# Custom filebeat module

**URL:** <https://discuss.elastic.co/t/custom-filebeat-module/149797>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 25, 2018, 10:03am UTC](https://discuss.elastic.co/t/custom-filebeat-module/149797 "2018-09-25T10:03:08Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mraz1337](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mraz1337/32/36379_2.png) [@mraz1337](https://discuss.elastic.co/u/mraz1337)\
**Post date:** [September 25, 2018, 10:03am UTC](https://discuss.elastic.co/t/custom-filebeat-module/149797/1 "2018-09-25T10:03:09Z")

</div>

Filebeat configuration supports multiple inputs, how can be this achived with custom module config.yml ?  
I would like to tag single path with the unique value.

```
type: log
paths:
  - C:/Logs1/*/*.log -> tag1
  - C:/Logs2/*/*.log -> tag2

```

I tried with two input definitions in the same file, but no success.

```
type: log
paths:
  - C:/Logs1/*/*.log 
tags: [Tag1]

type: log
paths:
  - C:/Logs2/*/*.log 
tags: [Tag2]
```

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [September 26, 2018, 1:22pm UTC](https://discuss.elastic.co/t/custom-filebeat-module/149797/2 "2018-09-26T13:22:05Z")

</div>

@mraz1337 I think you were close, but sometime YAML alignment get in the way. Something similar to the following should work.

```auto
filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so
# you can use different inputs for various configurations.
# Below are the input specific configurations.

- type: log

  # Change to true to enable this input configuration.
  enabled: true

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - /var/log/*.log
    #- c:\programdata\elasticsearch\logs\*
    
  # Optional additional fields. These fields can be freely picked
  # to add additional information to the crawled log files for filtering
  fields:
    tags: tag1

- type: log

  # Change to true to enable this input configuration.
  enabled: true

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - /var/other logs/*.log
    #- c:\programdata\elasticsearch\logs\*
    
  # Optional additional fields. These fields can be freely picked
  # to add additional information to the crawled log files for filtering
  fields:
    tags: mytag2
```

---

<div class="post-metadata">

**Author:** ![mraz1337](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mraz1337/32/36379_2.png) [@mraz1337](https://discuss.elastic.co/u/mraz1337)\
**Post date:** [September 27, 2018, 6:36am UTC](https://discuss.elastic.co/t/custom-filebeat-module/149797/3 "2018-09-27T06:36:21Z")

</div>

I used your example but i get an error in filebeat logs:

```
ERROR	fileset/factory.go:105	Error creating input: No paths were defined for input accessing config

```

....

```
ERROR	instance/beat.go:743	Exiting: No paths were defined for input accessing config
```

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [September 28, 2018, 12:50pm UTC](https://discuss.elastic.co/t/custom-filebeat-module/149797/4 "2018-09-28T12:50:22Z")

</div>

Can you add the output of `filebeat export config` to this thread?

---

<div class="post-metadata">

**Author:** ![mraz1337](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mraz1337/32/36379_2.png) [@mraz1337](https://discuss.elastic.co/u/mraz1337)\
**Post date:** [October 1, 2018, 8:33am UTC](https://discuss.elastic.co/t/custom-filebeat-module/149797/5 "2018-10-01T08:33:57Z")

</div>

Exported config:

```
filebeat:
  config:
    modules:
      path: d:\Elastic\filebeat-6.4.1-windows-x86_64/modules.d/*.yml
      reload:
        enabled: false
  inputs:
  - enabled: false
    paths: null
    type: log
logging:
  level: debug
output:
  elasticsearch:
    hosts:
    - localhost:9200
path:
  config: d:\Elastic\filebeat-6.4.1-windows-x86_64
  data: d:\Elastic\filebeat-6.4.1-windows-x86_64\data
  home: d:\Elastic\filebeat-6.4.1-windows-x86_64
  logs: d:\Elastic\filebeat-6.4.1-windows-x86_64\logs
setup:
  dashboards:
    enabled: true
  kibana:
    host: localhost:5601
  template:
    settings:
      index:
        number_of_shards: 3

```

filebeat.inputs: are configured inside module.

---

<div class="post-metadata">

**Author:** ![mraz1337](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mraz1337/32/36379_2.png) [@mraz1337](https://discuss.elastic.co/u/mraz1337)\
**Post date:** [October 24, 2018, 8:00am UTC](https://discuss.elastic.co/t/custom-filebeat-module/149797/6 "2018-10-24T08:00:01Z")

</div>

@pierhugues did you manage to figure something out?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 21, 2018, 8:00am UTC](https://discuss.elastic.co/t/custom-filebeat-module/149797/7 "2018-11-21T08:00:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
