# Can we use datastreams with Filebeat?659+

**URL:** <https://discuss.elastic.co/t/can-we-use-datastreams-with-filebeat-659/259693>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 27, 2020, 6:26pm UTC](https://discuss.elastic.co/t/can-we-use-datastreams-with-filebeat-659/259693 "2020-12-27T18:26:12Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [December 27, 2020, 6:26pm UTC](https://discuss.elastic.co/t/can-we-use-datastreams-with-filebeat-659/259693/1 "2020-12-27T18:26:12Z")

</div>

Hello,

So "Can we use datastreams with Filebeat?" And more importantly, can we mix multiple inputs, where some use legacy ilm and some use datastreams? This is in a test 7.10.1 setup without Logstash.

For example untill now I had these 2 log inputs:

```
filebeat.inputs:
- type: log
  paths: C:\Windows\System32\LogFiles\Firewall\*.log
  pipeline: filebeat-windows-firewall
  fields_under_root: true
  fields.service.name: "Windows Firewall"
  
- type: syslog
  protocol.udp:
    max_message_size: 25KiB
    host: "192.168.1.102:10514"
  pipeline: filebeat-pfsense

```

I'd love to migrate my pfsense to a datastream, and leave the Windows Firewall logs as they are.

`logs-netgate.pfsense-default` should be the name of the datastream. Should I try use a conditional on `output.elasticsearch.index`? Should I set \_index in the new pipeline? Or what is the recommended way to start migrating to datastreams?

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 24, 2021, 8:26pm UTC](https://discuss.elastic.co/t/can-we-use-datastreams-with-filebeat-659/259693/2 "2021-01-24T20:26:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
