# Several filebeat installations on a Kibana / Elasticsearch server in one log file

**URL:** <https://discuss.elastic.co/t/several-filebeat-installations-on-a-kibana-elasticsearch-server-in-one-log-file/318754>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 11, 2022, 4:21pm UTC](https://discuss.elastic.co/t/several-filebeat-installations-on-a-kibana-elasticsearch-server-in-one-log-file/318754 "2022-11-11T16:21:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sharbich](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@sharbich](https://discuss.elastic.co/u/sharbich)\
**Post date:** [November 11, 2022, 4:21pm UTC](https://discuss.elastic.co/t/several-filebeat-installations-on-a-kibana-elasticsearch-server-in-one-log-file/318754/1 "2022-11-11T16:21:21Z")

</div>

Hello,

I have filebeat installed on a host and all syslog data is sent to Elasticsearch / Kibana. Visible via (Discover / Dashboard).  
Now I would like to install filebeat on another host and also transfer the syslog data to the same server as above.  
That means I want both syslog files to be visible in one (Discover / Dashboard).  
Separated by the computer name.  
Unfortunately, this is not possible with the same filebeat.yml.

Here is my filebeat.yml file:

> logging.level: info  
> logging.to\_files: true  
> logging.files:  
> path: /var/log/filebeat  
> name: dsme01  
> keepfiles: 7  
> permissions: 0640

All filebeat.yml are identical except this entry is changed in each:

> name: dsme01

What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![sharbich](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@sharbich](https://discuss.elastic.co/u/sharbich)\
**Post date:** [November 11, 2022, 5:56pm UTC](https://discuss.elastic.co/t/several-filebeat-installations-on-a-kibana-elasticsearch-server-in-one-log-file/318754/2 "2022-11-11T17:56:31Z")

</div>

The filebeat.yml is identical on all Linux hosts.

```auto
root@dsme01:~# cat /etc/filebeat/filebeat.yml 
###################### Filebeat Configuration Example #########################
filebeat.inputs:
- type: filestream
  id: my-filestream-id
  enabled: false
  paths:
    - /var/log/*.log
# ============================== Filebeat modules ==============================
filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: true
# ======================= Elasticsearch template setting =======================
setup.template.settings:
  index.number_of_shards: 1
  index.number_of_replicas: 1
# ================================== General ===================================
# ================================= Dashboards =================================
# =================================== Kibana ===================================
setup.kibana:
  host: "https://kibana.intern.example.com:5601"
  ssl.enabled: true
  ssl.verification_node: "none"
# =============================== Elastic Cloud ================================
# ================================== Outputs ===================================
# ---------------------------- Elasticsearch Output ----------------------------
output.elasticsearch:
  hosts: ["node1.elasticsearch.intern.example.com:9200"]
  protocol: "https"
  ssl.certificate_authourities: ["/etc/ssl/certs/HarbichCA.cacert.pem"]
  username: "elastic"
  password: "#######"
# ------------------------------ Logstash Output -------------------------------
# ================================= Processors =================================
processors:
  - add_host_metadata:
      when.not.contains.tags: forwarded
  - add_cloud_metadata: ~
# ================================== Logging ===================================
logging.level: info
logging.to_files: true
logging.files:
  path: /var/log/filebeat
  name: dsme01
  keepfiles: 7
  permissions: 0640
# ============================= X-Pack Monitoring ==============================
# ============================== Instrumentation ===============================
# ================================= Migration ==================================

```

Except for the following entry:

> name: dsme01

Each host has a different name in it

Why can't I see all hosts in Kibana under "Discover" & "filebeat\_\*" & "Kibana"?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 13, 2022, 11:43pm UTC](https://discuss.elastic.co/t/several-filebeat-installations-on-a-kibana-elasticsearch-server-in-one-log-file/318754/3 "2022-11-13T23:43:10Z")

</div>

What do the Filebeat logs on one of the other hosts show?

---

<div class="post-metadata">

**Author:** ![sharbich](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@sharbich](https://discuss.elastic.co/u/sharbich)\
**Post date:** [November 14, 2022, 8:32pm UTC](https://discuss.elastic.co/t/several-filebeat-installations-on-a-kibana-elasticsearch-server-in-one-log-file/318754/4 "2022-11-14T20:32:01Z")

</div>

> [@warkolm](#):
>
> What do the Filebeat logs on one of the other hosts show?

I got syslog working via filebeat and logstash after elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2022, 10:32pm UTC](https://discuss.elastic.co/t/several-filebeat-installations-on-a-kibana-elasticsearch-server-in-one-log-file/318754/5 "2022-12-12T22:32:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
