# Dec 13th, 2017: \[EN\]\[Beats\]Moving to the Beat: Filebeat config updates in 6.x

**URL:** <https://discuss.elastic.co/t/dec-13th-2017-en-beats-moving-to-the-beat-filebeat-config-updates-in-6-x/111112>\
**Category:** Advent Calendar\
**Created:** [December 11, 2017, 2:21pm UTC](https://discuss.elastic.co/t/dec-13th-2017-en-beats-moving-to-the-beat-filebeat-config-updates-in-6-x/111112 "2017-12-11T14:21:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![crayzeigh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/crayzeigh/32/23084_2.png) [@crayzeigh](https://discuss.elastic.co/u/crayzeigh)\
**Post date:** [December 11, 2017, 2:21pm UTC](https://discuss.elastic.co/t/dec-13th-2017-en-beats-moving-to-the-beat-filebeat-config-updates-in-6-x/111112/1 "2017-12-11T14:21:17Z")

</div>

# Moving to the Beat: Filebeat config updates in 6.x

Hi everyone 👋! I am relatively new to the Elastic. Consequently, a good portion of my time has been devoted to shoring up my knowledge, filling the gaps between self-taught and formally trained. I found this information along the way about one of my favorite Elastic Utilities: [Filebeat](https://www.elastic.co/guide/en/beats/filebeat/5.6/filebeat-overview.html).

By design, Filebeat is simple to configure and lightweight. Want to ship some logs? No problem, here's how you set it up:

```auto
filebeat.prospectors:
- type: log
  paths:
    - /var/log/nginx/access.log*
  exclude_files: ['\.gz$']

- type: log
  paths:
    - /var/log/messages
    - /var/log/*.log

```

It's not especially glamorous, it gets the job done and moves log data. If you want to get rich data, it needs to cycle through Logstash to be interpreted. But, I found out I can make the setup process easier!

I ran into the Filebeat modules when I was re-familiarizing myself with 5.X (ironically just weeks before the 6.0 release) and loved how simple it was to set up shipping of some common logs to Elasticsearch and load basic dashboards to get started on a new project quickly.

First, set up your dashboards (this uses your output setting for Elasticsearch in `filbeat.yml`, you'll receive an error if this is incorrect or missing):

```auto
$ ./filebeat -e -modules=nginx -setup

```

That automatically configures sample dashboards for the nginx module, so it only needs to be run once for the module dashboards you want to load. Then you can configure the modules through the config file in the future:

```auto
filebeat.modules:
- module: nginx

```

You can distribute that config using some configuration management (like Chef, Ansible, or Puppet) and get sane outputs for Nginx out of the box! It's very handy for quickly configuring some data output or managing minimally complex configurations using an Elasticsearch ingest node. As you can imagine, though, that single filebeat.yml file could get quite large. And you might need a separate config for multiple server types.

In 6.x, though, configuration got a little more manageable! Now, the Filebeat modules are all stored in separate configuration files located in `filebeat/modules.d/`

```auto
$ ls modules.d
apache2.yml.disabled icinga.yml.disabled
nginx.yml.disabled system.yml.disabled
auditd.yml.disabled mysql.yml.disabled   
redis.yml.disabled

```

From the output above, you can see the modules start by default as \*.disabled, but they already contain some default settings. Simply renaming the file to remove disabled will load the module with default settings which alone allows you to quickly test and iterate on your server configuration settings.

Furthermore, "setup" can be run as a standalone command instead of a flag when starting Filebeat, making it easier to handle from an operator's machine with the following command:

```auto
filebeat setup --modules MODULE_LIST --dashboards

```

This builds your Kibana Dashboards only — there’s no ingesting unwanted data, or having to separate your setup steps from your server configs.

All of this doubles to make distribution of your configuration across the environment way easier. Using some configuration management, your servers can now have a common filebeat.yml for configuring common settings (like output and TLS), and include your `filebeat/modules.d/*.yml` based on roles. You can configure your Elastic Stack dashboards from an operator computer and then write your configurations once, instead of rewriting a full `filebeat.yml` for each system.

All granular details for the current module configurations can be found in our [modules documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules-overview.html), but I always learn by getting hands-on with some new tech. So whether you prefer reading the technical specifications or messing with a new test config, I hope I’ve inspired you to continuously improve your Elastic Stack configurations this holiday season!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2017, 12:17am UTC](https://discuss.elastic.co/t/dec-13th-2017-en-beats-moving-to-the-beat-filebeat-config-updates-in-6-x/111112/2 "2017-12-20T00:17:16Z")

</div>

This topic was automatically closed after 7 days. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 26, 2017, 12:15am UTC](https://discuss.elastic.co/t/dec-13th-2017-en-beats-moving-to-the-beat-filebeat-config-updates-in-6-x/111112/3 "2017-12-26T00:15:41Z")

</div>



---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 23, 2018, 8:31am UTC](https://discuss.elastic.co/t/dec-13th-2017-en-beats-moving-to-the-beat-filebeat-config-updates-in-6-x/111112/4 "2018-08-23T08:31:24Z")

</div>


