# Filebeat.full.yml Complete

**URL:** <https://discuss.elastic.co/t/filebeat-full-yml-complete/91782>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 4, 2017, 1:45pm UTC](https://discuss.elastic.co/t/filebeat-full-yml-complete/91782 "2017-07-04T13:45:38Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![erion](https://avatars.discourse-cdn.com/v4/letter/e/779978/32.png) [@erion](https://discuss.elastic.co/u/erion)\
**Post date:** [July 4, 2017, 1:45pm UTC](https://discuss.elastic.co/t/filebeat-full-yml-complete/91782/1 "2017-07-04T13:45:38Z")

</div>

Hi, my ocnfiguration filebeat.yml in like

> Filebeat.prospectors:  
> -input\_type: log  
> Paths:
> 
> - /mnt/analog/file\_name\_log  
> Output.elasticsearch:  
> hosts: [“27.49.258.78”]  
> protocol: “https”

when i try to upload log with command cat send me some errors.  
I think it occurs because i don't config filebeat.full.yml. I don't understand how can i configure that for apache logs. i've tried add my logstash conf

> input {  
> stdin {  
> }
> 
> filter {  
> grok {  
> match =\> {  
> "message" =\> '(?:-|%{IPORHOST:clientip}) %{USER:ident} %{USER:auth} [%{HTTPDATE:timestamp}] "%{NOTSPACE:verb} %{DATA:request} HTTP/%{NUMBER:httpversion}" %{NUMBER:response:int} (?:-|%{NUMBER:bytes:int}) %{QS:referrer} %{QS:agent}'  
> }  
> }  
> mutate {  
> add\_field =\> {  
> "richiesta" =\> "%{request}"  
> }  
> }  
> mutate {  
> lowercase =\> ["request"]  
> }  
> date {  
> match =\> ["timestamp", "dd/MMM/YYYY:HH:mm:ss Z"]  
> target =\> "@timestamp"  
> locale =\> en  
> }

> geoip {  
> source =\> "clientip"  
> }

> useragent {  
> source =\> "agent"  
> target =\> "useragent"  
> }  
> }

> output {  
> stdout {  
> codec =\> dots {}  
> }  
> elasticsearch {  
> hosts =\> ["25.528.67.24"]  
> index =\> "apache\_elastic"  
> template =\> "./apache\_template.json"  
> template\_name =\> "apache\_elastic"  
> template\_overwrite =\> false  
> }  
> }

When i add this config to filebeat.full.yml sand me lot of error.  
What can i do for use filebeat easly like logstash?  
thanks for replay. help please

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 4, 2017, 8:19pm UTC](https://discuss.elastic.co/t/filebeat-full-yml-complete/91782/2 "2017-07-04T20:19:07Z")

</div>

`filebeat.full.yml` is a reference file. It is not read by Filebeat.

I recommend that you follow the Filebeat [getting started guide](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-getting-started.html), and ensure that you have a beats input enabled in your Logstash config (which is covered by the [guide](https://www.elastic.co/guide/en/beats/libbeat/5.4/logstash-installation.html#logstash-setup)).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 1, 2017, 8:19pm UTC](https://discuss.elastic.co/t/filebeat-full-yml-complete/91782/3 "2017-08-01T20:19:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
