# Multiple definitions for the same module?

**URL:** <https://discuss.elastic.co/t/multiple-definitions-for-the-same-module/106839>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 8, 2017, 9:54am UTC](https://discuss.elastic.co/t/multiple-definitions-for-the-same-module/106839 "2017-11-08T09:54:44Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sebastien.k](https://avatars.discourse-cdn.com/v4/letter/s/e99b99/32.png) [@sebastien.k](https://discuss.elastic.co/u/sebastien.k)\
**Post date:** [November 8, 2017, 9:54am UTC](https://discuss.elastic.co/t/multiple-definitions-for-the-same-module/106839/1 "2017-11-08T09:54:44Z")

</div>

Hi,

We have created a specific filebeat module to parse Drupal logs.

In `filebeat.yml` we declare two entries for `filebeat.modules` with this custom module in order to distinguish preprod and prod environments (by adding some fields and tags).

Here the config

```auto
filebeat.modules:
- module: drupal
  syslog:
    enabled: true
    var.paths:
      - /home/client/preprod.client.fr/log/drupal/*.log
    prospector:
      fields:
        project_customer: "client"
        project_name: "preprod.client.fr"
        origin: "drupal-syslog"
      tags:
        - "preprod.client.fr"
        - "website"

- module: drupal
  syslog:
    enabled: true
    var.paths:
      - /home/client/www.client.fr/log/drupal/*.log
    prospector:
      fields:
        project_customer: "client"
        project_name: "www.client.fr"
        origin: "drupal-syslog"
      tags:
        - "www.client.fr"
        - "website"

```

But when filebeat start (_version 5.6.0_), only the last entry is loaded

```auto
2017/11/07 15:52:29.453488 log.go:91: INFO Harvester started for file: /home/client/www.client.fr/log/drupal/drupal.log

```

I have made some tests

- disabling the second entry (`enabled: false`) : this made the two modules definitions disabled and we got an error

```auto
2017/11/07 15:48:53.973675 beat.go:346: CRIT Exiting: No modules or prospectors enabled and configuration reloading disabled. What files do you want me to watch?

```

- remove the second entry : the first definition is loaded

```auto
2017/11/07 15:50:48.751536 log.go:91: INFO Harvester started for file: /home/client/preprod.client.fr/log/drupal/drupal.log

```

My questions are

- Multiple definitions for the same module aren't possible ?
- Do I use the correct method to do such things ?

Thanks,  
Sébastien KURTZEMANN

---

<div class="post-metadata">

**Author:** ![Vitaly\_il](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitaly_il/32/130964_2.png) [@Vitaly\_il](https://discuss.elastic.co/u/Vitaly_il)\
**Post date:** [November 8, 2017, 10:24am UTC](https://discuss.elastic.co/t/multiple-definitions-for-the-same-module/106839/2 "2017-11-08T10:24:34Z")

</div>

> [@sebastien.k](#):
>
> filebeat.modules

I guess you should use "drupal\_prod" and "drupal\_preprod" as module names.

---

<div class="post-metadata">

**Author:** ![sebastien.k](https://avatars.discourse-cdn.com/v4/letter/s/e99b99/32.png) [@sebastien.k](https://discuss.elastic.co/u/sebastien.k)\
**Post date:** [November 8, 2017, 11:17am UTC](https://discuss.elastic.co/t/multiple-definitions-for-the-same-module/106839/3 "2017-11-08T11:17:36Z")

</div>

@Vitaly_il : but if I do that I need to duplicate the "drupal" module code, no ?

We want to have one drupal module and have multiples declarations for it

---

<div class="post-metadata">

**Author:** ![Vitaly\_il](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitaly_il/32/130964_2.png) [@Vitaly\_il](https://discuss.elastic.co/u/Vitaly_il)\
**Post date:** [November 9, 2017, 7:06am UTC](https://discuss.elastic.co/t/multiple-definitions-for-the-same-module/106839/4 "2017-11-09T07:06:12Z")

</div>

Well, I may be wrong...  
Let's wait for Elastic team answer 🙂

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [November 9, 2017, 4:57pm UTC](https://discuss.elastic.co/t/multiple-definitions-for-the-same-module/106839/5 "2017-11-09T16:57:00Z")

</div>

Hi!

When your configuration is normalized the first `drupal` module gets overwritten by the second one.

AFAIK right now it is not supported to have multiple definitions for the same module by Filebeat.  
But I think @tudor can add more on this topic.

---

<div class="post-metadata">

**Author:** ![sebastien.k](https://avatars.discourse-cdn.com/v4/letter/s/e99b99/32.png) [@sebastien.k](https://discuss.elastic.co/u/sebastien.k)\
**Post date:** [November 10, 2017, 8:56am UTC](https://discuss.elastic.co/t/multiple-definitions-for-the-same-module/106839/6 "2017-11-10T08:56:16Z")

</div>

Thanks for this explanation @kvch !

I'll wait for more informations from @tudor 😉

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2017, 8:56am UTC](https://discuss.elastic.co/t/multiple-definitions-for-the-same-module/106839/7 "2017-12-08T08:56:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
