# How to configure different types of logs

**URL:** <https://discuss.elastic.co/t/how-to-configure-different-types-of-logs/53356>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 20, 2016, 6:39pm UTC](https://discuss.elastic.co/t/how-to-configure-different-types-of-logs/53356 "2016-06-20T18:39:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![keya](https://avatars.discourse-cdn.com/v4/letter/k/8baadc/32.png) [@keya](https://discuss.elastic.co/u/keya)\
**Post date:** [June 20, 2016, 6:39pm UTC](https://discuss.elastic.co/t/how-to-configure-different-types-of-logs/53356/1 "2016-06-20T18:39:39Z")

</div>

I want to configure two different logs in FIlebeat. I have system logs and JSON logs from my application. Can I configure both these in a single config file? If yes, what would be the configuration required for it?  
In the filebeat.yml I have below configuration:

```auto
prospectors:
    # Each - is a prospector. Below are the prospector specific configurations
    -
      input_type: log
      # Paths that should be crawled and fetched. Glob based paths.
      # For each file found under this path, a harvester is started.
      paths:
        - /home/Downloads/logs/log5.log
      # Type to be published in the 'type' field. For Elasticsearch output,
      # the type defines the document type these entries should be stored
      # in. Default: log
      document_type: applog
      json:
        message_key: log
        keys_under_root: true
        overwrite_keys: true
    -
      input_type: log
      paths:
        - /home/Downloads/logs_sys/log1.log
      document_type: systemlog

```

```auto
Thanks
```

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [June 21, 2016, 11:19am UTC](https://discuss.elastic.co/t/how-to-configure-different-types-of-logs/53356/2 "2016-06-21T11:19:55Z")

</div>

Yes, you can configure both in one config file. Your config looks ok. About the mapping: That depends on your json. I assume the reason you posted it, is that something is not working as expected?

---

<div class="post-metadata">

**Author:** ![keya](https://avatars.discourse-cdn.com/v4/letter/k/8baadc/32.png) [@keya](https://discuss.elastic.co/u/keya)\
**Post date:** [June 21, 2016, 3:21pm UTC](https://discuss.elastic.co/t/how-to-configure-different-types-of-logs/53356/3 "2016-06-21T15:21:05Z")

</div>

Yes. In app logs I have nested JSON objects while in the sys logs I have string in messages. IS there a way to specify a mapping where message can accept both string and JSON object.

I am getting below error in filebeat logs:  
WARN Can not index event (status=400): {"type":"mapper\_parsing\_exception","reason":"object mapping for [message] tried to parse field [message] as object, but found a concrete value"}

Also, if I have JSON logs do I need to use Filebeat 5.0.0-alpha3 only or can I also use Filebeat1.2 for it?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [June 22, 2016, 6:17am UTC](https://discuss.elastic.co/t/how-to-configure-different-types-of-logs/53356/4 "2016-06-22T06:17:34Z")

</div>

For the mapping: Elasticsearch can only have one mapping type for a single field. What you can do in your case is use Logstash to route the data to two difference indices.

JSON support is only available in the 5.0 releases.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2016, 6:39pm UTC](https://discuss.elastic.co/t/how-to-configure-different-types-of-logs/53356/5 "2016-07-11T18:39:47Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
