# Different config files for different log sources

**URL:** <https://discuss.elastic.co/t/different-config-files-for-different-log-sources/242734>\
**Category:** Logstash\
**Created:** [July 27, 2020, 10:35am UTC](https://discuss.elastic.co/t/different-config-files-for-different-log-sources/242734 "2020-07-27T10:35:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bigranawab](https://avatars.discourse-cdn.com/v4/letter/b/53a042/32.png) [@Bigranawab](https://discuss.elastic.co/u/Bigranawab)\
**Post date:** [July 27, 2020, 10:35am UTC](https://discuss.elastic.co/t/different-config-files-for-different-log-sources/242734/1 "2020-07-27T10:35:10Z")

</div>

Hi,  
I am new to ELK, and I have tried to integrate some sources with ELk, I have integrated 'Microsoft DNS logs' and 'Fortigate' using Logstash config.  
My question here is that what is best practice for logstash configuration i.e to create tow separate config files for dns and fortigate and others or one config file for all sources and by using filter to differentiate.  
Need assistance.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 27, 2020, 10:36am UTC](https://discuss.elastic.co/t/different-config-files-for-different-log-sources/242734/2 "2020-07-27T10:36:47Z")

</div>

I think [https://www.elastic.co/guide/en/logstash/current/multiple-pipelines.html](https://www.elastic.co/guide/en/logstash/current/multiple-pipelines.html) would be the best option.

---

<div class="post-metadata">

**Author:** ![Bigranawab](https://avatars.discourse-cdn.com/v4/letter/b/53a042/32.png) [@Bigranawab](https://discuss.elastic.co/u/Bigranawab)\
**Post date:** [July 27, 2020, 11:09am UTC](https://discuss.elastic.co/t/different-config-files-for-different-log-sources/242734/3 "2020-07-27T11:09:13Z")

</div>

so according to this link, I should create multiple pipelines with different config files right?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 27, 2020, 9:32pm UTC](https://discuss.elastic.co/t/different-config-files-for-different-log-sources/242734/4 "2020-07-27T21:32:08Z")

</div>

Yep. You can create a single file, but then you need to manage a tonne of conditionals.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2020, 9:32pm UTC](https://discuss.elastic.co/t/different-config-files-for-different-log-sources/242734/5 "2020-08-24T21:32:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
