# Simplification of filebeat.yml?

**URL:** <https://discuss.elastic.co/t/simplification-of-filebeat-yml/82946>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 19, 2017, 7:22pm UTC](https://discuss.elastic.co/t/simplification-of-filebeat-yml/82946 "2017-04-19T19:22:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![\_Ian](https://avatars.discourse-cdn.com/v4/letter/_/ccd318/32.png) [@\_Ian](https://discuss.elastic.co/u/_Ian)\
**Post date:** [April 19, 2017, 7:22pm UTC](https://discuss.elastic.co/t/simplification-of-filebeat-yml/82946/1 "2017-04-19T19:22:35Z")

</div>

What would be the best way to configure Filebeat to ship multiple rolling log types while simplifying the configuration?

I have ~30 of these files to monitor and was hoping to use reference variables to streamline the configuration. Most of the file-specific settings will be the same while certain file-specific attributes will be unique to each file, if that makes any sense. Any input would be appreciated.

```
- input_type: log
  paths:
- /path/a.log
  fields:
    document_type: log
    type: log-a
  enabled: true
  ignore_older: 7h
  document_type: log
  scan_frequency: 1s
  clean_inactive: 8h
  close_timeout: 7h
  close_inactive: 7h
  close_renamed: true

- input_type: log
  paths:
- /path/b.log
  fields:
    document_type: log
    type: log-b
  enabled: true
  ignore_older: 7h
  document_type: log
  scan_frequency: 1s
  clean_inactive: 8h
  close_timeout: 7h
  close_inactive: 7h
  close_renamed: true
```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 20, 2017, 10:34am UTC](https://discuss.elastic.co/t/simplification-of-filebeat-yml/82946/2 "2017-04-20T10:34:55Z")

</div>

filebeat doesn't support global defaults, but it support referencing other settings via `${full-name}`.

If you have common settings and might want to change them all at once you can do this:

```auto
filebeat.prospectors:
- input_type: log # < I think this is the default and can be removed
  paths: ...
  fields:
    document_type: log
    type: log-b
  enabled: true # < always true by default, not required. You can use variables to have a class of prospectors to be enabled/disabled at once like:
  # enabled: ${defaults.class.logs}
  ignore_older: ${defaults.ignore_older}
  scan_frequency: ${defaults.scan_frequency}
  ...

defaults:
  ignore_older: 7h
  scan_frequency: 1s
  class:
    logs: true
    other: false

```

Using the `class` idea, you can have defaults by class like:

```auto
defaults:
  ignore_older: 7h
  scan_frequency: 1s
  class:
    logs.ignore_older: ${defaults.ignore_older}
    logs.scan_frequency: ${defaults.scan_frequency}
    app.ignore_older: 24h
    app.scan_frequency: ${defaults.scan_frequency}  

```

See [docs](https://www.elastic.co/guide/en/beats/libbeat/current/config-file-format.html) for filebeat config files features. E.g. you can use environment variables and defaults or start filebeat with `-E <varname>=<value>` to overwrite variables in the `defaults` namespace.

With this much repetition, you might also consider a script writing a configuration file before starting filebeat using templates.

---

<div class="post-metadata">

**Author:** ![\_Ian](https://avatars.discourse-cdn.com/v4/letter/_/ccd318/32.png) [@\_Ian](https://discuss.elastic.co/u/_Ian)\
**Post date:** [April 20, 2017, 1:43pm UTC](https://discuss.elastic.co/t/simplification-of-filebeat-yml/82946/3 "2017-04-20T13:43:23Z")

</div>

I just wrote a quick script to generate out the config. Unfortunate there's no simple way to do a more global override/default for templating of sub-values. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2017, 1:50pm UTC](https://discuss.elastic.co/t/simplification-of-filebeat-yml/82946/4 "2017-05-18T13:50:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
