# Multiple input configuration

**URL:** <https://discuss.elastic.co/t/multiple-input-configuration/143299>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 7, 2018, 9:54am UTC](https://discuss.elastic.co/t/multiple-input-configuration/143299 "2018-08-07T09:54:25Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 7, 2018, 9:54am UTC](https://discuss.elastic.co/t/multiple-input-configuration/143299/1 "2018-08-07T09:54:25Z")

</div>

I want to read multiple log files and send it to logstash. Below is my configuration (I just wanted to test it locally so the configuration I used is given below):

```
filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: false

setup.template.settings:
  index.number_of_shards: 0

filebeat.prospectors:

- input_type: log
  enabled: true
  paths:
    - C:\data\log\eis.log
  fields: {log_type: eis}

- input_type: log
  enabled: true
  paths:
    - C:\data\log\sa.log
  fields: {log_type: sa}
 
output.file:
   path: "c:/var/"
   filename: "filebeat.log"

```

I see that only one of the file is getting written. How can I configure to write the other file as well ? I have updated my whole configuration file for your reference.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 7, 2018, 10:10am UTC](https://discuss.elastic.co/t/multiple-input-configuration/143299/2 "2018-08-07T10:10:14Z")

</div>

Hi @Raghuveer_SJ,

Be careful with Windows paths in filebeat configuration, backslash (`\`) is used to escape characters in yaml, so you need to escape these backslashes (`C:\\data\\log\\eis.log`), or quote the paths with single quotes (`'C:\data\log\eis.log'`).

---

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 7, 2018, 10:17am UTC](https://discuss.elastic.co/t/multiple-input-configuration/143299/3 "2018-08-07T10:17:47Z")

</div>

With that change no files are getting generated 🙂 and filebeat exited with the error :

```
2018-08-07T15:44:38.817+0530 ERROR instance/beat.go:691 Exiting: Error in initing input: No paths were defined for input accessing 'filebeat.prospectors.2' (source:'filebeat.yml')
Exiting: Error in initing input: No paths were defined for input accessing 'filebeat.prospectors.2' (source:'filebeat.yml')

```

Can you please look into my whole configuration file that I have posted. Just to mention I am using 6.3 ELK stack. I see `filebeat.inputs` is mentioned not the prospectors so are they deprecated ? Anyway I see the double slash is not something that works in 6.3 version. We should use the normal path. So I still see only my first file is getting written not the second file. Kindly help.

---

<div class="post-metadata">

**Author:** ![Manikandan622](https://avatars.discourse-cdn.com/v4/letter/m/82dd89/32.png) [@Manikandan622](https://discuss.elastic.co/u/Manikandan622)\
**Post date:** [August 7, 2018, 12:16pm UTC](https://discuss.elastic.co/t/multiple-input-configuration/143299/4 "2018-08-07T12:16:18Z")

</div>

Works for me in Windows with following changes in filebeat.yml  
paths:  
- D:\ELK\log\_FileBeat\*.log  
- D:\ELK\AnotherLogPath\*.log

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 7, 2018, 12:29pm UTC](https://discuss.elastic.co/t/multiple-input-configuration/143299/5 "2018-08-07T12:29:36Z")

</div>

`filebeat.prospectors` is deprecated in favour of `filebeat.inputs` yes, but both options should work by now.

What do you mean by seeing only the first file written? Files in input paths are only read.

---

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 7, 2018, 12:31pm UTC](https://discuss.elastic.co/t/multiple-input-configuration/143299/6 "2018-08-07T12:31:21Z")

</div>

But I also want to categorize them with `fields` so that I can make a switch in logstash grok filter can you suggest how I can do it?

---

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 7, 2018, 12:56pm UTC](https://discuss.elastic.co/t/multiple-input-configuration/143299/7 "2018-08-07T12:56:47Z")

</div>

I see only the eis.log file the other file is not there in ELK. Filebeat is harvesting only 1 file not sure why its ignoring the other file i.e. sa.log.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 7, 2018, 1:14pm UTC](https://discuss.elastic.co/t/multiple-input-configuration/143299/8 "2018-08-07T13:14:54Z")

</div>

For adding fields, the `fields` setting you are already using should be enough.

Does the `sa.log` file exist in this path? Could you check the logs in case you see something related to this file?

---

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 7, 2018, 1:16pm UTC](https://discuss.elastic.co/t/multiple-input-configuration/143299/9 "2018-08-07T13:16:34Z")

</div>

The file sa.log was saved as sa.txt.log I spent a whole half a day just to figure out this ...

thanks a lot

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2018, 1:16pm UTC](https://discuss.elastic.co/t/multiple-input-configuration/143299/10 "2018-09-04T13:16:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
