# Adding more logs to filebeat to export and on elk server to logstash to receive

**URL:** <https://discuss.elastic.co/t/adding-more-logs-to-filebeat-to-export-and-on-elk-server-to-logstash-to-receive/64527>\
**Category:** Logstash\
**Created:** [November 1, 2016, 8:15am UTC](https://discuss.elastic.co/t/adding-more-logs-to-filebeat-to-export-and-on-elk-server-to-logstash-to-receive/64527 "2016-11-01T08:15:55Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![pkhodaveissi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkhodaveissi/32/12866_2.png) [@pkhodaveissi](https://discuss.elastic.co/u/pkhodaveissi)\
**Post date:** [November 1, 2016, 8:15am UTC](https://discuss.elastic.co/t/adding-more-logs-to-filebeat-to-export-and-on-elk-server-to-logstash-to-receive/64527/1 "2016-11-01T08:15:55Z")

</div>

Hello  
I have this starter config which derives from [DigitalOcean](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-ubuntu-16-04) and looks like this:  
input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}

I like to add mysql slow query logs and tomcat logs, each from a different server to this config, how the approach would look like and how to handle two or more multiline pattern in input and then filter sections?  
thanks a lot  
Pierre

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 1, 2016, 8:25am UTC](https://discuss.elastic.co/t/adding-more-logs-to-filebeat-to-export-and-on-elk-server-to-logstash-to-receive/64527/2 "2016-11-01T08:25:34Z")

</div>

- Set the document type on the Filebeat side and it'll get carried over to Logstash. Then add conditional filters to process events of different types in different ways.
- Do multiline processing as close to the source as possible, i.e. do it in Filebeat and not in Logstash.

---

<div class="post-metadata">

**Author:** ![pkhodaveissi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkhodaveissi/32/12866_2.png) [@pkhodaveissi](https://discuss.elastic.co/u/pkhodaveissi)\
**Post date:** [November 1, 2016, 8:44am UTC](https://discuss.elastic.co/t/adding-more-logs-to-filebeat-to-export-and-on-elk-server-to-logstash-to-receive/64527/3 "2016-11-01T08:44:33Z")

</div>

thank you for your comment, is there any example showing how would the approach look like for each part, "Set the document type on the Filebeat side", "add conditional filters to process events of different types in different ways", "doing multiline processing in source" ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 1, 2016, 9:28am UTC](https://discuss.elastic.co/t/adding-more-logs-to-filebeat-to-export-and-on-elk-server-to-logstash-to-receive/64527/4 "2016-11-01T09:28:57Z")

</div>

> how would the approach look like for each part, "Set the document type on the Filebeat side",

I believe the Filebeat option is named `document_type`. See its documentation.

> "add conditional filters to process events of different types in different ways",

> **[Accessing event data and fields | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html)**

> "doing multiline processing in source" ?

> **[Manage multiline messages | Filebeat Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html)**

---

<div class="post-metadata">

**Author:** ![pkhodaveissi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkhodaveissi/32/12866_2.png) [@pkhodaveissi](https://discuss.elastic.co/u/pkhodaveissi)\
**Post date:** [November 1, 2016, 9:39am UTC](https://discuss.elastic.co/t/adding-more-logs-to-filebeat-to-export-and-on-elk-server-to-logstash-to-receive/64527/5 "2016-11-01T09:39:00Z")

</div>

thank you so much for your answer, I'll go through it step by step, to safe assure the first part, you mean input\_type option, don't you?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 1, 2016, 9:41am UTC](https://discuss.elastic.co/t/adding-more-logs-to-filebeat-to-export-and-on-elk-server-to-logstash-to-receive/64527/6 "2016-11-01T09:41:25Z")

</div>

> you mean input\_type option, don't you?

No, I really mean `document_type`.

---

<div class="post-metadata">

**Author:** ![pkhodaveissi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkhodaveissi/32/12866_2.png) [@pkhodaveissi](https://discuss.elastic.co/u/pkhodaveissi)\
**Post date:** [November 1, 2016, 9:46am UTC](https://discuss.elastic.co/t/adding-more-logs-to-filebeat-to-export-and-on-elk-server-to-logstash-to-receive/64527/7 "2016-11-01T09:46:15Z")

</div>

Found it (document\_type) here: [Filebeat Configuration Options](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#_document_type)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:31am UTC](https://discuss.elastic.co/t/adding-more-logs-to-filebeat-to-export-and-on-elk-server-to-logstash-to-receive/64527/8 "2017-07-06T04:31:48Z")

</div>


