# Custom ingest alongside with IIS module

**URL:** https://discuss.elastic.co/t/custom-ingest-alongside-with-iis-module/232682
**Category:** Beats
**Tags:** filebeat
**Created:** [May 14, 2020, 4:00pm UTC](https://discuss.elastic.co/t/custom-ingest-alongside-with-iis-module/232682 "2020-05-14T16:00:34Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Jujule](https://avatars.discourse-cdn.com/v4/letter/j/bb73d2/32.png) [@Jujule](https://discuss.elastic.co/u/Jujule)
#### Post date: [May 14, 2020, 4:00pm UTC](https://discuss.elastic.co/t/custom-ingest-alongside-with-iis-module/232682/1 "2020-05-14T16:00:34Z")

</div>

Hi,

warning: those are probably some newbie questions.

Context: wanting to filebeat some files to ES with ingest pipelines, and IIS logs, from differents files on the same machine.

Are the main configuration from filebeat.yml, and config from IIS module, cleanly isolated ? (example: output.elasticsearch.pipeline and output.elasticsearch.index)

Do I have to make a custom module, one per application ? Is it recommended ?

Modules can be considered as isolated, separated threads ? Is the main config file, can be considered as a module in itself ?

Thanks a lot

---

<div class="post-metadata">

### Author: ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)
#### Post date: [May 14, 2020, 6:46pm UTC](https://discuss.elastic.co/t/custom-ingest-alongside-with-iis-module/232682/2 "2020-05-14T18:46:35Z")

</div>

Hey @Jujule, welcome to discuss 🙂

Let me try to explain.

> [@Jujule](#):
>
> Are the main configuration from filebeat.yml, and config from IIS module, cleanly isolated ? (example: output.elasticsearch.pipeline and output.elasticsearch.index)

Output configuration is the same for all the inputs and modules in the same filebeat instance. If you want two different outputs, you need two filebeat instances, but this is usually not needed. A single elasticsearch output can send the events to different indexes depending on their content, but this is also usually not needed.

> [@Jujule](#):
>
> Do I have to make a custom module, one per application ? Is it recommended ?

Not sure of understanding this question. There are [many modules available](https://www.elastic.co/guide/en/beats/filebeat/7.7/filebeat-modules.html), you can use them, for example there is one for IIS, you could use it for your IIS logs, no need to create a custom module, but you may need to customize the configuration for your deployment.

You can also use [inputs](https://www.elastic.co/guide/en/beats/filebeat/7.7/configuration-filebeat-options.html) directly to collect logs from files or other origins. For custom parsing you can use processors or ingest pipelines.

> [@Jujule](#):
>
> Modules can be considered as isolated, separated threads ? Is the main config file, can be considered as a module in itself ?

Module files can contain many modules configurations. The main configuration file can contain inputs and modules. Modules configure inputs under the hood, they work mostly independently, each one harvesting their logs, but this is more an implementation detail.

---

<div class="post-metadata">

### Author: ![Jujule](https://avatars.discourse-cdn.com/v4/letter/j/bb73d2/32.png) [@Jujule](https://discuss.elastic.co/u/Jujule)
#### Post date: [May 15, 2020, 10:05am UTC](https://discuss.elastic.co/t/custom-ingest-alongside-with-iis-module/232682/3 "2020-05-15T10:05:31Z")

</div>

Hi @jsoriano,

Thanks a lot for your reply. This sounds OK.

From what you say I believe that all modules share the same output configuration.

In order to understand well, the IIS module creates in ES a pipeline named 'filebeat-7.6.2-iis-access-default'. Where is this output configured in the module ?

And if two modules are enabled, what is the merged output config ?

---

<div class="post-metadata">

### Author: ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)
#### Post date: [May 15, 2020, 12:25pm UTC](https://discuss.elastic.co/t/custom-ingest-alongside-with-iis-module/232682/4 "2020-05-15T12:25:15Z")

</div>

> [@Jujule](#):
>
> From what you say I believe that all modules share the same output configuration.

That's it.

> [@Jujule](#):
>
> In order to understand well, the IIS module creates in ES a pipeline named 'filebeat-7.6.2-iis-access-default'. Where is this output configured in the module ?

Each event can contain some metadata about what pipeline should be used to be processed. Modules fill this metadata so the correct pipeline is used when ES receives it. So the output is the same for all modules and inputs, but each event can be processed with a different pipeline.

Notice that [the pipeline can be configured in the output](https://www.elastic.co/guide/en/beats/filebeat/7.7/elasticsearch-output.html#pipeline-option-es), but it can be also configured at the [input](https://www.elastic.co/guide/en/beats/filebeat/7.7/filebeat-input-log.html#_pipeline_7) level.

> [@Jujule](#):
>
> And if two modules are enabled, what is the merged output config ?

There is no merged output config, modules or inputs don't modify the output configuration. But they can include in their events some metadata so Elasticsearch knows what pipeline to use for them.

---

<div class="post-metadata">

### Author: ![Jujule](https://avatars.discourse-cdn.com/v4/letter/j/bb73d2/32.png) [@Jujule](https://discuss.elastic.co/u/Jujule)
#### Post date: [May 15, 2020, 12:50pm UTC](https://discuss.elastic.co/t/custom-ingest-alongside-with-iis-module/232682/5 "2020-05-15T12:50:51Z")

</div>

ok thanks that's crystal clear now !

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 12, 2020, 12:50pm UTC](https://discuss.elastic.co/t/custom-ingest-alongside-with-iis-module/232682/6 "2020-06-12T12:50:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
