# Could filebeat support multipath for input and output separately?

**URL:** <https://discuss.elastic.co/t/could-filebeat-support-multipath-for-input-and-output-separately/50297>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 18, 2016, 5:44am UTC](https://discuss.elastic.co/t/could-filebeat-support-multipath-for-input-and-output-separately/50297 "2016-05-18T05:44:29Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![tuankun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tuankun/32/8590_2.png) [@tuankun](https://discuss.elastic.co/u/tuankun)\
**Post date:** [May 18, 2016, 5:44am UTC](https://discuss.elastic.co/t/could-filebeat-support-multipath-for-input-and-output-separately/50297/1 "2016-05-18T05:44:29Z")

</div>

Hi anybody,  
I would like to capture some logs with totally different fields using filebeat on windows 2008 server,and then send logs to different index in elasticsearch.  
Could filebeat support multipath like this (individually):  
input1-\>output1  
input2-\>output2  
input3-\>output3  
...

just like routing mechanism.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 18, 2016, 11:02am UTC](https://discuss.elastic.co/t/could-filebeat-support-multipath-for-input-and-output-separately/50297/2 "2016-05-18T11:02:08Z")

</div>

this is currently not supported by filebeat. For event-routing of any-kind we recommend logstash.

---

<div class="post-metadata">

**Author:** ![tuankun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tuankun/32/8590_2.png) [@tuankun](https://discuss.elastic.co/u/tuankun)\
**Post date:** [May 18, 2016, 2:53pm UTC](https://discuss.elastic.co/t/could-filebeat-support-multipath-for-input-and-output-separately/50297/3 "2016-05-18T14:53:32Z")

</div>

@steffens  
but logstash is really big size,not lightweight, Is there a plan to improve the filebeat for event-routing function?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [May 18, 2016, 7:29pm UTC](https://discuss.elastic.co/t/could-filebeat-support-multipath-for-input-and-output-separately/50297/4 "2016-05-18T19:29:45Z")

</div>

@tuankun One of the main goals of beats is to keep it lightweight. So we are very careful when adding new features. Concerning output there are several ongoing discussions on Github, for example this one here: [https://github.com/elastic/beats/issues/1587](https://github.com/elastic/beats/issues/1587) Routing is currently not on the closer roadmap.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 18, 2016, 8:37pm UTC](https://discuss.elastic.co/t/could-filebeat-support-multipath-for-input-and-output-separately/50297/5 "2016-05-18T20:37:58Z")

</div>

> but logstash is really big size,not lightweight, Is there a plan to improve the filebeat for event-routing function?

Why not run multiple Filebeat instances? The RAM overhead of each process shouldn't be more than 20 MB or so, most of which should be shared between the processes.

---

<div class="post-metadata">

**Author:** ![tuankun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tuankun/32/8590_2.png) [@tuankun](https://discuss.elastic.co/u/tuankun)\
**Post date:** [May 19, 2016, 12:21am UTC](https://discuss.elastic.co/t/could-filebeat-support-multipath-for-input-and-output-separately/50297/6 "2016-05-19T00:21:35Z")

</div>

@magnusbaeck  
would you please describe the steps on how to run multiple filebeat instances? I run filebeat as a service, thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 19, 2016, 5:29am UTC](https://discuss.elastic.co/t/could-filebeat-support-multipath-for-input-and-output-separately/50297/7 "2016-05-19T05:29:51Z")

</div>

The answer probably depends on whether you run Filebeat via systemd or as a classic SysV init script, but at least in the latter case you should be okay if you make a copy of the init script and adjust the NAME, DAEMON\_ARGS, and PIDFILE variables. I haven't tried it myself.

---

<div class="post-metadata">

**Author:** ![tuankun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tuankun/32/8590_2.png) [@tuankun](https://discuss.elastic.co/u/tuankun)\
**Post date:** [May 19, 2016, 7:45am UTC](https://discuss.elastic.co/t/could-filebeat-support-multipath-for-input-and-output-separately/50297/8 "2016-05-19T07:45:52Z")

</div>

@magnusbaeck  
Got it, I will test.  
thank you so much.

@steffens  
@ruflin  
Thank you two also! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:51pm UTC](https://discuss.elastic.co/t/could-filebeat-support-multipath-for-input-and-output-separately/50297/9 "2017-07-05T21:51:47Z")

</div>


