# Input multiple files using Elastic Agent

**URL:** <https://discuss.elastic.co/t/input-multiple-files-using-elastic-agent/317150>\
**Category:** Elastic Agent\
**Created:** [October 20, 2022, 7:17pm UTC](https://discuss.elastic.co/t/input-multiple-files-using-elastic-agent/317150 "2022-10-20T19:17:26Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![shuuny-matrix](https://avatars.discourse-cdn.com/v4/letter/s/7993a0/32.png) [@shuuny-matrix](https://discuss.elastic.co/u/shuuny-matrix)\
**Post date:** [October 20, 2022, 7:17pm UTC](https://discuss.elastic.co/t/input-multiple-files-using-elastic-agent/317150/1 "2022-10-20T19:17:26Z")

</div>

Hi,  
I wanted to input multiple files with same category from a directory to a same index into Kibana with Elasticsearch backend. I noticed that it could be done using Logstash but not clear documentation on how to do to using Elastic agent and ingest pipelines. Any ideas or tips would be appreciated. Thanks.

---

<div class="post-metadata">

**Author:** ![cheshirecat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheshirecat/32/109532_2.png) [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Post date:** [October 21, 2022, 11:34am UTC](https://discuss.elastic.co/t/input-multiple-files-using-elastic-agent/317150/2 "2022-10-21T11:34:50Z")

</div>

> [@shuuny-matrix](#):
>
> nput multiple files with same category from a directory

How about FSCrawler?

---

<div class="post-metadata">

**Author:** ![shuuny-matrix](https://avatars.discourse-cdn.com/v4/letter/s/7993a0/32.png) [@shuuny-matrix](https://discuss.elastic.co/u/shuuny-matrix)\
**Post date:** [October 21, 2022, 4:30pm UTC](https://discuss.elastic.co/t/input-multiple-files-using-elastic-agent/317150/3 "2022-10-21T16:30:06Z")

</div>

@cheshirecat Is there no inbuilt solution for this with elastic agent and ingest pipeline?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 21, 2022, 5:39pm UTC](https://discuss.elastic.co/t/input-multiple-files-using-elastic-agent/317150/4 "2022-10-21T17:39:47Z")

</div>

@shuuny-matrix

Perhaps take a look at Custom Logs Integration add each of the Logs Paths and and an Ingest Pipelines settings etc

You might need to Create a Top Level Pipeline that then call the more specific pipelines to process each type, much like using the If / Else processing

 ![Screen Shot 2022-10-21 at 10.37.28 AM](https://us1.discourse-cdn.com/elastic/original/3X/9/b/9b21895d106c610121de9eb8bf6dd59b4a9e5503.png)

---

<div class="post-metadata">

**Author:** ![shuuny-matrix](https://avatars.discourse-cdn.com/v4/letter/s/7993a0/32.png) [@shuuny-matrix](https://discuss.elastic.co/u/shuuny-matrix)\
**Post date:** [October 22, 2022, 10:08am UTC](https://discuss.elastic.co/t/input-multiple-files-using-elastic-agent/317150/5 "2022-10-22T10:08:29Z")

</div>

@stephenb Yes, I think I should look into this. Maybe its time to make a documentation about this from Elastic team.

---

<div class="post-metadata">

**Author:** ![cheshirecat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheshirecat/32/109532_2.png) [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Post date:** [October 24, 2022, 8:31am UTC](https://discuss.elastic.co/t/input-multiple-files-using-elastic-agent/317150/6 "2022-10-24T08:31:21Z")

</div>

> [@shuuny-matrix](#):
>
> @cheshirecat Is there no inbuilt solution for this with elastic agent and ingest pipeline?

I don't know things like that - I use FSCrawler for ingesting many files into indices.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 24, 2022, 6:23pm UTC](https://discuss.elastic.co/t/input-multiple-files-using-elastic-agent/317150/7 "2022-10-24T18:23:10Z")

</div>

@shuuny-matrix

You could also look at

> **[Tutorial: Transform data with custom ingest pipelines | Fleet and Elastic...](https://www.elastic.co/guide/en/fleet/current/data-streams-pipeline-tutorial.html)**

---

<div class="post-metadata">

**Author:** ![shuuny-matrix](https://avatars.discourse-cdn.com/v4/letter/s/7993a0/32.png) [@shuuny-matrix](https://discuss.elastic.co/u/shuuny-matrix)\
**Post date:** [October 25, 2022, 8:27am UTC](https://discuss.elastic.co/t/input-multiple-files-using-elastic-agent/317150/8 "2022-10-25T08:27:17Z")

</div>

@stephenb Thanks but the above link is for adding a new field to each document. But what I am looking is concatenating 100's of log files into a single index from a specified directory.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 25, 2022, 3:06pm UTC](https://discuss.elastic.co/t/input-multiple-files-using-elastic-agent/317150/9 "2022-10-25T15:06:42Z")

</div>

The picture I showed above using custom logs can accomplish that ... you can use wildcards in the log path

`/path/to/logs/*.log`

I am not sure what you mean by concatenating ... but it is very common to read many log files into a single index / index pattern etc that is a very common use case.

---

<div class="post-metadata">

**Author:** ![shuuny-matrix](https://avatars.discourse-cdn.com/v4/letter/s/7993a0/32.png) [@shuuny-matrix](https://discuss.elastic.co/u/shuuny-matrix)\
**Post date:** [October 25, 2022, 4:08pm UTC](https://discuss.elastic.co/t/input-multiple-files-using-elastic-agent/317150/10 "2022-10-25T16:08:38Z")

</div>

@stephenb. Yes, I am playing with custom logs integration. I think `/path/to/logs/*.log` will work. Thanks for the reply.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2022, 4:09pm UTC](https://discuss.elastic.co/t/input-multiple-files-using-elastic-agent/317150/11 "2022-11-22T16:09:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
