# Configure multiple logs location on filebeat

**URL:** <https://discuss.elastic.co/t/configure-multiple-logs-location-on-filebeat/322971>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 11, 2023, 8:58pm UTC](https://discuss.elastic.co/t/configure-multiple-logs-location-on-filebeat/322971 "2023-01-11T20:58:22Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [January 11, 2023, 8:58pm UTC](https://discuss.elastic.co/t/configure-multiple-logs-location-on-filebeat/322971/1 "2023-01-11T20:58:22Z")

</div>

Hi!

let's say I need to send logs from a few directories to elasticsearch, like this:

/var/log/logfolder1/server.log  
/var/log/logfolder2/server.log  
/var/log/logfolder3/server.log  
/var/log/logfolder4/server.log

what about my filebeat.yaml? should it look like:

```auto
- type: filestream
    id: id1
    enabled: true
    paths:
     - /var/log/logfolder1/server.log

- type: filestream
    id: id2
    enabled: true
    paths:
     - /var/log/logfolder2/server.log

- type: filestream
    id: id3
    enabled: true
    paths:
     - /var/log/logfolder3/server.log

```

---

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [January 11, 2023, 8:59pm UTC](https://discuss.elastic.co/t/configure-multiple-logs-location-on-filebeat/322971/2 "2023-01-11T20:59:23Z")

</div>

or just one -type: filestream should be used ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 11, 2023, 9:52pm UTC](https://discuss.elastic.co/t/configure-multiple-logs-location-on-filebeat/322971/3 "2023-01-11T21:52:23Z")

</div>

Do you need to have a specific `id` for each of them?

---

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [January 11, 2023, 10:41pm UTC](https://discuss.elastic.co/t/configure-multiple-logs-location-on-filebeat/322971/4 "2023-01-11T22:41:54Z")

</div>

not sure I'm new in ELK.. I thought it is needed to figure out,define logs in Kibana

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 11, 2023, 11:27pm UTC](https://discuss.elastic.co/t/configure-multiple-logs-location-on-filebeat/322971/5 "2023-01-11T23:27:06Z")

</div>

Perhaps look at the [path](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-filestream.html#filestream-input-paths) setting and what you can do.

> A list of glob-based paths that will be crawled and fetched. All patterns supported by Go Glob are also supported here. For example, to fetch all files from a predefined level of subdirectories, the following pattern can be used: `/var/log/*/*.log`. This fetches all .log files from the subfolders of /var/log

---

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [January 11, 2023, 11:30pm UTC](https://discuss.elastic.co/t/configure-multiple-logs-location-on-filebeat/322971/6 "2023-01-11T23:30:45Z")

</div>

Hi!

Thank you for the link

I understand that I can config this way. The question is how to figure out in Kibana later on which line belongs to which log file on filebeat host. That's the reason I assigned different IDs. I hoped it will help later on

---

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [January 11, 2023, 11:31pm UTC](https://discuss.elastic.co/t/configure-multiple-logs-location-on-filebeat/322971/7 "2023-01-11T23:31:24Z")

</div>

I don't use logstash for now.. filebeat sends data to elasticsearch

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 11, 2023, 11:33pm UTC](https://discuss.elastic.co/t/configure-multiple-logs-location-on-filebeat/322971/8 "2023-01-11T23:33:43Z")

</div>

If you want to maintain the specific tagging like that then you will need 3 separate `filestream` inputs like that.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 11, 2023, 11:37pm UTC](https://discuss.elastic.co/t/configure-multiple-logs-location-on-filebeat/322971/9 "2023-01-11T23:37:39Z")

</div>

Filebeat includes the log path and name in each event by default.

IDs are fine too!

```auto
"log": {
      "file": {
        "path": "/var/log/jamf.log"
      },
      "offset": 11171602
    },

```

---

<div class="post-metadata">

**Author:** ![vassiliy.vins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassiliy.vins/32/113615_2.png) [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Post date:** [January 12, 2023, 1:25am UTC](https://discuss.elastic.co/t/configure-multiple-logs-location-on-filebeat/322971/10 "2023-01-12T01:25:15Z")

</div>

thank you, gents!

I believe we can close discussion

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 12, 2023, 1:36am UTC](https://discuss.elastic.co/t/configure-multiple-logs-location-on-filebeat/322971/11 "2023-01-12T01:36:53Z")

</div>

> [@vassiliy.vins](#):
>
> I believe we can close discussion

Topics auto close on their own after 28 days...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 9, 2023, 3:37am UTC](https://discuss.elastic.co/t/configure-multiple-logs-location-on-filebeat/322971/12 "2023-02-09T03:37:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
