernetes_metadata` is also materialized as enrichment fields for message-pattern and rate filtering.

??? tenx-keyfiles "Key Files"

    | File | Purpose |
    |------|---------|
    | [`stream.yaml`](https://github.com/log-10x/modules/blob/main/pipelines/run/modules/input/forwarder/filebeat/stream.yaml) | Stdin input (Filebeat events + Filebeat log lines) and Unix-socket output stream definitions |
    | [`log4j2.yaml`](https://github.com/log-10x/modules/blob/main/pipelines/run/modules/input/forwarder/filebeat/log4j2.yaml) | Appenders that replay Filebeat's own log lines to the destinations declared in `filebeat.yml`'s `logging.*` |
    | [`script/tenx-receive.js`](https://github.com/log-10x/modules/blob/main/pipelines/run/modules/input/forwarder/filebeat/script/tenx-receive.js) | Receiver processor, marks + emits events to stdout, cancels them so they loop back over the socket |
    | [`script/tenx-report.js`](https://github.com/log-10x/modules/blob/main/pipelines/run/modules/input/forwarder/filebeat/script/tenx-report.js) | Reporter processor, read-only variant that emits to stdout without canceling |
    | [`conf/tenxNix.yml`](https://github.com/log-10x/modules/blob/main/pipelines/run/modules/input/forwarder/filebeat/conf/tenxNix.yml) | `unix` input snippet for Linux/macOS, referenced from your `filebeat.yml` via `filebeat.config.inputs.path`, and read by the engine to discover the socket address |
    | [`conf/tenxWin.yml`](https://github.com/log-10x/modules/blob/main/pipelines/run/modules/input/forwarder/filebeat/conf/tenxWin.yml) | Same as above for Windows (uses `${TEMP}\tenx_filebeat.sock`) |

## Quickstart

**1. Wire up your Filebeat config**, load the return-path `unix` input and add the script processor to your inputs:

```yaml title="filebeat.yml"
# Loads the unix input that receives processed events back from Log10x.
filebeat.config.inputs:
  enabled: true
  # Linux/macOS
  path: ${TENX_MODULES}/pipelines/run/modules/input/forwarder/filebeat/conf/tenxNix.yml
  # Windows
  # path: ${TENX_MODULES}/pipelines/run/modules/input/forwarder/filebeat/conf/tenxWin.yml

filebeat.inputs:
  - type: filestream
    id: app-logs
    paths:
      - /var/log/app.log

    processors:
      # Hands every event off to Log10x via Filebeat's stdout, then cancels
      # it locally so destinations only see events that came back on the
      # unix socket.
      - script:
          lang: javascript
          file: ${TENX_MODULES}/pipelines/run/modules/input/forwarder/filebeat/script/tenx-receive.js

# Use any non-stdout output, output.console would collide with the stdout
# pipe that carries events to the engine.
output.elasticsearch:
  hosts: ["https://elasticsearch:9200"]
```

**2. Run Filebeat through Log10x**, Filebeat is launched as a child process of the sidecar, so start them as a single pipeline:

```bash
filebeat -c filebeat.yml -e 2>&1 | tenx run @run/input/forwarder/filebeat @apps/receiver
```

On Kubernetes, install the `log10x-elastic/filebeat` chart, which is the supported path. It carries the image swap, the licence wiring and probes that observe the engine as chart values:

```bash
helm repo add log10x-elastic https://log-10x.github.io/elastic-helm-charts
helm repo update
helm upgrade --install my-receiver log10x-elastic/filebeat \
  --version 1.5.0 \
  --set tenx.enabled=true \
  --set-file tenx.licenseJwt=license.jwt \
  --namespace logging --create-namespace
```

The upstream `elastic/filebeat` chart still works as a values overlay for installs already on it, but that repository was archived by Elastic in April 2023 and its probes test Filebeat only, so a frozen engine holds the pod Ready. See the [Helm chart overlay](https://doc.log10x.com/apps/receiver/deploy/#filebeat) for both paths and the probe detail.

For read-only Reporter mode (no event diversion) swap `tenx-receive.js` for `tenx-report.js` and run against `@apps/reporter`, see the [Reporter Quickstart](https://doc.log10x.com/apps/reporter/run/#filebeat).

## :material-wrench-outline: Config Files

To configure the Filebeat module, [:material-cog: Edit](https://doc.log10x.com/config/app/#module-config "Learn how to edit app and module configurations") these files.  

Below is the default configuration from: [filebeat/config.yaml](https://github.dev/log-10x/config/blob/main/pipelines/run/input/forwarder/filebeat/config.yaml "filebeat/config.yaml"){target="\_blank"}.  
  
<div class="edit-options">
    <a class="md-button tenx-edit-online-button" data-tooltip="Edit online on github.dev" href="https://github.dev/log-10x/config/blob/main/pipelines/run/input/forwarder/filebeat/config.yaml" target="_blank" rel="noopener noreferrer">
        <span class="twemoji" style="margin-right: 0.3rem;">
            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                <path d="M12 .297c-6.63 0-12 5.373-12 12 0 5.303 3.438 9.8 8.205 11.385.6.113.82-.258.82-.577 0-.285-.01-1.04-.015-2.04-3.338.724-4.042-1.61-4.042-1.61C4.422 18.07 3.633 17.7 3.633 17.7c-1.087-.744.084-.729.084-.729 1.205.084 1.838 1.236 1.838 1.236 1.07 1.835 2.809 1.305 3.495.998.108-.776.417-1.305.76-1.605-2.665-.3-5.466-1.332-5.466-5.93 0-1.31.465-2.38 1.235-3.22-.135-.303-.54-1.523.105-3.176 0 0 1.005-.322 3.3 1.23.96-.267 1.98-.399 3-.405 1.02.006 2.04.138 3 .405 2.28-1.552 3.285-1.23 3.285-1.23.645 1.653.24 2.873.12 3.176.765.84 1.23 1.91 1.23 3.22 0 4.61-2.805 5.625-5.475 5.92.42.36.81 1.096.81 2.22 0 1.606-.015 2.896-.015 3.286 0 .315.21.69.825.57C20.565 22.092 24 17.592 24 12.297c0-6.627-5.373-12-12-12"></path>
            </svg>
        </span> Edit Online
    </a>
    <button class="md-button tenx-config.yaml0-edit-button" data-tooltip="Edit configuration file" data-dialog-id="config-yaml0-dialog">
        <span style="margin-right: 0.3rem;">
            <span class="twemoji">
                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                    <path d="M20.71,7.04C21.1,6.65 21.1,6 20.71,5.63L18.37,3.29C18,2.9 17.35,2.9 16.96,3.29L15.12,5.12L18.87,8.87M3,17.25V21H6.75L17.81,9.93L14.06,6.18L3,17.25Z"></path>
                </svg>
            </span>
        </span>Edit Locally
    </button>
</div>

<dialog id="config-yaml0-dialog" class="md-dialog md-dialog--editor">
    <div class="editor-dialog-wrapper">
        <div class="editor-dialog-header">
            <span class="editor-dialog-title">Edit config.yaml Locally</span>
            <div class="editor-header-actions">
                <button class="editor-toolbar-btn yaml-editor-locations" data-tooltip="Save">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path></svg>
                </button>
                <button class="editor-toolbar-btn yaml-editor-reset" data-tooltip="Reset to default">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M12.5 8c-2.65 0-5.05 1-6.9 2.6L2 7v9h9l-3.62-3.62c1.39-1.16 3.16-1.88 5.12-1.88 3.54 0 6.55 2.31 7.6 5.5l2.37-.78C21.08 11.03 17.15 8 12.5 8z"></path></svg>
                </button>
                <button class="editor-toolbar-btn yaml-editor-copy" data-tooltip="Copy to clipboard">
                    <svg class="icon-copy" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path></svg>
                    <svg class="icon-check" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg>
                </button>
                <span class="header-divider"></span>
                <button class="editor-toolbar-btn yaml-editor-fullscreen" data-tooltip="Fullscreen">
                    <svg class="icon-maximize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5,5H10V7H7V10H5V5M14,5H19V10H17V7H14V5M17,14H19V19H14V17H17V14M10,17V19H5V14H7V17H10Z"></path></svg>
                    <svg class="icon-minimize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M5,16H8V19H10V14H5V16M14,14V19H16V16H19V14H14M16,5V8H19V10H14V5H16M10,5V10H5V8H8V5H10Z"></path></svg>
                </button>
                <span class="header-divider"></span>
                <button class="editor-toolbar-btn editor-dialog-close" onclick="closeDialog('config-yaml0-dialog')" data-tooltip="Close">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path></svg>
                </button>
            </div>
        </div>
        <div class="editor-dialog-content">
            <div class="yaml-editor-container"></div>
        </div>
        <div class="yaml-editor-statusbar">
            <span class="yaml-editor-status"></span>
        </div>
    </div>
    <!-- Locations Popup -->
    <div class="locations-popup" style="display: none;">
        <div class="locations-popup-content">
            <div class="locations-popup-header">
                <span class="locations-header-label">Download and save to:</span>
                <button class="locations-popup-close" aria-label="Close">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="16" height="16">
                        <path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path>
                    </svg>
                </button>
            </div>
            <ul class="locations-list">
                <li>
                    <span class="location-label">Linux / Docker / macOS
                        <span class="help-icon" data-tooltip="Default system location. The engine automatically reads configs from here at startup. Best for production deployments.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="default-path location-path" data-tooltip=""
                            data-copy-osx="/etc/log10x/config/run/input/forwarder/filebeat/config.yaml"
                            data-copy-nix="/etc/log10x/config/run/input/forwarder/filebeat/config.yaml"
                            data-copy-win="C:\log10x\configs/run/input/forwarder/filebeat/config.yaml"></code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
                <li>
                    <span class="location-label">Custom directory
                        <span class="help-icon" data-tooltip="Set TENX_CONFIG environment variable to point to a custom config directory. Useful when you want configs in a non-standard location.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="location-path" data-tooltip="$TENX_CONFIG/run/input/forwarder/filebeat/config.yaml">$TENX_CONFIG/run/input/forwarder/filebeat/config.yaml</code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
                <li>
                    <span class="location-label">Within cloned repo
                        <span class="help-icon" data-tooltip="First run: git clone github.com/log-10x/config. Then save the file to this path within the cloned folder. Use for version control.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="location-path" data-tooltip="./pipelines/run/input/forwarder/filebeat/config.yaml">./pipelines/run/input/forwarder/filebeat/config.yaml</code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
            </ul>
            <div class="locations-popup-footer">
                <button class="locations-download-btn" title="Download config file">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                        <path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path>
                    </svg>
                    <span>Download</span>
                </button>
            </div>
        </div>
    </div>
</dialog>

<template class="tenx-config-schema" data-encoding="base64">ewogICJ0eXBlIiA6ICJvYmplY3QiLAogICJwcm9wZXJ0aWVzIiA6IHsKICAgICJpbmNsdWRlIiA6IHsKICAgICAgInR5cGUiIDogImFycmF5IiwKICAgICAgIml0ZW1zIiA6IHsKICAgICAgICAidHlwZSIgOiAic3RyaW5nIgogICAgICB9CiAgICB9LAogICAgInRlbngiIDogewogICAgICAidHlwZSIgOiAic3RyaW5nIgogICAgfSwKICAgICJmaWxlYmVhdCIgOiB7CiAgICAgICJ0eXBlIiA6ICJvYmplY3QiLAogICAgICAiYWRkaXRpb25hbFByb3BlcnRpZXMiIDogZmFsc2UsCiAgICAgICJwcm9wZXJ0aWVzIiA6IHsKICAgICAgICAib3V0cHV0IiA6IHsKICAgICAgICAgICJ0eXBlIiA6ICJvYmplY3QiLAogICAgICAgICAgImFkZGl0aW9uYWxQcm9wZXJ0aWVzIiA6IGZhbHNlLAogICAgICAgICAgInByb3BlcnRpZXMiIDogewogICAgICAgICAgICAiZmllbGRzIiA6IHsKICAgICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgICAiYXJyYXkiLAogICAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgICBdLAogICAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJMaXN0IG9mIFRlblhPYmplY3QgZmllbGQgbmFtZXMgdG8gaW5jbHVkZSBhbG9uZ3NpZGUgdGhlIG1haW4gZXZlbnQgaW4gb3V0cHV0XG5cblNwZWNpZmllcyBUZW5YT2JqZWN0IGZpZWxkIG5hbWVzIHRvIGVtaXQgYWxvbmdzaWRlIHRoZSBtYWluIGV2ZW50IHRleHQgd2hlbiB3cml0aW5nIGJhY2sgdG8gdGhlIEZpbGViZWF0IGZvcndhcmRlci4gV2hlbiBlbXB0eSAoZGVmYXVsdCksIG9ubHkgdGhlIG1haW4gZXZlbnQgZmllbGQgaXMgd3JpdHRlbi4gRXhhbXBsZSBmaWVsZHM6IGxldmVsLCBncm91cCwgc3ltYm9sTWVzc2FnZS4gKERlZmF1bHQ6IFtdKSIsCiAgICAgICAgICAgICAgIml0ZW1zIiA6IHsKICAgICAgICAgICAgICAgICJ0eXBlIiA6ICJzdHJpbmciCiAgICAgICAgICAgICAgfSwKICAgICAgICAgICAgICAiZGVmYXVsdCIgOiBbIF0KICAgICAgICAgICAgfSwKICAgICAgICAgICAgImVuY29kZVR5cGUiIDogewogICAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgICAgXSwKICAgICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiT3V0cHV0IGZvcm1hdCB3aGVuIG91dHB1dEZpZWxkcyBhcmUgc2V0LiBQb3NzaWJsZSB2YWx1ZXM6IFtqc29uLCBkZWxpbWl0ZWRdXG5cblNwZWNpZmllcyBob3cgdGhlIGNvbWJpbmVkIG91dHB1dCAobWFpbiBldmVudCBmaWVsZCBwbHVzIG91dHB1dEZpZWxkcykgaXMgZW5jb2RlZCB3aGVuIHdyaXRpbmcgYmFjayB0byB0aGUgRmlsZWJlYXQgZm9yd2FyZGVyLiBQb3NzaWJsZSB2YWx1ZXM6IC0gKipqc29uKio6IGZvcm1hdHMgYWxsIGZpZWxkcyBhcyBhIEpTT04gb2JqZWN0IC0gKipkZWxpbWl0ZWQqKjogZm9ybWF0cyBmaWVsZCB2YWx1ZXMgc2VwYXJhdGVkIGJ5IHRoZSBvdXRwdXQgZGVsaW1pdGVyIE9ubHkgdGFrZXMgZWZmZWN0IHdoZW4gZmlsZWJlYXRPdXRwdXRGaWVsZHMgaXMgc2V0LiAoRGVmYXVsdDogZGVsaW1pdGVkKSIsCiAgICAgICAgICAgICAgImRlZmF1bHQiIDogImRlbGltaXRlZCIKICAgICAgICAgICAgfQogICAgICAgICAgfQogICAgICAgIH0sCiAgICAgICAgImNvbmZpZ1BhdGgiIDogewogICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICBdLAogICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIkNvbmZpZ3VyYXRpb24gZmlsZSBwYXRoXG5cblBhdGggY29udGFpbmluZyBGaWxlYmVhdCBjb25maWd1cmF0aW9uIGZpbGVzIgogICAgICAgIH0sCiAgICAgICAgImxvZ3NQYXRoIiA6IHsKICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICJudWxsIgogICAgICAgICAgXSwKICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJMb2cgZmlsZSBwYXRoXG5cblBhdGggY29udGFpbmluZyBGaWxlYmVhdCBsb2cgZmlsZXMiCiAgICAgICAgfSwKICAgICAgICAibmFtZSIgOiB7CiAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAibnVsbCIKICAgICAgICAgIF0sCiAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiRmlsZWJlYXQgbG9nIG5hbWVcblxuTmFtZSBvZiB0aGUgRmlsZWJlYXQgZmlsZXMgd2hlcmUgdGhlIGxvZ3MgYXJlIHdyaXR0ZW4gdG8iCiAgICAgICAgfSwKICAgICAgICAicGF0aCIgOiB7CiAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAibnVsbCIKICAgICAgICAgIF0sCiAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiT3V0cHV0IHBhdGggZm9yIEZpbGViZWF0IGxvZ3NcblxuQ29uZmlndXJlcyB0aGUgcGF0aCB3aGVyZSB0aGUgRmlsZWJlYXQgbG9ncyBhcmUgd3JpdHRlbiIKICAgICAgICB9LAogICAgICAgICJpbnRlcnZhbCIgOiB7CiAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAibnVsbCIKICAgICAgICAgIF0sCiAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiRW5hYmxlIEZpbGViZWF0IGxvZyBmaWxlIHJvdGF0aW9uXG5cbkVuYWJsZSBGaWxlYmVhdCBsb2cgZmlsZSByb3RhdGlvbiBvbiB0aW1lIGludGVydmFscyBpbiBhZGRpdGlvbiB0byB0aGUgc2l6ZS1iYXNlZCByb3RhdGlvbiIKICAgICAgICB9LAogICAgICAgICJyb3RhdGUiIDogewogICAgICAgICAgInR5cGUiIDogIm9iamVjdCIsCiAgICAgICAgICAiYWRkaXRpb25hbFByb3BlcnRpZXMiIDogZmFsc2UsCiAgICAgICAgICAicHJvcGVydGllcyIgOiB7CiAgICAgICAgICAgICJldmVyeUJ5dGVzIiA6IHsKICAgICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgICAibnVtYmVyIiwKICAgICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgICAgXSwKICAgICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiRmlsZWJlYXQgbG9nIGZpbGUgc2l6ZSBsaW1pdFxuXG5Db25maWd1cmUgRmlsZWJlYXQgbG9nIGZpbGUgc2l6ZSBsaW1pdC4gSWYgbGltaXQgaXMgcmVhY2hlZCwgbG9nIGZpbGUgd2lsbCBiZSBhdXRvbWF0aWNhbGx5IHJvdGF0ZWQgKEFjY2VwdHMgbnVtYmVyIG9yIHN0cmluZyB3aXRoICQ9IHByZWZpeCBmb3IgcnVudGltZSBldmFsdWF0aW9uKSIKICAgICAgICAgICAgfSwKICAgICAgICAgICAgIm9uU3RhcnR1cCIgOiB7CiAgICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICAgImJvb2xlYW4iLAogICAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgICBdLAogICAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJSb3RhdGUgZXhpc3RpbmcgRmlsZWJlYXQgbG9ncyB1cG9uIHN0YXJ0dXBcblxuUm90YXRlIGV4aXN0aW5nIEZpbGViZWF0IGxvZ3Mgb24gc3RhcnR1cCByYXRoZXIgdGhhbiBhcHBlbmRpbmcgdGhlbSB0byB0aGUgZXhpc3RpbmcgZmlsZSAoQWNjZXB0cyBib29sZWFuIG9yIHN0cmluZyB3aXRoICQ9IHByZWZpeCBmb3IgcnVudGltZSBldmFsdWF0aW9uKSIKICAgICAgICAgICAgfQogICAgICAgICAgfQogICAgICAgIH0sCiAgICAgICAgInBlcm1pc3Npb25zIiA6IHsKICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICJudWxsIgogICAgICAgICAgXSwKICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJMb2cgZmlsZSBwZXJtaXNzaW9ucyBtYXNrXG5cblBPU0lYIHBlcm1pc3Npb25zIG1hc2sgdG8gYXBwbHkgd2hlbiByb3RhdGluZyBGaWxlYmVhdCBsb2cgZmlsZXMiCiAgICAgICAgfSwKICAgICAgICAia2VlcEZpbGVzIiA6IHsKICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgIm51bWJlciIsCiAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAibnVsbCIKICAgICAgICAgIF0sCiAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiTnVtYmVyIG9mIHJvdGF0ZWQgRmlsZWJlYXQgbG9nIGZpbGVzIHRvIGtlZXBcblxuTnVtYmVyIG9mIHJvdGF0ZWQgRmlsZWJlYXQgbG9nIGZpbGVzIHRvIGtlZXAuIE9sZGVzdCBmaWxlcyB3aWxsIGJlIGRlbGV0ZWQgZmlyc3QgKEFjY2VwdHMgbnVtYmVyIG9yIHN0cmluZyB3aXRoICQ9IHByZWZpeCBmb3IgcnVudGltZSBldmFsdWF0aW9uKSIKICAgICAgICB9LAogICAgICAgICJpbnB1dFJlYWR5IiA6IHsKICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICJudWxsIgogICAgICAgICAgXSwKICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJJbnRlcm5hbFxuXG5BbiBpbnRlcm5hbCBtYXJrZXIgdXNlZCB0byBpbmRpY2F0ZSBGaWxlYmVhdCBpbnB1dCByZWFkeSIKICAgICAgICB9LAogICAgICAgICJsb2dnaW5nVG8iIDogewogICAgICAgICAgInR5cGUiIDogIm9iamVjdCIsCiAgICAgICAgICAiYWRkaXRpb25hbFByb3BlcnRpZXMiIDogZmFsc2UsCiAgICAgICAgICAicHJvcGVydGllcyIgOiB7CiAgICAgICAgICAgICJmaWxlcyIgOiB7CiAgICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICAgImJvb2xlYW4iLAogICAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgICBdLAogICAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJDb250cm9sIGxvZyBmaWxlIHJvdGF0aW9uXG5cblNldHMgRmlsZWJlYXQgbG9nZ2luZyB0byByb3RhdGluZyBmaWxlcy4gU2V0IGxvZ2dpbmcudG9fZmlsZXMgdG8gZmFsc2UgdG8gZGlzYWJsZSBsb2dnaW5nIHRvIGZpbGVzLiAoQWNjZXB0cyBib29sZWFuIG9yIHN0cmluZyB3aXRoICQ9IHByZWZpeCBmb3IgcnVudGltZSBldmFsdWF0aW9uKSIKICAgICAgICAgICAgfSwKICAgICAgICAgICAgInN0ZGVyciIgOiB7CiAgICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICAgImJvb2xlYW4iLAogICAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgICBdLAogICAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJGaWxlYmVhdCBsb2dnaW5nIHRvIHN0ZGVyclxuXG5GaWxlYmVhdCBsb2dnaW5nIHRvIHN0ZGVyci4gU2V0IGxvZ2dpbmcudG9fc3RkZXJyIHRvIGZhbHNlIHRvIGRpc2FibGUgbG9nZ2luZyB0byBzdGRlcnIuIChBY2NlcHRzIGJvb2xlYW4gb3Igc3RyaW5nIHdpdGggJD0gcHJlZml4IGZvciBydW50aW1lIGV2YWx1YXRpb24pIgogICAgICAgICAgICB9LAogICAgICAgICAgICAic3lzbG9nIiA6IHsKICAgICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgICAiYm9vbGVhbiIsCiAgICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICAgIF0sCiAgICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIkZpbGViZWF0IGxvZ2dpbmcgdG8gc3lzbG9nXG5cbkZpbGViZWF0IGxvZ2dpbmcgdG8gc3lzbG9nLiBTZXQgbG9nZ2luZy50b19zeXNsb2cgdG8gZmFsc2UgdG8gZGlzYWJsZSBsb2dnaW5nIHRvIHN5c2xvZy4gKEFjY2VwdHMgYm9vbGVhbiBvciBzdHJpbmcgd2l0aCAkPSBwcmVmaXggZm9yIHJ1bnRpbWUgZXZhbHVhdGlvbikiCiAgICAgICAgICAgIH0KICAgICAgICAgIH0KICAgICAgICB9CiAgICAgIH0KICAgIH0sCiAgICAicmF3T3V0cHV0VW5peFNvY2tldEFkZHJlc3MiIDogewogICAgICAidHlwZSIgOiBbCiAgICAgICAgInN0cmluZyIsCiAgICAgICAgIm51bGwiCiAgICAgIF0sCiAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJJbnRlcm5hbFxuXG5JbnRlcm5hbCB2YXJpYWJsZSB1c2VkIHRvIGxvYWQgc29ja2V0IGFkZHJlc3MgdG8gYmUgdXNlZCBpbiBtdWx0aXBsZSBlbmNvZGVycyIKICAgIH0KICB9LAogICJhZGRpdGlvbmFsUHJvcGVydGllcyIgOiB0cnVlCn0=</template>

```yaml
# 🔟❎ 'run' Filebeat receiver configuration
#
# Configures an input that reads events from a Filebeat forwarder (Filebeat
# runs as a subprocess of the sidecar) and an output that writes processed
# events back to Filebeat over a Unix domain socket.
# When 'receiverOptimize' is enabled, events are encoded for volume reduction.
#
# To learn more see https://doc.log10x.com/run/input/forwarder/filebeat/

tenx: run

# =============================== Dependencies ================================

include:
  - run/input/forwarder/config.yaml
  - run/modules/input/forwarder/filebeat

# ============================== Filebeat Options ==============================

filebeat:

  # ----------------------------- Output Options ----------------------------

  output:

    # 'fields' specifies TenXObject field names to emit alongside the main
    #  event. When set, enrichment fields are included in the sidecar output
    #  for forwarder post-processing.
    #  Example: fields: [level, group, symbolMessage]
    fields: []

    # 'encodeType' controls the output format when fields is set.
    #  Possible values: 'json' or 'delimited'
    encodeType: delimited
```

## :material-menu: Options

Specify the options below to [configure](/config "configure") the Filebeat:

|Name|Description|Category|
|---|---|---|
|[filebeatOutputFields](#filebeatoutputfields "list of TenXObject field names to include alongside the main event in output")|List of TenXObject field names to include alongside the main event in output|Output|
|[filebeatOutputEncodeType](#filebeatoutputencodetype "output format when outputFields are set. Possible values: [json, delimited]")|Output format when outputFields are set. Possible values: \[json, delimited\]|Output|
|[filebeatConfigPath](#filebeatconfigpath "configuration file path")|Configuration file path|FilebeatLog|
|[filebeatLogsPath](#filebeatlogspath "log file path")|Log file path|FilebeatLog|
|[filebeatLoggingToFiles](#filebeatloggingtofiles "control log file rotation")|Control log file rotation|FilebeatLog|
|[filebeatLoggingToStderr](#filebeatloggingtostderr "Filebeat logging to stderr")|Filebeat logging to stderr|FilebeatLog|
|[filebeatLoggingToSyslog](#filebeatloggingtosyslog "Filebeat logging to syslog")|Filebeat logging to syslog|FilebeatLog|
|[filebeatName](#filebeatname "Filebeat log name")|Filebeat log name|FilebeatLog|
|[filebeatPath](#filebeatpath "output path for Filebeat logs")|Output path for Filebeat logs|FilebeatLog|
|[filebeatInterval](#filebeatinterval "enable Filebeat log file rotation")|Enable Filebeat log file rotation|FilebeatLog|
|[filebeatRotateEveryBytes](#filebeatrotateeverybytes "Filebeat log file size limit")|Filebeat log file size limit|FilebeatLog|
|[filebeatRotateOnStartup](#filebeatrotateonstartup "rotate existing Filebeat logs upon startup")|Rotate existing Filebeat logs upon startup|FilebeatLog|
|[filebeatPermissions](#filebeatpermissions "log file permissions mask")|Log file permissions mask|FilebeatLog|
|[filebeatKeepFiles](#filebeatkeepfiles "number of rotated Filebeat log files to keep")|Number of rotated Filebeat log files to keep|FilebeatLog|
|[rawOutputUnixSocketAddress](#rawoutputunixsocketaddress "internal")|Internal|Internal|
|[filebeatInputReady](#filebeatinputready "internal")|Internal|Internal|

### Output

#### :material-menu-right-outline:**`filebeatOutputFields`**

List of TenXObject field names to include alongside the main event in output.

|Type|Default|Category|
|---|---|---|
|List|\[\]|Output|

Specifies TenXObject field names to emit alongside the main event text
when writing back to the Filebeat forwarder. When empty (default), only
the main event field is written. Example fields: level, group, symbolMessage.


#### :material-menu-right-outline:**`filebeatOutputEncodeType`**

Output format when outputFields are set. Possible values: \[json, delimited\].

|Type|Default|Category|
|---|---|---|
|String|delimited|Output|

Specifies how the combined output (main event field plus outputFields)
is encoded when writing back to the Filebeat forwarder. Possible values:

- **json**: formats all fields as a JSON object
- **delimited**: formats field values separated by the output delimiter
  Only takes effect when filebeatOutputFields is set.


### FilebeatLog

#### :material-menu-right-outline:**`filebeatConfigPath`**

Configuration file path.

|Type|Default|Category|
|---|---|---|
|File||FilebeatLog|

Path containing Filebeat configuration files.


#### :material-menu-right-outline:**`filebeatLogsPath`**

Log file path.

|Type|Default|Category|
|---|---|---|
|File||FilebeatLog|

Path containing Filebeat log files.


#### :material-menu-right-outline:**`filebeatLoggingToFiles`**

Control log file rotation.

|Type|Default|Category|
|---|---|---|
|Boolean|false|FilebeatLog|

Sets Filebeat logging to rotating files.
Set logging.to\_files to false to disable logging to files.


#### :material-menu-right-outline:**`filebeatLoggingToStderr`**

Filebeat logging to stderr.

|Type|Default|Category|
|---|---|---|
|Boolean|false|FilebeatLog|

Filebeat logging to stderr.
Set logging.to\_stderr to false to disable logging to stderr.


#### :material-menu-right-outline:**`filebeatLoggingToSyslog`**

Filebeat logging to syslog.

|Type|Default|Category|
|---|---|---|
|Boolean|false|FilebeatLog|

Filebeat logging to syslog.
Set logging.to\_syslog to false to disable logging to syslog.


#### :material-menu-right-outline:**`filebeatName`**

Filebeat log name.

|Type|Default|Category|
|---|---|---|
|File||FilebeatLog|

Name of the Filebeat files where the logs are written to.


#### :material-menu-right-outline:**`filebeatPath`**

Output path for Filebeat logs.

|Type|Default|Category|
|---|---|---|
|File||FilebeatLog|

Configures the path where the Filebeat logs are written.


#### :material-menu-right-outline:**`filebeatInterval`**

Enable Filebeat log file rotation.

|Type|Default|Category|
|---|---|---|
|String|""|FilebeatLog|

Enable Filebeat log file rotation on time intervals in addition to the size-based rotation.


#### :material-menu-right-outline:**`filebeatRotateEveryBytes`**

Filebeat log file size limit.

|Type|Default|Category|
|---|---|---|
|Number|0|FilebeatLog|

Configure Filebeat log file size limit.
If limit is reached, log file will be automatically rotated.


#### :material-menu-right-outline:**`filebeatRotateOnStartup`**

Rotate existing Filebeat logs upon startup.

|Type|Default|Category|
|---|---|---|
|Boolean|false|FilebeatLog|

Rotate existing Filebeat logs on startup rather than appending them to the existing file.


#### :material-menu-right-outline:**`filebeatPermissions`**

Log file permissions mask.

|Type|Default|Category|
|---|---|---|
|String|""|FilebeatLog|

POSIX permissions mask to apply when rotating Filebeat log files.


#### :material-menu-right-outline:**`filebeatKeepFiles`**

Number of rotated Filebeat log files to keep.

|Type|Default|Category|
|---|---|---|
|Number|0|FilebeatLog|

Number of rotated Filebeat log files to keep.
Oldest files will be deleted first.


### Internal

#### :material-menu-right-outline:**`rawOutputUnixSocketAddress`**

Internal.

|Type|Default|Category|
|---|---|---|
|String|""|Internal|

Internal variable used to load socket address to be used in multiple encoders.


#### :material-menu-right-outline:**`filebeatInputReady`**

Internal.

|Type|Default|Category|
|---|---|---|
|String|""|Internal|

An internal marker used to indicate Filebeat input ready.


<br/>:material-github: This module is defined in [filebeat/module.yaml](https://github.com/log-10x/modules/tree/main/pipelines/run/modules/input/forwarder/filebeat/module.yaml "filebeat/module.yaml"){target="\_blank"}.

