# Different files are entered into logstash . kibana fields show the same

**URL:** <https://discuss.elastic.co/t/different-files-are-entered-into-logstash-kibana-fields-show-the-same/161243>\
**Category:** Logstash\
**Created:** [December 18, 2018, 5:54am UTC](https://discuss.elastic.co/t/different-files-are-entered-into-logstash-kibana-fields-show-the-same/161243 "2018-12-18T05:54:55Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 18, 2018, 9:13am UTC](https://discuss.elastic.co/t/different-files-are-entered-into-logstash-kibana-fields-show-the-same/161243/4 "2018-12-18T09:13:33Z")

</div>

Did you not find anything when you searched the forum?

> [@Logstash 6.4.x : reading multiple files in conf.d](https://discuss.elastic.co/t/logstash-6-4-x-reading-multiple-files-in-conf-d/149515/3):
>
> Hello Thanks you Christian for your interest. I create 2 separate index, my 2 conf files are: root@kvm:~# cat /etc/logstash/conf.d/auth.conf input { tcp { port =\> "5001" codec =\> json tags =\> ["syslogauth"] } } filter { grok { named\_captures\_only =\> false break\_on\_match =\> true match =\> { "message" =\> [" New session %{NUMBER} of user %{USERNAME:user}."," Accepted password for %{USERNAME:user} from %{IP:ip} port %{NUMBER} ssh2"," Failed passw…

> [@Logstash sends multiple copies of data](https://discuss.elastic.co/t/logstash-sends-multiple-copies-of-data/160267/2):
>
> All config files in the directory are concatenated into a single pipeline. This means that each event generated by an input plugin will go through all filters and be sent to all outputs (all 5 of them). You can get around this by creating a single config file with multiple inputs, use conditionals or use the relatively new multiple pipeline feature. This is a common misunderstanding so you should easily be able to find examples.

> [@Message Created Twice in Elasticsearch via Logstash](https://discuss.elastic.co/t/message-created-twice-in-elasticsearch-via-logstash/142020):
>
> When I ingest document via logstash, I found the documents are created twice. Setup: Filebeat -\> Logstash -\> Elasticsearch Result: Same messages are ingested into Elasticsearch with different \_id So I tried the following testings: Testing 1: Inget Document directly from Filebeat i.e. Filebeat -\> Elasticsearch Result: 1 document is created Finding: the issue should be related to logstash or elasticsearch After reading the article: [https://www.elastic.co/blog/logstash-lessons-handling-du…](https://www.elastic.co/blog/logstash-lessons-handling-duplicates)

---

_[View the full topic](https://discuss.elastic.co/t/different-files-are-entered-into-logstash-kibana-fields-show-the-same/161243)._
