# Multiple configs in /etc/filebeat/\*.yml

**URL:** <https://discuss.elastic.co/t/multiple-configs-in-etc-filebeat-yml/63876>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 25, 2016, 1:54pm UTC](https://discuss.elastic.co/t/multiple-configs-in-etc-filebeat-yml/63876 "2016-10-25T13:54:57Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![jvdm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jvdm/32/12707_2.png) [@jvdm](https://discuss.elastic.co/u/jvdm)\
**Post date:** [October 25, 2016, 1:54pm UTC](https://discuss.elastic.co/t/multiple-configs-in-etc-filebeat-yml/63876/1 "2016-10-25T13:54:57Z")

</div>

Greetings all,

I'm trying to use multiple config files located in /etc/filebeat. The default config is stored as filebeat.yml, with additional configs stored as $service.yml. I've verified that all the configs are working and functional by using the "-c config.yml -e -d "\*"" switches against each .yml. When starting filebeat, only one prospector and accompanying paths from filebeat.yml are active. I'm using filebeat version 5.0.0-rc1.

I'm trying to use the same approach with packetbeat and metricbeat, whereby system defaults are located in \*beat.yml, and additional services are defined in $service.yml via configuration management (ansible).

Any help/suggestions would be most welcome!

-Jacques

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 25, 2016, 3:14pm UTC](https://discuss.elastic.co/t/multiple-configs-in-etc-filebeat-yml/63876/2 "2016-10-25T15:14:13Z")

</div>

What is your exact command that you use to start filebeat etc.?

---

<div class="post-metadata">

**Author:** ![jvdm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jvdm/32/12707_2.png) [@jvdm](https://discuss.elastic.co/u/jvdm)\
**Post date:** [October 25, 2016, 3:16pm UTC](https://discuss.elastic.co/t/multiple-configs-in-etc-filebeat-yml/63876/3 "2016-10-25T15:16:30Z")

</div>

Hi @ruflin,

"/usr/share/filebeat/bin/filebeat -c /etc/filebeat/filebeat.yml -path.home /usr/share/filebeat -path.config /etc/filebeat -path.data /var/lib/filebeat -path.logs /var/log/filebeat"

I've tried pointing -path.config to another location other than /etc/filebeat as well.

It's launched via systemctl, and I've tried manually on the command line as well...

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 26, 2016, 9:55am UTC](https://discuss.elastic.co/t/multiple-configs-in-etc-filebeat-yml/63876/4 "2016-10-26T09:55:58Z")

</div>

I think you are mixing here two things:

- You can use the `-c` option multiple times to chain multiple config files: [https://www.elastic.co/guide/en/beats/libbeat/5.0/config-file-format-cli.html](https://www.elastic.co/guide/en/beats/libbeat/5.0/config-file-format-cli.html) This works for all beats
- The option you are probably looking for in filebeat is `config_dir`: [https://www.elastic.co/guide/en/beats/filebeat/5.0/configuration-global-options.html#\_config\_dir](https://www.elastic.co/guide/en/beats/filebeat/5.0/configuration-global-options.html#_config_dir) This currently does not exist for the other beats
- Defining `path.config` only tells the beat where to look for the `beatname.yml` file.

Let me know if the above helps.

---

<div class="post-metadata">

**Author:** ![jvdm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jvdm/32/12707_2.png) [@jvdm](https://discuss.elastic.co/u/jvdm)\
**Post date:** [October 26, 2016, 12:09pm UTC](https://discuss.elastic.co/t/multiple-configs-in-etc-filebeat-yml/63876/5 "2016-10-26T12:09:21Z")

</div>

This does help indeed, thanks! The docs that I referenced previously did not mention the config\_dir option, and eluded to the -path.config switch instead.

Regarding the other beats, how does one take a modular approach with the configs?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 26, 2016, 8:34pm UTC](https://discuss.elastic.co/t/multiple-configs-in-etc-filebeat-yml/63876/6 "2016-10-26T20:34:08Z")

</div>

For the other beats currently the best approach is using the chaining of config files with `-c`. Or as you alreasy use ansible it should be possible to use ansible to generate one big config file.

What docs were you referencing to initially where the config\_dir was not mentioned?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 15, 2016, 1:55pm UTC](https://discuss.elastic.co/t/multiple-configs-in-etc-filebeat-yml/63876/7 "2016-11-15T13:55:05Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
