# How to auto sync the log files to log stash server

**URL:** <https://discuss.elastic.co/t/how-to-auto-sync-the-log-files-to-log-stash-server/373605>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 23, 2025, 10:39pm UTC](https://discuss.elastic.co/t/how-to-auto-sync-the-log-files-to-log-stash-server/373605 "2025-01-23T22:39:23Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![JyotiPrakash](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jyotiprakash/32/138143_2.png) [@JyotiPrakash](https://discuss.elastic.co/u/JyotiPrakash)\
**Post date:** [January 23, 2025, 10:39pm UTC](https://discuss.elastic.co/t/how-to-auto-sync-the-log-files-to-log-stash-server/373605/1 "2025-01-23T22:39:23Z")

</div>

Here is my set up,

I am running ELK on a remote VM, and I am trying to sync all the logfiles from the local machine to the remote server without restarting the filebeat service (note the filebeat service is running on my local machine).

_ **Configuration Details:** _

- ELK is running on a remote VM of Ubuntu Type
- Filebeat service is running on my local machine of Windows type.

_ **Problem statement:** _

- My app service is generating logs on my local machine, and I am trying to sync it with the ELK without restarting the filebeat service every time.
- I have two log file types: info log and error log, and I want to send both to the ELK stack.

_ **What am I solving this problem now?** _  
I am restating the file beat service on my Windows every time. But I am only seeing one type of log.

_ **Details:** _

- My file beat YML file configuration:

```auto

---
filebeat.inputs:
  - type: log
    id: i4eappinfo
    enabled: true
    paths:
      - C:\\appServerLog\\output\\i4e-mf-node-api-logs.log
    multiline.pattern: ^[0-9]{2}-[0-9]{2}-[0-9]{4}
    multiline.negate: true
    multiline.match: after
    refresh_frequency: 10s
    scan_frequency: 5s
  - type: log
    id: i4eapperror
    enabled: true
    paths:
      - C:\\appServerLog\\output\\i4e-mf-node-api-errors.log
    multiline.pattern: ^[0-9]{2}-[0-9]{2}-[0-9]{4}
    multiline.negate: true
    multiline.match: after
    refresh_frequency: 10s
    scan_frequency: 5s
filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: false
setup.template.settings:
  index.number_of_shards: 1
setup.kibana:
  host: <remote_server>:5601
output.elasticsearch:
  hosts:
    - <remote_server>:9200
  username: <user_name>
  password: <password>
  preset: balanced
processors:
  - add_host_metadata:
      when.not.contains.tags: forwarded
  - add_cloud_metadata: null
  - add_docker_metadata: null
  - add_kubernetes_metadata: null

```

And here is a sample of the logs files.

Error Log:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/a/6adeed7b6f6532e89f5c0bf7e5ccbf039513b9e0.png)

Info Log:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/f/df98fad3960852fb422543bda63e3537612f725d.png)

Service Details:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/8/88b5748d5e21ddd334ac3ad6959284956fde4d04.png)

_ **Configuration Details on ELK:** _

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/f/dfb2c2985b2add5b72764bdba9b9938fc5325f2f.png)

Could someone assist what I have missed here? That would be helpful.
