# Elastic output for modules and logstash output for prospectors?

**URL:** <https://discuss.elastic.co/t/elastic-output-for-modules-and-logstash-output-for-prospectors/139535>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 11, 2018, 10:22am UTC](https://discuss.elastic.co/t/elastic-output-for-modules-and-logstash-output-for-prospectors/139535 "2018-07-11T10:22:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![MarcusCaepio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcuscaepio/32/32458_2.png) [@MarcusCaepio](https://discuss.elastic.co/u/MarcusCaepio)\
**Post date:** [July 11, 2018, 10:22am UTC](https://discuss.elastic.co/t/elastic-output-for-modules-and-logstash-output-for-prospectors/139535/1 "2018-07-11T10:22:00Z")

</div>

Hi all, is it possible to send module's data directy to logstash, but prospector data to logstash indexer?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [July 11, 2018, 10:34am UTC](https://discuss.elastic.co/t/elastic-output-for-modules-and-logstash-output-for-prospectors/139535/2 "2018-07-11T10:34:52Z")

</div>

If you want to send to multiple outputs, you need to start multiple Filebeat instances.  
What do you mean by "module's data" and "prospector data"? Could you give me an example?

---

<div class="post-metadata">

**Author:** ![MarcusCaepio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcuscaepio/32/32458_2.png) [@MarcusCaepio](https://discuss.elastic.co/u/MarcusCaepio)\
**Post date:** [July 11, 2018, 10:40am UTC](https://discuss.elastic.co/t/elastic-output-for-modules-and-logstash-output-for-prospectors/139535/3 "2018-07-11T10:40:31Z")

</div>

Example:  
I activate the module "system,apache2,nginx" this data should go directly to elasticsearch because of the given mappings, fields, dashboards and so on.  
The I have an application called "bla" where there is no module available.  
I want to create a prospector for this logs in 'var/log/bla/\*.log", send them to logstash and grok them there

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [July 11, 2018, 10:44am UTC](https://discuss.elastic.co/t/elastic-output-for-modules-and-logstash-output-for-prospectors/139535/4 "2018-07-11T10:44:55Z")

</div>

Got it. Thanks for the clarification.

As I said above, unfortunately, right now sending to multiple outputs is not supported. So you need two instances of Filebeat. The configuration of the first one includes the module config and the output is Elasticsearch. The second config includes the prospector config and Logstash output.

---

<div class="post-metadata">

**Author:** ![MarcusCaepio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcuscaepio/32/32458_2.png) [@MarcusCaepio](https://discuss.elastic.co/u/MarcusCaepio)\
**Post date:** [July 11, 2018, 11:35am UTC](https://discuss.elastic.co/t/elastic-output-for-modules-and-logstash-output-for-prospectors/139535/5 "2018-07-11T11:35:25Z")

</div>

Ok thnaks for the info.  
Seems it ends up with using modules and send them to logstash too, to filter them there, like it is done at  
[https://www.elastic.co/guide/en/logstash/current/logstash-config-for-filebeat-modules.html](https://www.elastic.co/guide/en/logstash/current/logstash-config-for-filebeat-modules.html)

But defining different outputs should be a feature in future...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 8, 2018, 11:35am UTC](https://discuss.elastic.co/t/elastic-output-for-modules-and-logstash-output-for-prospectors/139535/6 "2018-08-08T11:35:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
