# Referenced config files FileBeat (Windows)

**URL:** <https://discuss.elastic.co/t/referenced-config-files-filebeat-windows/317310>\
**Category:** Logstash\
**Created:** [October 24, 2022, 11:20am UTC](https://discuss.elastic.co/t/referenced-config-files-filebeat-windows/317310 "2022-10-24T11:20:06Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Remco1985](https://avatars.discourse-cdn.com/v4/letter/r/bbe5ce/32.png) [@Remco1985](https://discuss.elastic.co/u/Remco1985)\
**Post date:** [October 24, 2022, 11:20am UTC](https://discuss.elastic.co/t/referenced-config-files-filebeat-windows/317310/1 "2022-10-24T11:20:06Z")

</div>

Hi,

Recently we have successfully installed Filebeat on our (test) Windows server. Right now I’m investigating to find out the best deployment strategy for Filebeat agents on all of our Windows Server systems.

We would like to use the same config file (filebeat.yml) for all systems, except for the filebeat.inputs parts. Because Filebeat is using YML my idea is to reference the log file paths to another config file, see example:

```auto
  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    include! C:\Sys\FileBeat\logref.yml

```

That way we can deploy the same filebeat.yml file on all systems, whenever there are specifics needs we only have to change the logref.yml on the local system.

However, when I configured it like this, no log data from the paths specified in logref.yml are appearing in Kibana/Elastic. The filebeat agent is starting succesfully on the other hand, so the config (syntax) seems fine.

I don't if this is possible at all, if not: Are there any other methods to use referenced config files?  
Thank you!

---

<div class="post-metadata">

**Author:** ![Remco1985](https://avatars.discourse-cdn.com/v4/letter/r/bbe5ce/32.png) [@Remco1985](https://discuss.elastic.co/u/Remco1985)\
**Post date:** [October 24, 2022, 11:23am UTC](https://discuss.elastic.co/t/referenced-config-files-filebeat-windows/317310/2 "2022-10-24T11:23:14Z")

</div>

Example of the logref.yml file:

```auto
# Log paths
    - D:\Loggingtest\logtest.txt

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 24, 2022, 4:49pm UTC](https://discuss.elastic.co/t/referenced-config-files-filebeat-windows/317310/3 "2022-10-24T16:49:38Z")

</div>

You should move this to the Beats forum, it has nothing to do with logstash.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 24, 2022, 5:13pm UTC](https://discuss.elastic.co/t/referenced-config-files-filebeat-windows/317310/4 "2022-10-24T17:13:05Z")

</div>

> [@Remco1985](#):
>
> I don't if this is possible at all, if not: Are there any other methods to use referenced config files?

It is possible, but it is a little different from what you are trying, you need to configure filebeat to [load external configuration files](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-configuration-reloading.html) as described in the documentation.

Basically you will have something like this in your `filebeat.yml`.

```auto
filebeat.config.inputs:
  enabled: true
  path: "C:/path/to/yml/configs/*.yml"

```

Then each file in the config dir needs to follow this example:

```auto
- type: filestream
  paths:
    - D:/path/to/file/file.txt

```

On a previous company I had a use case where I needed to collect logs from custom applications in Windows Servers, some applications where present in more than one server, others where present in just one server, to make things easier all the server have all the config files, if an application didn't exist in the server, filebeat will ignore it because the file to read won't exist.

---

<div class="post-metadata">

**Author:** ![Remco1985](https://avatars.discourse-cdn.com/v4/letter/r/bbe5ce/32.png) [@Remco1985](https://discuss.elastic.co/u/Remco1985)\
**Post date:** [October 26, 2022, 8:11am UTC](https://discuss.elastic.co/t/referenced-config-files-filebeat-windows/317310/5 "2022-10-26T08:11:26Z")

</div>

Thank you very much!

---

<div class="post-metadata">

**Author:** ![Remco1985](https://avatars.discourse-cdn.com/v4/letter/r/bbe5ce/32.png) [@Remco1985](https://discuss.elastic.co/u/Remco1985)\
**Post date:** [October 26, 2022, 11:14am UTC](https://discuss.elastic.co/t/referenced-config-files-filebeat-windows/317310/6 "2022-10-26T11:14:50Z")

</div>

I wonder if its also possible to define more than one path (referenced config file) in file.config.inputs?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 26, 2022, 1:15pm UTC](https://discuss.elastic.co/t/referenced-config-files-filebeat-windows/317310/7 "2022-10-26T13:15:20Z")

</div>

I don't think so, the documentation does not mention this, also the name of the setting is `path`, not `paths` like the settings where you can have an array of paths.

Why would you need to define multiple config paths if in the config path you already can have multiple inputs?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 23, 2022, 1:15pm UTC](https://discuss.elastic.co/t/referenced-config-files-filebeat-windows/317310/8 "2022-11-23T13:15:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
