# Difference between filebeat.modules and filebeat.prospectors

**URL:** <https://discuss.elastic.co/t/difference-between-filebeat-modules-and-filebeat-prospectors/90370>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 21, 2017, 10:45pm UTC](https://discuss.elastic.co/t/difference-between-filebeat-modules-and-filebeat-prospectors/90370 "2017-06-21T22:45:30Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![amarc](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@amarc](https://discuss.elastic.co/u/amarc)\
**Post date:** [June 21, 2017, 10:45pm UTC](https://discuss.elastic.co/t/difference-between-filebeat-modules-and-filebeat-prospectors/90370/1 "2017-06-21T22:45:30Z")

</div>

There are `filebeat.modules` for system, audit, apache etc.  
And same thing can be done using `filebeat.prospectors` with `path: /var/log/messages` etc.  
So what is the difference between using a module and using prospectors with path ?  
Do we get any additional benefits while using modules ?

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [June 22, 2017, 4:52am UTC](https://discuss.elastic.co/t/difference-between-filebeat-modules-and-filebeat-prospectors/90370/2 "2017-06-22T04:52:16Z")

</div>

The prospectors are only for scanning files. After configuring a prospector to scan a file, you will still need to configure the rest of the stack (i.e logstash/ingest pipelines and Kibana dashboards).

Filebeat modules in turn will not only configure the correct prospector, but it will also configure ingest pipelines for correct log parsing and also instantiate dashboards. See [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules-overview.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules-overview.html) for more details.

Cheers

---

<div class="post-metadata">

**Author:** ![Sandeep\_Rawat](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@Sandeep\_Rawat](https://discuss.elastic.co/u/Sandeep_Rawat)\
**Post date:** [June 26, 2017, 10:11am UTC](https://discuss.elastic.co/t/difference-between-filebeat-modules-and-filebeat-prospectors/90370/3 "2017-06-26T10:11:36Z")

</div>

Hi,

I've tried playing with filebeat module, but somehow if I comment out my prospector section then the filebeat process doesn't starts at all. Can you help?

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [June 26, 2017, 10:15am UTC](https://discuss.elastic.co/t/difference-between-filebeat-modules-and-filebeat-prospectors/90370/4 "2017-06-26T10:15:49Z")

</div>

What's your filebeat configuration? Also, when you say it doesn't starts, is there an error message in the logs?

---

<div class="post-metadata">

**Author:** ![Sandeep\_Rawat](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@Sandeep\_Rawat](https://discuss.elastic.co/u/Sandeep_Rawat)\
**Post date:** [June 26, 2017, 10:29am UTC](https://discuss.elastic.co/t/difference-between-filebeat-modules-and-filebeat-prospectors/90370/5 "2017-06-26T10:29:38Z")

</div>

this is the error that I'm getting  
`2017/06/26 10:27:52.944103 beat.go:339: CRIT Exiting: No prospectors defined. What files do you want me to watch?`

My filebeat.yml primarily contains this entry  
#========================== Modules configuration ============================  
filebeat.modules:

```
#-------------------------------- Nginx Module -------------------------------
- module: nginx
```

---

<div class="post-metadata">

**Author:** ![Sandeep\_Rawat](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@Sandeep\_Rawat](https://discuss.elastic.co/u/Sandeep_Rawat)\
**Post date:** [June 26, 2017, 11:05am UTC](https://discuss.elastic.co/t/difference-between-filebeat-modules-and-filebeat-prospectors/90370/6 "2017-06-26T11:05:14Z")

</div>

Also if somebody can point me out to an end-to-end tutorial that would be really great. The understanding that I've built is we don't need logstash as filebeat modules by themself will create proper indexed data and store it in Elasticsearch.

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [June 26, 2017, 9:46pm UTC](https://discuss.elastic.co/t/difference-between-filebeat-modules-and-filebeat-prospectors/90370/7 "2017-06-26T21:46:03Z")

</div>

Maybe @ruflin could shine here

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 27, 2017, 8:40am UTC](https://discuss.elastic.co/t/difference-between-filebeat-modules-and-filebeat-prospectors/90370/8 "2017-06-27T08:40:08Z")

</div>

This looks like a bug. Which filebeat version are you using?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 25, 2017, 8:40am UTC](https://discuss.elastic.co/t/difference-between-filebeat-modules-and-filebeat-prospectors/90370/9 "2017-07-25T08:40:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
