# Filebeat hints-based autodiscover with \> 2 streams

**URL:** <https://discuss.elastic.co/t/filebeat-hints-based-autodiscover-with-2-streams/273976>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 25, 2021, 4:31pm UTC](https://discuss.elastic.co/t/filebeat-hints-based-autodiscover-with-2-streams/273976 "2021-05-25T16:31:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![DougR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dougr/32/48095_2.png) [@DougR](https://discuss.elastic.co/u/DougR)\
**Post date:** [May 25, 2021, 4:31pm UTC](https://discuss.elastic.co/t/filebeat-hints-based-autodiscover-with-2-streams/273976/1 "2021-05-25T16:31:05Z")

</div>

I'm using hints-based autodiscover for filebeats deployed to a Kubernetes environment. Per [the docs](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover-hints.html), I can direct different streams to different filesets, per the following example for `nginx`:

```auto
co.elastic.logs/module: nginx
co.elastic.logs/fileset.stdout: access
co.elastic.logs/fileset.stderr: error

```

I'm turning on a module (elasticsearch) that appears to have \> 2 filesets (it appears to have 5?).

How can I separate out the filesets in this situation?

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [May 26, 2021, 7:07am UTC](https://discuss.elastic.co/t/filebeat-hints-based-autodiscover-with-2-streams/273976/2 "2021-05-26T07:07:07Z")

</div>

I'm not sure if i understand your concern. In general there are two properties to do that:

> **[Hints based autodiscover | Filebeat Reference \[7.13\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover-hints.html#_co_elastic_logsfileset)**

> **[Hints based autodiscover | Filebeat Reference \[7.13\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover-hints.html#_co_elastic_logsmodule)**

---

<div class="post-metadata">

**Author:** ![DougR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dougr/32/48095_2.png) [@DougR](https://discuss.elastic.co/u/DougR)\
**Post date:** [May 26, 2021, 12:52pm UTC](https://discuss.elastic.co/t/filebeat-hints-based-autodiscover-with-2-streams/273976/3 "2021-05-26T12:52:22Z")

</div>

> [@mtojek](#):
>
> I'm not sure if i understand your concern. In general there are two properties to do that:

I've already seen this part of the documentation and have it implemented. However, specifically for the Elasticsearch module, there appear to be five separate datasets (audit, deprecation, gc, server, and slowlog), and no indication which stream they're sent to with the official Elastic filebeat image (as far as I can tell). Specifically, I'm trying to determine with this whether I can still split the logs by dataset and, if so, how?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 23, 2021, 2:53pm UTC](https://discuss.elastic.co/t/filebeat-hints-based-autodiscover-with-2-streams/273976/4 "2021-06-23T14:53:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
