# Document for filebeat configuration

**URL:** <https://discuss.elastic.co/t/document-for-filebeat-configuration/310396>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 22, 2022, 12:37pm UTC](https://discuss.elastic.co/t/document-for-filebeat-configuration/310396 "2022-07-22T12:37:43Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![tractor\_boy](https://avatars.discourse-cdn.com/v4/letter/t/278dde/32.png) [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Post date:** [July 22, 2022, 12:37pm UTC](https://discuss.elastic.co/t/document-for-filebeat-configuration/310396/1 "2022-07-22T12:37:43Z")

</div>

Is there a link anywhere that details a full filebeat configuration file?

I want to know all of the configuration options that are possible. I have searched but not found anything.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 22, 2022, 12:49pm UTC](https://discuss.elastic.co/t/document-for-filebeat-configuration/310396/2 "2022-07-22T12:49:49Z")

</div>

It is in the [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuring-howto-filebeat.html).

And when you install filebeat there is also the `filebeat.reference.yml` that you could use.

---

<div class="post-metadata">

**Author:** ![tractor\_boy](https://avatars.discourse-cdn.com/v4/letter/t/278dde/32.png) [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Post date:** [July 22, 2022, 12:55pm UTC](https://discuss.elastic.co/t/document-for-filebeat-configuration/310396/3 "2022-07-22T12:55:51Z")

</div>

I have been through that page many times, and cannot yet find a simple page with all the configuration items on it, what am I missing?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 22, 2022, 12:58pm UTC](https://discuss.elastic.co/t/document-for-filebeat-configuration/310396/4 "2022-07-22T12:58:26Z")

</div>

As said in the page:

> There’s also a full example configuration file called `filebeat.reference.yml` that shows all non-deprecated options.

It is also linked in that same page, the last link in the list is [filebeat.reference.yml](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-reference-yml.html), this shows you an example file with all non-deprecated items, if you want an exaplanation on each one you will need to follow the links in the documentation.

---

<div class="post-metadata">

**Author:** ![tractor\_boy](https://avatars.discourse-cdn.com/v4/letter/t/278dde/32.png) [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Post date:** [July 22, 2022, 1:34pm UTC](https://discuss.elastic.co/t/document-for-filebeat-configuration/310396/5 "2022-07-22T13:34:35Z")

</div>

thanks. This will be very useful.

---

<div class="post-metadata">

**Author:** ![tractor\_boy](https://avatars.discourse-cdn.com/v4/letter/t/278dde/32.png) [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Post date:** [July 22, 2022, 1:41pm UTC](https://discuss.elastic.co/t/document-for-filebeat-configuration/310396/6 "2022-07-22T13:41:20Z")

</div>

Maybe I need a different topic, but what goes into this file

setup.ilm.policy\_file:

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 22, 2022, 1:49pm UTC](https://discuss.elastic.co/t/document-for-filebeat-configuration/310396/7 "2022-07-22T13:49:25Z")

</div>

Didn't know about this setting, but according to the documentation:

> The path to a JSON file that contains a lifecycle policy configuration. Use this setting to load your own lifecycle policy.

It should be the json that you would use when making a request to the API.

---

<div class="post-metadata">

**Author:** ![tractor\_boy](https://avatars.discourse-cdn.com/v4/letter/t/278dde/32.png) [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Post date:** [July 22, 2022, 3:19pm UTC](https://discuss.elastic.co/t/document-for-filebeat-configuration/310396/8 "2022-07-22T15:19:33Z")

</div>

Any idea what that file would look like?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 22, 2022, 3:43pm UTC](https://discuss.elastic.co/t/document-for-filebeat-configuration/310396/9 "2022-07-22T15:43:52Z")

</div>

You can check an example [here in the documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/ilm-put-lifecycle.html).

It is the json part:

```auto
{
  "policy": {
    "_meta": {
      "description": "used for nginx log",
      "project": {
        "name": "myProject",
        "department": "myDepartment"
      }
    },
    "phases": {
      "warm": {
        "min_age": "10d",
        "actions": {
          "forcemerge": {
            "max_num_segments": 1
          }
        }
      },
      "delete": {
        "min_age": "30d",
        "actions": {
          "delete": {}
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 19, 2022, 5:44pm UTC](https://discuss.elastic.co/t/document-for-filebeat-configuration/310396/10 "2022-08-19T17:44:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
