# ELK8.10 filebeat input combine modules and filestream and can not show dashboard current

**URL:** <https://discuss.elastic.co/t/elk8-10-filebeat-input-combine-modules-and-filestream-and-can-not-show-dashboard-current/344876>\
**Category:** Beats\
**Tags:** filebeat, datastreams\
**Created:** [October 12, 2023, 6:55am UTC](https://discuss.elastic.co/t/elk8-10-filebeat-input-combine-modules-and-filestream-and-can-not-show-dashboard-current/344876 "2023-10-12T06:55:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![p81061473525](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/p81061473525/32/125489_2.png) [@p81061473525](https://discuss.elastic.co/u/p81061473525)\
**Post date:** [October 12, 2023, 6:55am UTC](https://discuss.elastic.co/t/elk8-10-filebeat-input-combine-modules-and-filestream-and-can-not-show-dashboard-current/344876/1 "2023-10-12T06:55:00Z")

</div>

Hello,  
I'm currently installing version ELK8.10.  
my system diagram like this one  
filebeat -\> es cluster

my problem is my server has mutiple log need to collect .  
such as. nginx, php log, rsyslog ...  
and I know filebeat has nginx module and show defaut dashboard for me.

But I try a lot time can't do that.  
can someone help me?

```auto
output.elasticsearch:
  hosts: ["172.31.19.190:9200"]
  protocol: "https"
  username: "elastic"
  password: "$password"

  ssl.certificate_authorities: ["/etc/filebeat/http_ca.crt"]
  ssl.verification_mode: "certificate"

  indices:
  - index: "repo-php-dev"
    when.contains:
      tags: "php"

  - index: "repo-nginx-dev"

# setup.template.enabled: false
setup.template.name: "repo-nginx-dev"
setup.template.pattern: "repo-nginx-dev"
# I can't use two datastream..? So I only set one for nginx . 

```

filebeat/module/nginx.yml

```auto
# Module: nginx
# Docs: https://www.elastic.co/guide/en/beats/filebeat/main/filebeat-module-nginx.html

- module: nginx
  # Access logs
  access:
    enabled: true

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    # var.paths: ["/var/log/nginx/access.log"]
    var.paths: ["/var/log/nginx/*.log"]

  # Error logs
  error:
    enabled: true

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    var.paths: ["/var/log/nginx/*.log"]

  # Ingress-nginx controller logs. This is disabled by default. It could be used in Kubernetes environments to parse ingress-nginx logs
  ingress_controller:
    enabled: false

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    #var.paths:
~

```

Now , my kibana has two indices , I've see my log coming to indics.  
, but when I change dashboard source "repo-nginx-dev" , It not work.

In concusion .  
How can I combine filestream and modules in the same filebeat conf?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2023, 8:55am UTC](https://discuss.elastic.co/t/elk8-10-filebeat-input-combine-modules-and-filestream-and-can-not-show-dashboard-current/344876/2 "2023-11-09T08:55:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
