# Multiple config file

**URL:** https://discuss.elastic.co/t/multiple-config-file/203448
**Category:** Beats
**Tags:** filebeat
**Created:** [October 14, 2019, 12:18pm UTC](https://discuss.elastic.co/t/multiple-config-file/203448 "2019-10-14T12:18:20Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Mohammad.ali](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammad.ali/32/45665_2.png) [@Mohammad.ali](https://discuss.elastic.co/u/Mohammad.ali)
#### Post date: [October 14, 2019, 12:18pm UTC](https://discuss.elastic.co/t/multiple-config-file/203448/1 "2019-10-14T12:18:21Z")

</div>

Hello everyone  
i have a simple filebeat.yml which send some log from specific path to logstash  
my problem is how can i activate some filebeat modules such as system on this host while the output of filebeat.yml is logstash and the modules used elasticsearch as output??  
should i config multiple config file for this purpose?or should i have create multiple filebeat service ?

---

<div class="post-metadata">

### Author: ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)
#### Post date: [October 14, 2019, 12:30pm UTC](https://discuss.elastic.co/t/multiple-config-file/203448/2 "2019-10-14T12:30:12Z")

</div>

@Mohammad.ali,

Which version are you using? Yes, you can use filebeat modules with logstash output. You need to use logstash pipeline for parsing. Please refer the below documentation:

[Logstash pipeline for parsing](https://www.elastic.co/guide/en/logstash/current/logstash-config-for-filebeat-modules.html)

Thanks.

---

<div class="post-metadata">

### Author: ![Mohammad.ali](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammad.ali/32/45665_2.png) [@Mohammad.ali](https://discuss.elastic.co/u/Mohammad.ali)
#### Post date: [October 14, 2019, 12:33pm UTC](https://discuss.elastic.co/t/multiple-config-file/203448/3 "2019-10-14T12:33:40Z")

</div>

Thanks for reply...right now iam using 7.3.0  
so when the output of filebeat.yml is defined to logstash any activated filebeat modules send their log to logstash ?and for this purpose i can use the link you sent me,,am i right?

---

<div class="post-metadata">

### Author: ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)
#### Post date: [October 14, 2019, 12:40pm UTC](https://discuss.elastic.co/t/multiple-config-file/203448/4 "2019-10-14T12:40:35Z")

</div>

@Mohammad.ali,

For 7.3.0 you can refer below document:  
[Logstash pipeline for parsing](https://www.elastic.co/guide/en/logstash/7.3/logstash-config-for-filebeat-modules.html)

> [@Mohammad.ali](#):
>
> so when the output of filebeat.yml is defined to logstash any activated filebeat modules send their log to logstash ?and for this purpose i can use the link you sent me,,am i right?

Yes...document is saying this. But i did not use this. Currently i am using 6.4.0. There is slightly difference between both version. But i follow same procedure in 6.4.0. So it should work in 7.3.0 also and document is saying that.

Please read the document.

Thanks.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 11, 2019, 12:40pm UTC](https://discuss.elastic.co/t/multiple-config-file/203448/5 "2019-11-11T12:40:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
