# Filebeat: Apache module : two paths and two access inputs to configure

**URL:** <https://discuss.elastic.co/t/filebeat-apache-module-two-paths-and-two-access-inputs-to-configure/311404>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 4, 2022, 11:14am UTC](https://discuss.elastic.co/t/filebeat-apache-module-two-paths-and-two-access-inputs-to-configure/311404 "2022-08-04T11:14:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hboris](https://avatars.discourse-cdn.com/v4/letter/h/898d66/32.png) [@hboris](https://discuss.elastic.co/u/hboris)\
**Post date:** [August 4, 2022, 11:14am UTC](https://discuss.elastic.co/t/filebeat-apache-module-two-paths-and-two-access-inputs-to-configure/311404/1 "2022-08-04T11:14:00Z")

</div>

Hello,

I am a newbie and i am planing to install elastic stack.

Here is my architecture

 ![architecture](https://us1.discourse-cdn.com/elastic/original/3X/6/3/6370c81392173a2c658e3d860bb6c3bfd4d45732.png)

Here is what my apache module conf looks like:

```auto
#-------------------------------- Apache Module --------------------------------
- module: apache
  access:
    enabled: true
    var.paths: ["/customer1/access.log", "/customer2/access.log"]
    input: ???

```

My point concerne the input section. How can i

1. add custom fields for each of my access log files (customerName: c1 or c2, env: prod)
2. tell apache to ignore lines starting by 127.0.0.1 or localhost
3. tell apache to ignore 24h older access log files

Thank you for your help

---

<div class="post-metadata">

**Author:** ![hboris](https://avatars.discourse-cdn.com/v4/letter/h/898d66/32.png) [@hboris](https://discuss.elastic.co/u/hboris)\
**Post date:** [August 5, 2022, 1:59pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-two-paths-and-two-access-inputs-to-configure/311404/2 "2022-08-05T13:59:19Z")

</div>

Hello,

No one was already facing this issue?  
Is it relevant to do as follow?

```auto
- module: apache
  access:
    enabled: true
    var.paths: ["/customer1/access.log", "/customer2/access.log"]
    input:
        processors:
           - if:
                var.paths: ["/customer1/access.log"]
            then:
                add_fields:
                    customerName: c1
           - if:
                var.paths: ["/customer2/access.log"]
            then:
                add_fields:
                    customerName: c2

```

Thank you for your help

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 22, 2022, 2:50pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-two-paths-and-two-access-inputs-to-configure/311404/3 "2022-08-22T14:50:17Z")

</div>

Hey @hboris, welcome to discuss 🙂

Yes, processors is probably the way to go here. Your configuration looks fine, but if you have different configurations, it may be better to have a more clear separation. For example you could have one file per customer.

So the file for customer 1 would look like this:

```auto
- module: apache
  access:
    enabled: true
    var.paths: ["/customer1/access.log"]
    input:
        processors:
           - add_fields:
               customerName: c1

```

The file for customer 2 the same, but using the values for customer 2, and so on.

This would allow you to more easily add or remove configurations as your customer base grows 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 19, 2022, 4:51pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-two-paths-and-two-access-inputs-to-configure/311404/4 "2022-09-19T16:51:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
