# Multiple filebeat instances sending logs

**URL:** <https://discuss.elastic.co/t/multiple-filebeat-instances-sending-logs/318651>\
**Category:** Logstash\
**Created:** [November 10, 2022, 12:06pm UTC](https://discuss.elastic.co/t/multiple-filebeat-instances-sending-logs/318651 "2022-11-10T12:06:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [November 10, 2022, 12:06pm UTC](https://discuss.elastic.co/t/multiple-filebeat-instances-sending-logs/318651/1 "2022-11-10T12:06:33Z")

</div>

Hi, I have installed filebeat on multiple servers to pick system logs.  
The filebeat for server a works fine.  
filebeat.yml

- type: log  
enabled: true  
paths:
  - /var/log/jenkins/jenkins.log  
exclude\_files: ['.gz$']  
multiline.pattern: '\[1\]+\s[0-9]{1,2},\s[0-9]{4}\s[0-9]{1,2}:[0-9]{1,2}:[0-9]{1,2}\s(?:AM|am|PM|pm)'  
multiline.negate: true  
multiline.match: after  
fields:  
type: jenkins-server  
fields\_under\_root: true

logstash/conf.d/pipeline.conf  
output  
{  
if [type] == "jenkins-server" {  
elasticsearch {  
hosts =\> ["{{ elk\_ip }}:9200"]

```
            user => "{{ elk_user }}"
            password => "{{ elk_password }}"

            action => "index"
            index => "jenkins_syslog%{+YYYY.MM.dd}"
     }
   }

```

}  
Sends log as expected. For the second server the filebeat input is somewhat like this

- type: log  
enabled: true  
paths:
  - /var/log/elasticsearch/\*.log  
fields:  
type: elasticsearch\_syslog  
fields\_under\_root: true

- type: log  
enabled: true  
paths:
  - /var/log/kibana/\*.log  
fields:  
type: kibana\_syslog  
fields\_under\_root: true

When i add the following code in pipeline.conf  
if [type] == "elasticsearch\_syslog" {  
elasticsearch {  
hosts =\> ["43.204.205.20:9200"]

```
            user => "elastic"
            password => "minutus"

            action => "index"
            index => "elasticsearch_syslog%{+YYYY.MM.dd}"
     }
   }
   if [type] == "kibana_syslog" {
      elasticsearch {
            hosts => ["43.204.205.20:9200"]

            user => "elastic"
            password => "minutus"

            action => "index"
            index => "kibana_syslog%{+YYYY.MM.dd}"
     }
   }

```

The indexes aren't getting created.  
Is this the correct way to do it? or should i use a separate pipeline for every filebeat input, if yes how? do i need to add if else?

* * *

1. a-zA-Z

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2022, 12:07pm UTC](https://discuss.elastic.co/t/multiple-filebeat-instances-sending-logs/318651/2 "2022-12-08T12:07:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
