# Filebeats and multiple files

**URL:** <https://discuss.elastic.co/t/filebeats-and-multiple-files/57295>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 5, 2016, 2:00am UTC](https://discuss.elastic.co/t/filebeats-and-multiple-files/57295 "2016-08-05T02:00:08Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jamesl](https://avatars.discourse-cdn.com/v4/letter/j/c0e974/32.png) [@jamesl](https://discuss.elastic.co/u/jamesl)\
**Post date:** [August 5, 2016, 2:00am UTC](https://discuss.elastic.co/t/filebeats-and-multiple-files/57295/1 "2016-08-05T02:00:08Z")

</div>

Hi. I have a requirement to pull in multiple files from the same host, but in Logstash they need to follow different input/filter and output paths.  
I was going to setup 2 Filebeats on this Unix hosts but that doesn't seem too efficient.

Is there another 'easier' way to do this?

Thanks.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 5, 2016, 7:06am UTC](https://discuss.elastic.co/t/filebeats-and-multiple-files/57295/2 "2016-08-05T07:06:00Z")

</div>

Why not use [https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#configuration-fields](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#configuration-fields) and then [https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html)

---

<div class="post-metadata">

**Author:** ![jamesl](https://avatars.discourse-cdn.com/v4/letter/j/c0e974/32.png) [@jamesl](https://discuss.elastic.co/u/jamesl)\
**Post date:** [August 7, 2016, 10:36am UTC](https://discuss.elastic.co/t/filebeats-and-multiple-files/57295/3 "2016-08-07T10:36:27Z")

</div>

Hi. I setup another Prospectors in /etc/filebeat/filebeat.yml and can see it in Kibana.

Below is what I did in the config file:  
filebeat:

 prospectors: # Each - is a prospector. Below are the prospector specific configurations - paths: - /var/log/rsyslog.log.file input\_type: rsyslog.log01 - paths: - /var/log/\*.log - /var/log/syslog - /var/log/apt/\* input\_type: syslog

and an extract of the Kibana json.  
{  
"\_index": "logs-2016.08.07",  
"\_type": "logs-log02",  
"\_id": "AVZkjypyu9iLKWAc6aqV",  
"\_score": null,  
"\_source": {  
"message": "2016-08-07T20:30:54.641225+10:00 192.168.10.112 137: AP:e8b7.48de.05fb: \*Aug 7 10:30:53.529: %WIDS-6-ENABLED: IDS Signature is loaded and enabled",  
"@version": "1",  
"@timestamp": "2016-08-07T10:31:59.273Z",  
"path": "/var/log/rsyslog.log.file",  
"host": "log02",  
"type": "logs-log02"  
},  
"fields": {  
"@timestamp": [  
1470565919273  
]  
},  
"highlight": {  
"path": [  
"/var/log/@kibana-highlighted-field@rsyslog.log.file@/kibana-highlighted-field@"  
]  
},  
"sort": [  
1470565919273  
]  
}

Can I somehow call the index 'local\_syslog' so I can create an index of it?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 7, 2016, 3:06pm UTC](https://discuss.elastic.co/t/filebeats-and-multiple-files/57295/4 "2016-08-07T15:06:20Z")

</div>

As documented [here](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#_input_type), `input_type` supports only two possible values -- log and stdin. Try using [`document_type`](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#_document_type) or [`fields`](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#configuration-fields) (as previosly suggested by warkolm).

---

<div class="post-metadata">

**Author:** ![jamesl](https://avatars.discourse-cdn.com/v4/letter/j/c0e974/32.png) [@jamesl](https://discuss.elastic.co/u/jamesl)\
**Post date:** [August 10, 2016, 1:29pm UTC](https://discuss.elastic.co/t/filebeats-and-multiple-files/57295/5 "2016-08-10T13:29:03Z")

</div>

Thanks that worked.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 26, 2016, 2:00am UTC](https://discuss.elastic.co/t/filebeats-and-multiple-files/57295/6 "2016-08-26T02:00:10Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
