# Centralized Agent Config File

**URL:** <https://discuss.elastic.co/t/centralized-agent-config-file/128252>\
**Category:** Beats\
**Created:** [April 16, 2018, 8:50pm UTC](https://discuss.elastic.co/t/centralized-agent-config-file/128252 "2018-04-16T20:50:04Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [April 16, 2018, 8:50pm UTC](https://discuss.elastic.co/t/centralized-agent-config-file/128252/1 "2018-04-16T20:50:05Z")

</div>

Is it possible to have two config files for each beat. One residing on a network share that hands out the base config to all agents and then a second that is customized for each machine?

The config file I am using for winlogbeat is shown below:

```
winlogbeat.event_logs:
  - name: Application
    ignore_older: 72h
  - name: Security
  - name: System
setup.template.settings:
  index.number_of_shards: 1
  index.codec: best_compression
  _source.enabled: true
name: hostname
tags: ["Tag1", "Tag2", "Tag3"]
setup.kibana:
  host: "hostname:5601"
output.logstash:
  hosts: ["hostname:5044"]

```

Is it possible to split this up so everything except `name` and `tags` is in a config file on a network share and then each machine gets a config file that only specifies those two settings? Surely there is a way to centrally administer

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [April 17, 2018, 10:13am UTC](https://discuss.elastic.co/t/centralized-agent-config-file/128252/2 "2018-04-17T10:13:43Z")

</div>

Hi @wwalker,

You should be able to fill these settings from environment variables, have a look to [https://www.elastic.co/guide/en/beats/winlogbeat/current/using-environ-vars.html](https://www.elastic.co/guide/en/beats/winlogbeat/current/using-environ-vars.html)

Best regards

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [April 17, 2018, 10:39pm UTC](https://discuss.elastic.co/t/centralized-agent-config-file/128252/3 "2018-04-17T22:39:10Z")

</div>

So what you're saying is, change the beat's service install powershell script to use a network path for the -c option and then that file would use env variables that are configured on the host machines? The page appears to use examples designed for Linux, does this also work for Windows machines. I.E. if a Windows variable is `ES_HOSTNAME` with a value of `Computer` I would configure the beats.yml to `name: ${ES_HOSTNAME}` which would produce events in ElasticSearch with the field value being `Computer`?

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [April 18, 2018, 7:28pm UTC](https://discuss.elastic.co/t/centralized-agent-config-file/128252/4 "2018-04-18T19:28:24Z")

</div>

Having an issue configuring the agent service to look at the network share config file. Here's the syntaxes I've tried:

`-c `"\\SERVERNAME\\AgentConfig$\\WinlogBeat\WinlogBeat.yml`"`  
`-c `"\\SERVERNAME\AgentConfig$\WinlogBeat\WinlogBeat.yml`"`  
`-c `"\\\\SERVERNAME\\AgentConfig$\\WinlogBeat\WinlogBeat.yml`"`  
`-c `"\\\\SERVERNAME\\AgentConfig$\\WinlogBeat\\WinlogBeat.yml`"`  
`-c `"\\\\SERVERNAME\\AgentConfig\$\\WinlogBeat\WinlogBeat.yml`"`  
`-c `"\\\SERVERNAME\\AgentConfig$\\WinlogBeat\WinlogBeat.yml`"`  
`-c `"\\\SERVERNAME\\AgentConfig$\\WinlogBeat\\WinlogBeat.yml`"`

Service fails to start with any of the above. Having issues understanding exactly how the `\` character is used by Windows Service Manager. I thought it was used as an escape character to allow literal `\` in the path but that doesn't seem to be the case.

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [April 19, 2018, 9:42am UTC](https://discuss.elastic.co/t/centralized-agent-config-file/128252/5 "2018-04-19T09:42:29Z")

</div>

Perhaps you can try to copy it to a local folder and use it from there?

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [April 19, 2018, 12:07pm UTC](https://discuss.elastic.co/t/centralized-agent-config-file/128252/6 "2018-04-19T12:07:48Z")

</div>

Well....of course it works from a local folder, that's default functionality. I want to deploy from a network location so that instead of managing 100 different config files, I only manage one.

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [April 19, 2018, 12:37pm UTC](https://discuss.elastic.co/t/centralized-agent-config-file/128252/7 "2018-04-19T12:37:28Z")

</div>

Yes, what I meant is that you can script a copy of the file before launching Winlogbeat, that way you ensure you always have a fresh copy from the network share.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [April 20, 2018, 2:15am UTC](https://discuss.elastic.co/t/centralized-agent-config-file/128252/8 "2018-04-20T02:15:47Z")

</div>

How would I script that into the service on a Windows box?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2018, 4:16am UTC](https://discuss.elastic.co/t/centralized-agent-config-file/128252/9 "2018-05-18T04:16:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
