Blog
Using Lua Scripts in Elastic Beats for Lightweight Edge Processing
Learn how to add Lua processors to Filebeat for custom transformations while monitoring resource impact.
Published by Tasadduq Burney
07 Apr 2026, 14:40 UTC
3 min58.2K views0

The Edge Processing Dilemma
When shipping logs from many servers, you want to cleanse or enrich data before it leaves the host, but you cannot let the shipper consume too much CPU or memory. Elastic Beats solves this by keeping the agent lightweight and moving heavy processing to Logstash or Elasticsearch ingest pipelines.
The takeaway: Beats include a Lua interpreter that lets you add custom transformations without recompiling the Go binary, but you must watch the resource cost on the host.
How Beats Stay Lightweight
Beats are written in Go, giving a small memory footprint and fast start‑up. Unlike Logstash, which runs on the JVM, a Beat is meant to do one thing—such as tailing a file—and ship events immediately.
To avoid overwhelming a slow backend, Beats implement a backpressure mechanism: if the output (Elasticsearch or Logstash) cannot keep up, the Beat reduces its read rate, preventing unbounded memory growth.
Adding Custom Logic with Lua
Standard processors cover many cases, but for tasks like masking sensitive data or complex conditional renaming, you can use a
If you apply complex logic to a high‑volume stream (e.g., >5 000 events / second), the Lua interpreter can become a bottleneck, increasing CPU usage and activating the Beat’s backpressure mechanism. In such cases, move the transformation to a Logstash pipeline where you can scale independently.
Verification and Monitoring
Monitor the built‑in metrics
script processor with Lua.
Example: Mask an API Key
Assume a log line contains an api_key field that must be masked before leaving the host.
# filebeat.yml snippet
processors:
- script:
lang: lua
source: |
function process(event)
if event.fields.api_key then
local key = event.fields.api_key
-- keep last 4 chars, mask the rest
event.fields.api_key = string.rep('*', #key - 4) .. string.sub(key, -4)
end
return event
end
Where to apply: Edit filebeat.yml on the source host and restart the Filebeat service.
Permissions: The user running Filebeat must be able to read the configuration file.
Expected check: After restart, view events in Kibana; the api_key field should show asterisks followed by the last four characters.
Risk: A poorly written Lua script (e.g., infinite loop or heavy regex) can spike CPU on the host and trigger backpressure, slowing log ingestion.
Trade‑off: Edge vs. Central Processing
Moving logic to the edge has advantages and drawbacks.
| Aspect | Edge Processing (Lua) | Central Processing (Logstash) |
|---|---|---|
| CPU impact | Consumes resources on the application server | Uses a dedicated processing cluster |
| Security | Sensitive data is masked before it leaves the host | Raw data travels over the network |
| Updates | Requires restarting the Beat on each host | Can be changed centrally without touching agents |
beat.cpu.usage and beat.mem.usage (available via Metricbeat or the Beat’s HTTP endpoint). A rise in CPU accompanied by a drop in the events.out rate signals that the Lua script is too heavy. At that point, either simplify the script or offload the work to Logstash.0 replies
A thoughtful contribution can make all the difference. Be the first to share one.