# Analyse the log files

**URL:** <https://discuss.elastic.co/t/analyse-the-log-files/66815>\
**Category:** Logstash\
**Created:** [November 22, 2016, 6:59am UTC](https://discuss.elastic.co/t/analyse-the-log-files/66815 "2016-11-22T06:59:59Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![parmeet81](https://avatars.discourse-cdn.com/v4/letter/p/5f9b8f/32.png) [@parmeet81](https://discuss.elastic.co/u/parmeet81)\
**Post date:** [November 22, 2016, 6:59am UTC](https://discuss.elastic.co/t/analyse-the-log-files/66815/1 "2016-11-22T06:59:59Z")

</div>

Hi,

I just finished setting up ELK on log server(one folder for each new issue) and edited my filebeat.yml file for the log folder. So the next step is to create index so that it can be easily searched. so do I need to set up different filebeat.yml file for every new issue or I can give the path of root folder and it will automatically create the index and will show me th result in Kibana. Can you please guide me how it will do it.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 22, 2016, 7:10am UTC](https://discuss.elastic.co/t/analyse-the-log-files/66815/2 "2016-11-22T07:10:43Z")

</div>

Filebeat supports wildcards so if you have a directory hierarchy you can tell Filebeat to monitor all those files with a single filename pattern.

---

<div class="post-metadata">

**Author:** ![parmeet81](https://avatars.discourse-cdn.com/v4/letter/p/5f9b8f/32.png) [@parmeet81](https://discuss.elastic.co/u/parmeet81)\
**Post date:** [November 22, 2016, 7:18am UTC](https://discuss.elastic.co/t/analyse-the-log-files/66815/4 "2016-11-22T07:18:46Z")

</div>

My Hierarchy is

/log/A/1.log, 2.log, 3.log  
/log/B/1.log, 2.log, 3.log

Can you please point me to the documentation or give me an example. I am a new bie to this framework

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 22, 2016, 7:57am UTC](https://discuss.elastic.co/t/analyse-the-log-files/66815/5 "2016-11-22T07:57:16Z")

</div>

Standard wildcard patterns apply, so /log/_/_.log should work for you.

[https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#\_paths](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#_paths)

---

<div class="post-metadata">

**Author:** ![parmeet81](https://avatars.discourse-cdn.com/v4/letter/p/5f9b8f/32.png) [@parmeet81](https://discuss.elastic.co/u/parmeet81)\
**Post date:** [November 22, 2016, 8:09am UTC](https://discuss.elastic.co/t/analyse-the-log-files/66815/6 "2016-11-22T08:09:05Z")

</div>

where do I specify for Index .. so that I can search for A or B

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 22, 2016, 10:36am UTC](https://discuss.elastic.co/t/analyse-the-log-files/66815/7 "2016-11-22T10:36:13Z")

</div>

Are you going to use Filebeat with Logstash or will you send directly to Elasticsearch?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2016, 10:36am UTC](https://discuss.elastic.co/t/analyse-the-log-files/66815/8 "2016-12-20T10:36:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
