# How to use filebeat changes to collect the entire file

**URL:** <https://discuss.elastic.co/t/how-to-use-filebeat-changes-to-collect-the-entire-file/233440>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 20, 2020, 2:45am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-changes-to-collect-the-entire-file/233440 "2020-05-20T02:45:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![lisongtao](https://avatars.discourse-cdn.com/v4/letter/l/e5b9ba/32.png) [@lisongtao](https://discuss.elastic.co/u/lisongtao)\
**Post date:** [May 20, 2020, 2:45am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-changes-to-collect-the-entire-file/233440/1 "2020-05-20T02:45:42Z")

</div>

I want to use filbeat to collect configuration files, and when the file content has CRUD operations, the entire file content will be collected

---

<div class="post-metadata">

**Author:** ![lisongtao](https://avatars.discourse-cdn.com/v4/letter/l/e5b9ba/32.png) [@lisongtao](https://discuss.elastic.co/u/lisongtao)\
**Post date:** [May 20, 2020, 2:53am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-changes-to-collect-the-entire-file/233440/2 "2020-05-20T02:53:59Z")

</div>

Can you do this using configuration items? Like a multi-line merge

---

<div class="post-metadata">

**Author:** ![robhuang](https://avatars.discourse-cdn.com/v4/letter/r/db5fbb/32.png) [@robhuang](https://discuss.elastic.co/u/robhuang)\
**Post date:** [May 20, 2020, 3:22am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-changes-to-collect-the-entire-file/233440/3 "2020-05-20T03:22:13Z")

</div>

why don't consider auditbeat file integrity module [https://www.elastic.co/guide/en/beats/auditbeat/master/auditbeat-module-file\_integrity.html](https://www.elastic.co/guide/en/beats/auditbeat/master/auditbeat-module-file_integrity.html)

Any change to the file would be logged by this module

---

<div class="post-metadata">

**Author:** ![lisongtao](https://avatars.discourse-cdn.com/v4/letter/l/e5b9ba/32.png) [@lisongtao](https://discuss.elastic.co/u/lisongtao)\
**Post date:** [June 8, 2020, 9:47am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-changes-to-collect-the-entire-file/233440/4 "2020-06-08T09:47:56Z")

</div>

I want to receive the contents of the file, not the index data. Like collecting the full amount of configuration files every time

---

<div class="post-metadata">

**Author:** ![lisongtao](https://avatars.discourse-cdn.com/v4/letter/l/e5b9ba/32.png) [@lisongtao](https://discuss.elastic.co/u/lisongtao)\
**Post date:** [June 8, 2020, 9:49am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-changes-to-collect-the-entire-file/233440/5 "2020-06-08T09:49:23Z")

</div>

You get the full contents of the file every time you make a change

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2020, 9:49am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-changes-to-collect-the-entire-file/233440/6 "2020-07-06T09:49:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
