# Filebeat Monitoring Log files

**URL:** <https://discuss.elastic.co/t/filebeat-monitoring-log-files/142680>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 2, 2018, 5:35am UTC](https://discuss.elastic.co/t/filebeat-monitoring-log-files/142680 "2018-08-02T05:35:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Priyaranjan\_Mudliar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priyaranjan_mudliar/32/33726_2.png) [@Priyaranjan\_Mudliar](https://discuss.elastic.co/u/Priyaranjan_Mudliar)\
**Post date:** [August 2, 2018, 5:35am UTC](https://discuss.elastic.co/t/filebeat-monitoring-log-files/142680/1 "2018-08-02T05:35:46Z")

</div>

I am using filebeat to monitor log files and what i am trying to do is print only "Found Error" in another log file (using output.files option) if my log files has a message which contains "Error" string.

Can someone help me on this one?

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [August 2, 2018, 8:23am UTC](https://discuss.elastic.co/t/filebeat-monitoring-log-files/142680/2 "2018-08-02T08:23:41Z")

</div>

Hi @Priyaranjan_Mudliar,

I don't think that's possible, something you could do is output the line containing Error to that other log. Basically you can read everything and use `drop_event` processor to only output the lines that contain Error. Have a look to our docs here: [https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html)

Best regards

---

<div class="post-metadata">

**Author:** ![Debashis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/debashis/32/45290_2.png) [@Debashis](https://discuss.elastic.co/u/Debashis)\
**Post date:** [August 3, 2018, 10:38am UTC](https://discuss.elastic.co/t/filebeat-monitoring-log-files/142680/3 "2018-08-03T10:38:15Z")

</div>

@Priyaranjan_Mudliar Kindly provide your log file and describe exactly what you want in output. It will be very helpful to give proper response

---

<div class="post-metadata">

**Author:** ![Priyaranjan\_Mudliar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priyaranjan_mudliar/32/33726_2.png) [@Priyaranjan\_Mudliar](https://discuss.elastic.co/u/Priyaranjan_Mudliar)\
**Post date:** [August 3, 2018, 10:40am UTC](https://discuss.elastic.co/t/filebeat-monitoring-log-files/142680/4 "2018-08-03T10:40:07Z")

</div>

Thanks for the reply @exekias

I used the method that you mentioned. I used drop event processor but still getting an error while running filebeat. The error says "error in config file : did not find expected key". My filebeat input config part looks like this :

#=========================== Filebeat inputs =============================

filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so

# you can use different inputs for various configurations.

# Below are the input specific configurations.

- type: log  
processors:
- drop\_event:  
when:  
not:  
contains:  
message: "Error"

# Change to true to enable this input configuration.

enabled: true

# Paths that should be crawled and fetched. Glob based paths.

paths:  
- D:\Filebeat\mylog.log  
#- c:\programdata\elasticsearch\logs\*

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2018, 10:40am UTC](https://discuss.elastic.co/t/filebeat-monitoring-log-files/142680/5 "2018-08-31T10:40:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
