# Multiple prospector path

**URL:** <https://discuss.elastic.co/t/multiple-prospector-path/64271>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 28, 2016, 10:27am UTC](https://discuss.elastic.co/t/multiple-prospector-path/64271 "2016-10-28T10:27:50Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![txisme](https://avatars.discourse-cdn.com/v4/letter/t/dbc845/32.png) [@txisme](https://discuss.elastic.co/u/txisme)\
**Post date:** [October 28, 2016, 10:27am UTC](https://discuss.elastic.co/t/multiple-prospector-path/64271/1 "2016-10-28T10:27:51Z")

</div>

Hey,

i want to use 2 prospectors, filebeal.yml is working perfect with just one;

 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/17cb53275ccb4c20c742bb9f61d64375408234c9.png)

However, if i uncomment the 2nd prospector, the filebeat fails to start:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/5/5317b0e70db3da25a3307103bf309f27f50499f3.png)

* * *

After some trial and error i figured out that if i change the path of the 2nd prospector to anything else that doesn't have the same first folder (coriant), filebeat starts normally. Why is this happening?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 28, 2016, 2:54pm UTC](https://discuss.elastic.co/t/multiple-prospector-path/64271/2 "2016-10-28T14:54:48Z")

</div>

Can you share your config file in text format instead of screen shots? This makes it easier to read.

- Did you have 2 prospectors with the same files to harvest?
- Which filebeat version are you using?
- Can you provide some log outputs from filebeat?

---

<div class="post-metadata">

**Author:** ![txisme](https://avatars.discourse-cdn.com/v4/letter/t/dbc845/32.png) [@txisme](https://discuss.elastic.co/u/txisme)\
**Post date:** [October 28, 2016, 3:14pm UTC](https://discuss.elastic.co/t/multiple-prospector-path/64271/3 "2016-10-28T15:14:19Z")

</div>

Hey, thank you for your help, here is what you requested:

```
  prospectors:
# Each - is a prospector. Below are the prospector specific configurations
-
  # Paths that should be crawled and fetched. Glob based paths.
  # To fetch all ".log" files from a specific level of subdirectories
  # /var/log/*/*.log can be used.
  # For each file found under this path, a harvester is started.
  # Make sure not file is defined twice as this can lead to unexpected behaviour.
  paths:
  - "/coriant/sdn/logs/tc/Heap_Logs/*"
  #- c:\programdata\elasticsearch\logs\*
  input_type: log
  fields:
    log_type: heap
-
paths:
- "/coriant/sdn/logs/tc/GC_Logs/*"
input_type: log
fields:
log_type: GC

```

- 2 prospectors to different files (One to Heap\_Logs, another to GC\_Logs)

- im using filebeat 1.3

- here is the logging from filebeat, i havent seen it before, but still i dont understand what it meants, the file path is working fine for the first prospector but not for the second even though they are very similar

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 31, 2016, 9:24am UTC](https://discuss.elastic.co/t/multiple-prospector-path/64271/4 "2016-10-31T09:24:15Z")

</div>

Yaml is quite picky about the indentation (only spaces, no tabs). The above config file you posted looks like there are quite a few issues with the indentation. Best is to take the original config file and add your own values.

---

<div class="post-metadata">

**Author:** ![txisme](https://avatars.discourse-cdn.com/v4/letter/t/dbc845/32.png) [@txisme](https://discuss.elastic.co/u/txisme)\
**Post date:** [November 2, 2016, 10:16am UTC](https://discuss.elastic.co/t/multiple-prospector-path/64271/5 "2016-11-02T10:16:34Z")

</div>

yeah i suspected it was that but i ve been doing this config file over and over. Maybe im doing always the same mistake. Will keep trying until YAML gets in better mood and accepts it. Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 18, 2016, 10:28am UTC](https://discuss.elastic.co/t/multiple-prospector-path/64271/6 "2016-11-18T10:28:05Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
