# Applying configuration to all prospectors

**URL:** <https://discuss.elastic.co/t/applying-configuration-to-all-prospectors/109431>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 28, 2017, 4:04pm UTC](https://discuss.elastic.co/t/applying-configuration-to-all-prospectors/109431 "2017-11-28T16:04:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![vkurup](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vkurup/32/24159_2.png) [@vkurup](https://discuss.elastic.co/u/vkurup)\
**Post date:** [November 28, 2017, 4:04pm UTC](https://discuss.elastic.co/t/applying-configuration-to-all-prospectors/109431/1 "2017-11-28T16:04:19Z")

</div>

Is it possible to apply configuration to 'all' prospectors? For example, I know i can set up 2 prospectors with multiline configuration like this:

```auto
filebeat.prospectors:
  - input_type: log
    paths:
      - /var/log/syslog
    multiline.pattern: '^[[:space:]]'
    multiline.negate: false
    multiline.match: after
    fields:
      type: syslog
  - input_type: log
    paths:
      - /var/log/rabbitmq/rabbit@*.log
    multiline.pattern: '^[[:space:]]'
    multiline.negate: false
    multiline.match: after
    fields:
      type: rabbitmq

```

Is it possible to write all those `multiline` items in just one place? I didn't see a clear example in the docs discussing that possibility.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 28, 2017, 5:00pm UTC](https://discuss.elastic.co/t/applying-configuration-to-all-prospectors/109431/2 "2017-11-28T17:00:43Z")

</div>

There is no built in way to do this, but if you are comfortable with YAML you can use YAML anchors. If you aren't comfortable with anchors and how they work then I would leave the config as you have it. For example:

```auto
macros:
  syslog_defaults: &syslog
    input_type: log
    multiline.pattern: '^[[:space:]]'
    multiline.negate: false
    multiline.match: after
    fields:
      type: syslog
  
filebeat.prospectors:
- <<: *syslog
  paths:
    - /var/log/rabbitmq/rabbit@*.log

- <<: *syslog
  paths:
    - /var/log/syslog
  fields:
    type: rabbitmq

```

The final config would look like this. (tested with `./filebeat -e -d "config"`)

```json
{
  "filebeat": {
    "prospectors": [
      {
        "fields": {
          "type": "syslog"
        },
        "input_type": "log",
        "multiline": {
          "match": "after",
          "negate": false,
          "pattern": "^[[:space:]]"
        },
        "paths": [
          "/var/log/rabbitmq/rabbit@*.log"
        ]
      },
      {
        "fields": {
          "type": "rabbitmq"
        },
        "input_type": "log",
        "multiline": {
          "match": "after",
          "negate": false,
          "pattern": "^[[:space:]]"
        },
        "paths": [
          "/var/log/syslog"
        ]
      }
    ]
  }
}

```

---

<div class="post-metadata">

**Author:** ![vkurup](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vkurup/32/24159_2.png) [@vkurup](https://discuss.elastic.co/u/vkurup)\
**Post date:** [November 28, 2017, 5:20pm UTC](https://discuss.elastic.co/t/applying-configuration-to-all-prospectors/109431/3 "2017-11-28T17:20:42Z")

</div>

Thank you! I'll stick with my version, but nice to know this is possible.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 29, 2017, 1:55pm UTC](https://discuss.elastic.co/t/applying-configuration-to-all-prospectors/109431/4 "2017-11-29T13:55:42Z")

</div>

You can also reference other settings using the `${<setting-name>}` syntax from any setting. Including full namespaces. e.g.

```auto
filebeat.prospectors:
  - input_type: log
    paths:
      - /var/log/syslog
    multiline: ${common.multiline}
    fields.type: syslog
  - input_type: log
    paths:
      - /var/log/rabbitmq/rabbit@*.log
    multiline: ${common.multiline}
    fields.type: rabbitmq

common.multiline:
  pattern: '^[[:space:]]'
  negate: false
  match: after

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 29, 2017, 2:29pm UTC](https://discuss.elastic.co/t/applying-configuration-to-all-prospectors/109431/5 "2017-11-29T14:29:46Z")

</div>

That's certainly more friendly that anchors. Thanks @steffens.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2017, 2:30pm UTC](https://discuss.elastic.co/t/applying-configuration-to-all-prospectors/109431/6 "2017-12-27T14:30:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
