# How to enable symlinks?

**URL:** <https://discuss.elastic.co/t/how-to-enable-symlinks/126852>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 5, 2018, 6:40am UTC](https://discuss.elastic.co/t/how-to-enable-symlinks/126852 "2018-04-05T06:40:31Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ayrodrig](https://avatars.discourse-cdn.com/v4/letter/a/8dc957/32.png) [@ayrodrig](https://discuss.elastic.co/u/ayrodrig)\
**Post date:** [April 5, 2018, 6:40am UTC](https://discuss.elastic.co/t/how-to-enable-symlinks/126852/1 "2018-04-05T06:40:31Z")

</div>

Hi there!

I'm pretty much interested in enabling the symlinks option for the reason already stated at the documentation [https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#\_literal\_symlinks\_literal](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#_literal_symlinks_literal) "The symlinks option can be useful if symlinks to the log files have additional metadata in the file name, and you want to process the metadata in Logstash. This is, for example, the case for Kubernetes log files."

I'm trying to collect logs from kubernetes, and I can do it without issues when I'm accessing non symlinks files, that is actually what I want to do, since the symlinks files names are giving me a bunch of extra information (app or system that generated the logs).

I tried to add a line "symlinks: true" in the snippet section of the corresponding collector but this just add the line at the end of filebeat.yml.

How should I write the snippet? Or is there any other way to make this working?

Thanks!

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [April 5, 2018, 9:24am UTC](https://discuss.elastic.co/t/how-to-enable-symlinks/126852/2 "2018-04-05T09:24:02Z")

</div>

To use `symlink: true` you have to add it to your [prospector configuration](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html), and check that your `paths` are only configured with the paths to your symlink files.

---

<div class="post-metadata">

**Author:** ![ayrodrig](https://avatars.discourse-cdn.com/v4/letter/a/8dc957/32.png) [@ayrodrig](https://discuss.elastic.co/u/ayrodrig)\
**Post date:** [April 5, 2018, 9:46am UTC](https://discuss.elastic.co/t/how-to-enable-symlinks/126852/3 "2018-04-05T09:46:38Z")

</div>

I'm using a collector sidecar that generates the filebeat.yml from the graylog server. This is why I was trying to include that option using a snippet. Is there any way to write the snippet in order to place that line in the [https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html) as you mention?

Thx!

---

<div class="post-metadata">

**Author:** ![ayrodrig](https://avatars.discourse-cdn.com/v4/letter/a/8dc957/32.png) [@ayrodrig](https://discuss.elastic.co/u/ayrodrig)\
**Post date:** [April 5, 2018, 10:11am UTC](https://discuss.elastic.co/t/how-to-enable-symlinks/126852/4 "2018-04-05T10:11:47Z")

</div>

Another way to solve this issue would be to include support for the symlinks as for other features [https://github.com/Graylog2/graylog-plugin-collector/issues/78](https://github.com/Graylog2/graylog-plugin-collector/issues/78)

Any help really appreciate!

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [April 5, 2018, 6:51pm UTC](https://discuss.elastic.co/t/how-to-enable-symlinks/126852/5 "2018-04-05T18:51:25Z")

</div>

Yes, it seems more an issue with Greylog then, it should allow to add configuration in the `prospector` itself, does it have any way to do it?

---

<div class="post-metadata">

**Author:** ![ayrodrig](https://avatars.discourse-cdn.com/v4/letter/a/8dc957/32.png) [@ayrodrig](https://discuss.elastic.co/u/ayrodrig)\
**Post date:** [April 6, 2018, 7:06am UTC](https://discuss.elastic.co/t/how-to-enable-symlinks/126852/6 "2018-04-06T07:06:17Z")

</div>

Nop, AFAIK...

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [April 6, 2018, 12:17pm UTC](https://discuss.elastic.co/t/how-to-enable-symlinks/126852/7 "2018-04-06T12:17:56Z")

</div>

It seems that it there is a way to do it, but putting all prospectors configuration in snippets, see [https://community.graylog.org/t/how-to-configure-filebeat-from-graylog-to-parse-json/3226/8](https://community.graylog.org/t/how-to-configure-filebeat-from-graylog-to-parse-json/3226/8)

---

<div class="post-metadata">

**Author:** ![ayrodrig](https://avatars.discourse-cdn.com/v4/letter/a/8dc957/32.png) [@ayrodrig](https://discuss.elastic.co/u/ayrodrig)\
**Post date:** [April 9, 2018, 6:21am UTC](https://discuss.elastic.co/t/how-to-enable-symlinks/126852/8 "2018-04-09T06:21:35Z")

</div>

Thx. I just copied the full prospectors configuration in snippets and it worked, but I get the configuration twice since the input/output could not be empty. I will do a pull request with a fix to correct it in a more elegant way.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2018, 6:21am UTC](https://discuss.elastic.co/t/how-to-enable-symlinks/126852/9 "2018-05-07T06:21:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
