# Filebeat multi source logs problem

**URL:** <https://discuss.elastic.co/t/filebeat-multi-source-logs-problem/147850>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 9, 2018, 9:23am UTC](https://discuss.elastic.co/t/filebeat-multi-source-logs-problem/147850 "2018-09-09T09:23:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![abu.sayeed](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@abu.sayeed](https://discuss.elastic.co/u/abu.sayeed)\
**Post date:** [September 9, 2018, 9:23am UTC](https://discuss.elastic.co/t/filebeat-multi-source-logs-problem/147850/1 "2018-09-09T09:23:30Z")

</div>

cat /etc/filebeat/filebeat.yml

```auto
filebeat.config.modules:
  path: /etc/filebeat/modules.d/*.yml
  reload.enabled: false
filebeat.inputs:
- type: log
  enabled: false
paths:
    - /var/log/*.log
    - /home/local/example/example.log
filebeat.registry_file: /var/lib/filebeat/registry
output.elasticsearch:
hosts: ["192.168.100.100:9200"]
ssl.certificate_authorities: ["/etc/pki/tls/certs/beats.crt"]
setup.template.settings:
  index:
    number_of_shards: 3
setup.kibana:
    host: "192.168.100.100:5601"
logging.to_files: true
logging.files:
rotateeverybytes: 10485760 # = 10MB
keepfiles: 7

```

cat /etc/filebeat/modules.d/system.yml

```auto
- module: system
  syslog:
    enabled: true

    var.paths: ["/var/log/syslog*"]
    var.convert_timezone: true

  auth:
    enabled: true
    var.paths: ["/var/log/auth.log*"]

    var.convert_timezone: true

```

filebeat modules list

**Enabled:**  
system

**Disabled:**  
apache2  
auditd  
elasticsearch  
icinga  
iis  
kafka  
kibana  
logstash  
mongodb  
mysql  
nginx  
osquery  
postgresql  
redis  
traefik

Elk server show only  
source: /var/log/syslog\* and /var/log/auth.log\*

Don't show:  
source: /home/local/example/example.log

I need also /home/local/example/example.log source logs and syslog both.

What is my wrong?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [September 10, 2018, 5:59pm UTC](https://discuss.elastic.co/t/filebeat-multi-source-logs-problem/147850/2 "2018-09-10T17:59:03Z")

</div>

Looking at your `filebeat.yml` I see that the inputs that you have defined for `/home/local` have the `enabled` flag set to **false** , you have to enable it. Look at my example below:

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /var/log/*.log
    - /home/local/example/example.log

```

---

<div class="post-metadata">

**Author:** ![abu.sayeed](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@abu.sayeed](https://discuss.elastic.co/u/abu.sayeed)\
**Post date:** [October 3, 2018, 9:52am UTC](https://discuss.elastic.co/t/filebeat-multi-source-logs-problem/147850/3 "2018-10-03T09:52:19Z")

</div>

I have some custom grok in logstash conf.d directory. That grok split /home/local/example/example.log path data. I wish - /var/log/\*.log path data will be split via filebeat system module and /home/local/example/example.log path data will be split via custom grok.

If I configue filebeat.yum like

output.logstash:  
hosts: ["192.168.10.1:5044"]

/home/local/example/example.log path data split field:  
"Class" =\> "c.n.s.s.SmsGatewayService:331"  
"source" =\> "/home/local/example/example.log",  
"@timestamp" =\> 2018-10-03T09:35:57.404Z,  
"Thread" =\> "http-nio-8080-exec-6",  
"host" =\> {  
"name" =\> "vm1"  
},

But I configure filebeat like

setup.kibana:  
host: "192.168.10.1:5601"

output.elasticsearch:  
hosts: ["192.168.10.1:9200"]

/home/local/example/example.log path data will not be split:  
message:xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.

I need to split module data and custom path data via output elasticsearch and kibana host.

Thanks for help me

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 31, 2018, 9:52am UTC](https://discuss.elastic.co/t/filebeat-multi-source-logs-problem/147850/4 "2018-10-31T09:52:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
