# Filebeat with Nginx, how to differentiate 2 files?

**URL:** <https://discuss.elastic.co/t/filebeat-with-nginx-how-to-differentiate-2-files/103346>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 10, 2017, 10:42am UTC](https://discuss.elastic.co/t/filebeat-with-nginx-how-to-differentiate-2-files/103346 "2017-10-10T10:42:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![gabriel\_tessier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel_tessier/32/27911_2.png) [@gabriel\_tessier](https://discuss.elastic.co/u/gabriel_tessier)\
**Post date:** [October 10, 2017, 10:42am UTC](https://discuss.elastic.co/t/filebeat-with-nginx-how-to-differentiate-2-files/103346/1 "2017-10-10T10:42:49Z")

</div>

Good evening,

I use Filebeat for nginx files with ingest, here my filebeat config file:

```
{
  "output.elasticsearch": {
    "hosts": [
      "172.16.1.3:9200"
    ],
    "template.enabled": false,
    "index": "prod-%{+yyyy.MM.dd}"
  },
  "filebeat.modules": [
    {
      "access": {
        "enabled": true,
        "var.paths": [
          "/var/log/nginx/access-http.log",
          "/var/log/nginx/access-https.log",
        ],
        "encoding": utf-8
      },
      "module": "nginx"
    }
  ],
  "logging.to_files": false,
  "logging.files": null,
  "tags": ["prod", "service_prod"]
}

```

Everything work perfectly, I receive the content of both files in my index, my problem is how can I make a difference between the data coming from access-http and the data from access-https?  
I tried several key like "document-type", "input-type" duplicate the "access" key inside modules array, also tried to define prospector key, I didn't get error but the value in kibana (and elastic) for type field is always log!!

Which key I need to define to differentiate the data coming from this 2 files, where and what to split to do it?

Thanks for any help.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 10, 2017, 11:37am UTC](https://discuss.elastic.co/t/filebeat-with-nginx-how-to-differentiate-2-files/103346/2 "2017-10-10T11:37:31Z")

</div>

You should have a field `source` in each event which contains the full file path.

---

<div class="post-metadata">

**Author:** ![gabriel\_tessier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel_tessier/32/27911_2.png) [@gabriel\_tessier](https://discuss.elastic.co/u/gabriel_tessier)\
**Post date:** [October 11, 2017, 2:15am UTC](https://discuss.elastic.co/t/filebeat-with-nginx-how-to-differentiate-2-files/103346/3 "2017-10-11T02:15:36Z")

</div>

Yes, you are great!! Big thanks.

I need new glasses! 😀

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 8, 2017, 2:16am UTC](https://discuss.elastic.co/t/filebeat-with-nginx-how-to-differentiate-2-files/103346/4 "2017-11-08T02:16:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
