# \[suggestion\] Filebeat prospector configuration template

**URL:** <https://discuss.elastic.co/t/suggestion-filebeat-prospector-configuration-template/62687>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 11, 2016, 7:53am UTC](https://discuss.elastic.co/t/suggestion-filebeat-prospector-configuration-template/62687 "2016-10-11T07:53:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![fld](https://avatars.discourse-cdn.com/v4/letter/f/65b543/32.png) [@fld](https://discuss.elastic.co/u/fld)\
**Post date:** [October 11, 2016, 7:53am UTC](https://discuss.elastic.co/t/suggestion-filebeat-prospector-configuration-template/62687/1 "2016-10-11T07:53:54Z")

</div>

We are heavily starting to use filebeat (to push to kafka) and we have a configuration with 100+ prospectors (100+ kafka topics)  
For each prospector we repeat some parameters like encoding, ignore\_older, scan\_frequency, ...

We think filebeat would benefit of either:

- a way to change the default value for all prospectors (for example the default value of max\_bytes is currently 10MB (10485760). If I want to set 20MB for all my prospectors, I have to copy past the parameter for each of them. This works for people having many prospectors of the same kind
- a way to define templates: when creating a propsector, we can import values from a template or another. This works for people having many prospectors of a few kinds
- a way to copy parameters from a previously defined prospector

For now, we use puppet to create our configuration file so we use a loop in our ERB file and this works fine. The only problem is that the deployed configuration file is quite long and can be reduced with one of the options above

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 12, 2016, 6:06am UTC](https://discuss.elastic.co/t/suggestion-filebeat-prospector-configuration-template/62687/2 "2016-10-12T06:06:49Z")

</div>

Good timing. We had a very similar discussion just recently internally. One question from my side is: As you auto generate the config file anyways, is the size of the config file an issue?

Probably the best here is to open a feature request on [https://github.com/elastic/beats](https://github.com/elastic/beats) for further discussions.

---

<div class="post-metadata">

**Author:** ![fld](https://avatars.discourse-cdn.com/v4/letter/f/65b543/32.png) [@fld](https://discuss.elastic.co/u/fld)\
**Post date:** [October 17, 2016, 1:04pm UTC](https://discuss.elastic.co/t/suggestion-filebeat-prospector-configuration-template/62687/3 "2016-10-17T13:04:21Z")

</div>

No, the generated file size is not really an issue. At least not for filebeat. For OPs reading it to check its content, it can be.

And about opening a feature request on github, it is was I wanted to do first but ended up posting here because it says:

> Please post all questions and issues on [Beats - Discuss the Elastic Stack](https://discuss.elastic.co/c/beats)  
> before opening a Github Issue. Your questions will reach a wider audience there,  
> and if we confirm that there is a bug, then you can open a new issue.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 24, 2016, 6:35am UTC](https://discuss.elastic.co/t/suggestion-filebeat-prospector-configuration-template/62687/4 "2016-10-24T06:35:37Z")

</div>

@fld I really appreciate that you posted it here first and this is the recommended way. Like this we can check in advance if there is already something similar planned (or not). I this case I think it is definitively worth opening a Github issue.

---

<div class="post-metadata">

**Author:** ![fld](https://avatars.discourse-cdn.com/v4/letter/f/65b543/32.png) [@fld](https://discuss.elastic.co/u/fld)\
**Post date:** [October 26, 2016, 7:25am UTC](https://discuss.elastic.co/t/suggestion-filebeat-prospector-configuration-template/62687/5 "2016-10-26T07:25:53Z")

</div>

Thanks, I just did

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 1, 2016, 7:54am UTC](https://discuss.elastic.co/t/suggestion-filebeat-prospector-configuration-template/62687/6 "2016-11-01T07:54:08Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
