# Problem to define multiples propsector with filebeat

**URL:** <https://discuss.elastic.co/t/problem-to-define-multiples-propsector-with-filebeat/36918>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 10, 2015, 8:46pm UTC](https://discuss.elastic.co/t/problem-to-define-multiples-propsector-with-filebeat/36918 "2015-12-10T20:46:59Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![aaroy428](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@aaroy428](https://discuss.elastic.co/u/aaroy428)\
**Post date:** [December 10, 2015, 8:46pm UTC](https://discuss.elastic.co/t/problem-to-define-multiples-propsector-with-filebeat/36918/1 "2015-12-10T20:46:59Z")

</div>

Hi everybody,  
I am new to filebeat. I do have some issues to properly format filebeat to use multiples prospector. My goal is to separate my file type with a separate prospector to add selector fields used after in my logstash instance to parse the row properly and then index in the proper index.

My prospector block look like the following:

```
filebeat:
prospectors:
     - 
       paths:
            - "/var/log/messages*"
       encoding: plain
       input_type: log
       document_type: log
       ignore_older: 240h
       fields:
            log_type: "messages"
            index_name: "my_index"
    -
   ...

```

I am presently getting an error if I put more than one prospector in the same filebeat configuration file. so currently, I do start manually one filebeat instance per file type. What is the proper way to achieve what I want.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 11, 2015, 8:19am UTC](https://discuss.elastic.co/t/problem-to-define-multiples-propsector-with-filebeat/36918/2 "2015-12-11T08:19:08Z")

</div>

Since YAML is sensitive to leading whitespace, please format your configuration snippet as code so we can see exactly what you're using.

> I am presently getting an error if I put more than one prospector in the same filebeat configuration file.

What did you try and what error message did you get?

---

<div class="post-metadata">

**Author:** ![aaroy428](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@aaroy428](https://discuss.elastic.co/u/aaroy428)\
**Post date:** [December 11, 2015, 6:35pm UTC](https://discuss.elastic.co/t/problem-to-define-multiples-propsector-with-filebeat/36918/3 "2015-12-11T18:35:09Z")

</div>

When you mentioned that the space are important with the yaml configuration file, I did watch closely how your file was built. Correct me if I am wrong: The paths argument has to be the next line and the next column, no extra space. path,encoding, input\_type, document\_type, ignore\_older and fields all aligned starting at the same column. After, I did those changes, I can't clone my error and it seems you fix my problem.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 12, 2015, 2:50pm UTC](https://discuss.elastic.co/t/problem-to-define-multiples-propsector-with-filebeat/36918/4 "2015-12-12T14:50:27Z")

</div>

There doesn't have to be a linebreak before the hyphen and "path", i.e. this is fine too:

```auto
filebeat:
  prospectors:
    - paths:
        - "/var/log/messages*"
      encoding: plain
      input_type: log
      document_type: log
      ignore_older: 240h
      fields:
        log_type: "messages"
        index_name: "my_index"

```

---

<div class="post-metadata">

**Author:** ![jovanmal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jovanmal/32/17330_2.png) [@jovanmal](https://discuss.elastic.co/u/jovanmal)\
**Post date:** [April 12, 2017, 1:30pm UTC](https://discuss.elastic.co/t/problem-to-define-multiples-propsector-with-filebeat/36918/5 "2017-04-12T13:30:40Z")

</div>

I faced with same problem, with the 5.3 version of Filebeat. ELK stack is installed on CentOS 7.3 x64 server.

This is part of my filebeat.yml file:

```
filebeat.prospectors:
- input_type: log
  paths:
    - /var/log/httpd/access_log
document_type: accesslog1

- input_type: log
  paths:
    - /var/log/httpd/error_log
document_type: errorlog

```

When I try to start filebeat service, service is failing to start and getting this error:

root@filebeatcli1(~)$systemctl start filebeat.service  
[15:19] root@filebeatcli1(~)$systemctl status filebeat.service  
● filebeat.service - filebeat  
Loaded: loaded (/usr/lib/systemd/system/filebeat.service; enabled; vendor preset: disabled)  
Active: failed (Result: start-limit) since Wed 2017-04-12 15:19:55 CEST; 3s ago  
Docs: [https://www.elastic.co/guide/en/beats/filebeat/current/index.html](https://www.elastic.co/guide/en/beats/filebeat/current/index.html)  
Process: 2774 ExecStart=/usr/share/filebeat/bin/filebeat -c /etc/filebeat/filebeat.yml -path.home /usr/share/filebeat -path.config /etc/filebeat -path.data /var/lib/filebeat -path.logs /var/log/filebeat (code=exited, status=1/FAILURE)  
Main PID: 2774 (code=exited, status=1/FAILURE)

Apr 12 15:19:55 filebeatcli1.bsmain.local systemd[1]: filebeat.service: main process exite...E  
Apr 12 15:19:55 filebeatcli1.bsmain.local systemd[1]: Unit filebeat.service entered failed....  
Apr 12 15:19:55 filebeatcli1.bsmain.local systemd[1]: filebeat.service failed.  
Apr 12 15:19:55 filebeatcli1.bsmain.local systemd[1]: filebeat.service holdoff time over, ....  
Apr 12 15:19:55 filebeatcli1.bsmain.local systemd[1]: start request repeated too quickly f...e  
Apr 12 15:19:55 filebeatcli1.bsmain.local systemd[1]: Failed to start filebeat.  
Apr 12 15:19:55 filebeatcli1.bsmain.local systemd[1]: Unit filebeat.service entered failed....  
Apr 12 15:19:55 filebeatcli1.bsmain.local systemd[1]: filebeat.service failed.  
Hint: Some lines were ellipsized, use -l to show in full.

If I comment any of prospectors, service is starting correctly. They cannot work together Example:

```
filebeat.prospectors:
- input_type: log
  paths:
    - /var/log/httpd/access_log
document_type: accesslog1

#- input_type: log
# paths:
# - /var/log/httpd/error_log
#document_type: errorlog

```

Please help me if somebody knows, what I have done wrong

Thank you in advance

---

<div class="post-metadata">

**Author:** ![jovanmal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jovanmal/32/17330_2.png) [@jovanmal](https://discuss.elastic.co/u/jovanmal)\
**Post date:** [April 13, 2017, 8:53am UTC](https://discuss.elastic.co/t/problem-to-define-multiples-propsector-with-filebeat/36918/6 "2017-04-13T08:53:31Z")

</div>

I got it working.

> [@magnusbaeck](#):
>
> Since YAML is sensitive to leading whitespace, please format your configuration snippet as code so we can see exactly what you're using.

You were right, there likely was a problem with yaml syntax. Probably I had some spaces that I could not see, or something similar

I've done following:  
Renamed my filebeat.yml to filebeat.yml.old. File filebeat.full.yml renamed to filebeat.yml. In a new config file, in Filebeat prospectors carefuly entered following configuration:

```
filebeat.prospectors:
- input_type: log
  paths:
    - /var/log/httpd/access_log
  document_type: accesslog

- input_type: log
  paths:
    - /var/log/httpd/error_log
  document_type: errorlog

```

This configuration worked, I am now able to filter documents in Logstash using document type, for different log formats.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [April 18, 2017, 2:20pm UTC](https://discuss.elastic.co/t/problem-to-define-multiples-propsector-with-filebeat/36918/7 "2017-04-18T14:20:25Z")

</div>

There is a problem in 5.3 when there is an invalid prospector, it can happen that filebeat panics instead of shutting down properly. Here is the potential fix for it: [https://github.com/elastic/beats/pull/4037](https://github.com/elastic/beats/pull/4037)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:49pm UTC](https://discuss.elastic.co/t/problem-to-define-multiples-propsector-with-filebeat/36918/8 "2017-07-05T21:49:39Z")

</div>


