# Default prospector options - Filebeat 5.4.1

**URL:** <https://discuss.elastic.co/t/default-prospector-options-filebeat-5-4-1/88953>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 11, 2017, 1:40pm UTC](https://discuss.elastic.co/t/default-prospector-options-filebeat-5-4-1/88953 "2017-06-11T13:40:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lefagr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lefagr/32/18830_2.png) [@lefagr](https://discuss.elastic.co/u/lefagr)\
**Post date:** [June 11, 2017, 1:40pm UTC](https://discuss.elastic.co/t/default-prospector-options-filebeat-5-4-1/88953/1 "2017-06-11T13:40:38Z")

</div>

Hello!

I have several filebeat (5.4.1) prospectors and I want to use the same options for most of them.  
Is it possible to set the options as defaults for all prospectors and then overwrite them under prospector?  
As an example, I currently have:

> ```
> filebeat.prospectors:
> -
> paths:
> - "/var/log/nginx/*access*log"
> exclude_files: ['.gz$', '.xz$']
> tail_files: true
> close_inactive: 1m
> close_removed: true
> ignore_older: 60m
> clean_inactive: 61m
> clean_removed: true
> scan_frequency: 10s
> input_type: log
> document_type: nginx_access
> tags: ["nginx", "access_log", "plain"]
> -
> paths:
> - "/var/log/nginx/*error*log"
> exclude_files: ['.gz$', '.xz$']
> tail_files: true
> close_inactive: 1m
> close_removed: true
> ignore_older: 60m
> clean_inactive: 61m
> clean_removed: true
> scan_frequency: 10s
> input_type: log
> document_type: nginx_error
> tags: ["nginx", "error_log", "plain"]
> 
> ```

And I'd like to have:

> ## filebeat.prospectors: defaults: exclude\_files: ['.gz$', '.xz$'] tail\_files: true close\_inactive: 1m close\_removed: true ignore\_older: 60m clean\_inactive: 61m clean\_removed: true scan\_frequency: 10s input\_type: log
> 
> ```
> paths:
> - "/var/log/nginx/*access*log"
> exclude_files: ['.gz$', '.xz$']
> tail_files: false
> document_type: nginx_access
> tags: ["nginx", "access_log", "plain"]
> 
> ```
> 
> - paths:  
> - "/var/log/nginx/_error_log"  
> document\_type: nginx\_error  
> scan\_frequency: 5s  
> tags: ["nginx", "error\_log", "plain"]

As you can see in my original configuration I have to maintain the same options in all prospectors.  
Is there anything similar you can do in filebeat configuration, or any workarounds, so I can have separate prospector config files with minimal options set per prospector?

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [June 12, 2017, 9:03am UTC](https://discuss.elastic.co/t/default-prospector-options-filebeat-5-4-1/88953/2 "2017-06-12T09:03:27Z")

</div>

Hi,

this is an interesting feature, although I'm not sure how many people would benefit from it.

You can open an enhancement request in our Github issues page: [https://github.com/elastic/beats/issues](https://github.com/elastic/beats/issues), then we can track interest from other people.

---

<div class="post-metadata">

**Author:** ![lefagr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lefagr/32/18830_2.png) [@lefagr](https://discuss.elastic.co/u/lefagr)\
**Post date:** [June 12, 2017, 1:22pm UTC](https://discuss.elastic.co/t/default-prospector-options-filebeat-5-4-1/88953/3 "2017-06-12T13:22:16Z")

</div>

I've opened an issue @ [https://github.com/elastic/beats/issues/4489](https://github.com/elastic/beats/issues/4489)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2017, 1:22pm UTC](https://discuss.elastic.co/t/default-prospector-options-filebeat-5-4-1/88953/4 "2017-07-10T13:22:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
