# Multiple Filebeat Inputs Files

**URL:** <https://discuss.elastic.co/t/multiple-filebeat-inputs-files/149348>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 20, 2018, 7:46pm UTC](https://discuss.elastic.co/t/multiple-filebeat-inputs-files/149348 "2018-09-20T19:46:29Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Esity](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@Esity](https://discuss.elastic.co/u/Esity)\
**Post date:** [September 20, 2018, 7:46pm UTC](https://discuss.elastic.co/t/multiple-filebeat-inputs-files/149348/1 "2018-09-20T19:46:29Z")

</div>

I was wondering if it is possible to have a conf.d type folder for filebeat to create multiple input items. I know I can list them all in filebeat.yml but that isn't preferable. I also don't think it makes sense to use a module like syslog if they are application logs. If someone wants to correct me, feel free to

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [September 21, 2018, 12:13pm UTC](https://discuss.elastic.co/t/multiple-filebeat-inputs-files/149348/2 "2018-09-21T12:13:47Z")

</div>

I don't know if this works before 6.4.x, but in the latest versions you can put the following in filebeat.yml:

```auto
filebeat.config:
  inputs:
    enabled: true
    path: inputs.d/*.yml
    reload.enabled: true
    reload.period: 10s

```

And then have multiple files under `inputs.d` like this:

```auto
/etc
  |- filebeat
       |- inputs.d
           |- log_mailoney.yml
           |- log_snort.yml
           |- log_suricata_eve.yml

```

The contents of the files in `inputs.d` can be as simple as this:

```auto
# Suricata EVE JSON Logs
- type: log
  enabled: true
  paths:
    - /var/log/suricata/eve.json
  fields:
    event.type: suricata_eve
  fields_under_root: true

```

---

<div class="post-metadata">

**Author:** ![Esity](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@Esity](https://discuss.elastic.co/u/Esity)\
**Post date:** [September 22, 2018, 3:08pm UTC](https://discuss.elastic.co/t/multiple-filebeat-inputs-files/149348/3 "2018-09-22T15:08:41Z")

</div>

> [@rcowart](#):
>
> path: inputs.d/\*.yml

How did I miss this? Thanks, this solves my issue!

---

<div class="post-metadata">

**Author:** ![dedemorton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dedemorton/32/84409_2.png) [@dedemorton](https://discuss.elastic.co/u/dedemorton)\
**Post date:** [September 24, 2018, 7:30pm UTC](https://discuss.elastic.co/t/multiple-filebeat-inputs-files/149348/4 "2018-09-24T19:30:44Z")

</div>

Just wanted to add that loading external config files has been supported for quite awhile (see the [docs](https://www.elastic.co/guide/en/beats/filebeat/6.4/filebeat-configuration-reloading.html)), but it looks like we never updated the docs to show `path: inputs.d/*.yml` instead of `path: configs/*.yml`. I'll update the docs so the config example matches what people expect. Thanks!

---

<div class="post-metadata">

**Author:** ![Esity](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@Esity](https://discuss.elastic.co/u/Esity)\
**Post date:** [October 1, 2018, 3:20am UTC](https://discuss.elastic.co/t/multiple-filebeat-inputs-files/149348/5 "2018-10-01T03:20:10Z")

</div>

Thanks a bunch!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 29, 2018, 5:20am UTC](https://discuss.elastic.co/t/multiple-filebeat-inputs-files/149348/6 "2018-10-29T05:20:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
