---
title: Charmhub | Deploy Filebeat using Charmhub - The Open Operator Collection
description: Deploy the latest version of Filebeat on any cloud.
url: https://charmhub.io/filebeat/configurations
---

# Filebeat

[Filebeat Charmers](https://charmhub.io/publisher/filebeat-charmers "View all packages from Filebeat Charmers")

* [Filebeat Charmers](https://charmhub.io/publisher/filebeat-charmers "View all packages from Filebeat Charmers")
* [Monitoring](https://charmhub.io/?filter=monitoring)

Platform:

22.04

20.04

18.04

16.04

14.04

stable 23.04-7-g8e8e984

```
juju deploy filebeat
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [clean\_inactive](https://charmhub.io/filebeat/configurations#clean_inactive)
* [exclude\_files](https://charmhub.io/filebeat/configurations#exclude_files)
* [exclude\_lines](https://charmhub.io/filebeat/configurations#exclude_lines)
* [extra\_inputs](https://charmhub.io/filebeat/configurations#extra_inputs)
* [extra\_packages](https://charmhub.io/filebeat/configurations#extra_packages)
* [fields](https://charmhub.io/filebeat/configurations#fields)
* [harvester\_buffer\_size](https://charmhub.io/filebeat/configurations#harvester_buffer_size)
* [ignore\_older](https://charmhub.io/filebeat/configurations#ignore_older)
* [install\_keys](https://charmhub.io/filebeat/configurations#install_keys)
* [install\_sources](https://charmhub.io/filebeat/configurations#install_sources)
* [kafka\_hosts](https://charmhub.io/filebeat/configurations#kafka_hosts)
* [kafka\_topic](https://charmhub.io/filebeat/configurations#kafka_topic)
* [kafka\_topics](https://charmhub.io/filebeat/configurations#kafka_topics)
* [kafka\_version](https://charmhub.io/filebeat/configurations#kafka_version)
* [kube\_logs](https://charmhub.io/filebeat/configurations#kube_logs)
* [log\_level](https://charmhub.io/filebeat/configurations#log_level)
* [logging\_to\_syslog](https://charmhub.io/filebeat/configurations#logging_to_syslog)
* [logpath](https://charmhub.io/filebeat/configurations#logpath)
* [logstash\_hosts](https://charmhub.io/filebeat/configurations#logstash_hosts)
* [logstash\_ssl\_cert](https://charmhub.io/filebeat/configurations#logstash_ssl_cert)
* [logstash\_ssl\_key](https://charmhub.io/filebeat/configurations#logstash_ssl_key)
* [max\_bytes](https://charmhub.io/filebeat/configurations#max_bytes)
* [package\_status](https://charmhub.io/filebeat/configurations#package_status)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* clean\_inactive | int

  When this option is enabled, Filebeat removes the state of a file after the specified period of inactivity has
  elapsed. Bear in mind that if clean\_inactive is enabled, it must be greater than ignore\_older + scan\_frequency to
  make sure that no states are removed while a file is still being harvested. The passed values should be integers,
  e.g., "90", "3600", "600". The values are assumed to be in seconds:
  https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-log.html#filebeat-input-log-clean-inactive"
* exclude\_files | string

  Default: ["/filebeat.\*", ".\*gz$"]

  A list of regular expressions to match the files that you want Filebeat to ignore:
  https://www.elastic.co/guide/en/beats/filebeat/6.7/filebeat-input-log.html#filebeat-input-log-exclude-files"
* exclude\_lines | string

  Default: []

  A list of regular expressions to match the lines that you want Filebeat to exclude:
  https://www.elastic.co/guide/en/beats/filebeat/6.7/filebeat-input-log.html#filebeat-input-log-exclude-lines"
* extra\_inputs | string

  A YAML list which will be injected to define additional prospectors/inputs.
* extra\_packages | string

  Space separated list of extra deb packages to install.
* fields | string

  Space seperated list of key:value that the prospector will assign as field to each beat
* harvester\_buffer\_size | int

  Default: 16384

  Defines the buffer size every harvester uses when fetching the file
* ignore\_older | int

  If this option is enabled, Filebeat ignores any files that were modified before the specified timespan.
  Configuring ignore\_older can be especially useful if you keep log files for a long time. The passed
  values should be integers, e.g., "90", "3600", "600". The values are assumed to be in seconds
  https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-log.html#filebeat-input-log-ignore-older"
* install\_keys | string

  Default: D88E42B4

  Elastic Beats apt repository key
* install\_sources | string

  Default: deb https://artifacts.elastic.co/packages/6.x/apt stable main

  Elastic Beats apt repository
* kafka\_hosts | string

  A comma separated list of kafka output hosts in addition to those from relations.
* kafka\_topic | string

  Default: %{[type]}

  Topic name. Format strings are allowed.
* kafka\_topics | string

  Expert setting topics filter.
* kafka\_version | string

  Expert setting kafka version.
* kube\_logs | boolean

  Whether or not to include the Kubernetes audit log as well as any K8s metadata
  when container logs are present on the system:
  https://www.elastic.co/guide/en/beats/filebeat/6.7/add-kubernetes-metadata.html

  Note: this option has no effect when related to a non Charmed Kubernetes charm.
* log\_level | string

  Default: info

  Beats log level. One of debug, info, warning, error, or critical:
  https://www.elastic.co/guide/en/beats/filebeat/5.6/configuration-logging.html#level
* logging\_to\_syslog | boolean

  Default: True

  Send beats logs to syslog:
  https://www.elastic.co/guide/en/beats/filebeat/5.6/configuration-logging.html#\_to\_syslog
* logpath | string

  Default: /var/log/\*.log /var/log/\*/\*.log

  Space separated log paths to monitor. Can contain wildcards.
* logstash\_hosts | string

  A comma separated list of logstash output hosts in addition to those from relations.
* logstash\_ssl\_cert | string

  Public SSL certificate data (base64 encoded) for connecting securely to logstash.
* logstash\_ssl\_key | string

  Private SSL key data (base64 encoded) for connecting security to logstash.
* max\_bytes | int

  Default: 10485760

  Maximum number of bytes a single log event can have. Default 10MB
* package\_status | string

  Default: install

  The status of service-affecting packages will be set to this value in the dpkg database. Valid values are "install" and "hold".
