# Exiting: error unpacking config data: more than one namespace configured accessing 'output' (source:'filebeat.yml')

**URL:** <https://discuss.elastic.co/t/exiting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-filebeat-yml/240640>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 10, 2020, 4:27am UTC](https://discuss.elastic.co/t/exiting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-filebeat-yml/240640 "2020-07-10T04:27:39Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bhavin\_Varsur](https://avatars.discourse-cdn.com/v4/letter/b/ecccb3/32.png) [@Bhavin\_Varsur](https://discuss.elastic.co/u/Bhavin_Varsur)\
**Post date:** [July 10, 2020, 4:27am UTC](https://discuss.elastic.co/t/exiting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-filebeat-yml/240640/1 "2020-07-10T04:27:39Z")

</div>

when i enable elasticsearch output and logstash output in filebeat.yml i get this error.  
Exiting: error unpacking config data: more than one namespace configured accessing 'output' (source:'filebeat.yml')

please give me the solution of this problem !!

here are my filebeat.yml file:

filebeat.inputs:

- type: log  
enabled: true  
paths:
  - /var/log/\*.log
  - D:\Git\finance.api\FinanceAPI\logs\*.log  
#- c:\programdata\elasticsearch\logs\*

filebeat.config.modules:  
path: ${path.config}/modules.d/\*.yml  
reload.enabled: false

setup.template.settings:  
index.number\_of\_shards: 1

setup.kibana:

host: "localhost:5601"

output.elasticsearch:  
hosts: ["localhost:9200"]  
username: "elastic"  
password: "changeme"

output.logstash:  
hosts: ["localhost:5044"]

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [July 10, 2020, 10:08am UTC](https://discuss.elastic.co/t/exiting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-filebeat-yml/240640/2 "2020-07-10T10:08:01Z")

</div>

You cannot have 2 different output on the same filebeat.

Please consider using logstash as a forwarder or another filebeat.

---

<div class="post-metadata">

**Author:** ![Bhavin\_Varsur](https://avatars.discourse-cdn.com/v4/letter/b/ecccb3/32.png) [@Bhavin\_Varsur](https://discuss.elastic.co/u/Bhavin_Varsur)\
**Post date:** [July 15, 2020, 9:45am UTC](https://discuss.elastic.co/t/exiting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-filebeat-yml/240640/3 "2020-07-15T09:45:39Z")

</div>

Thank you for your reply !!  
now I have only one output is a logstash output.  
can you tell me how can I do logstash as forwarder or another instance of filebeat ?

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [July 15, 2020, 1:48pm UTC](https://discuss.elastic.co/t/exiting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-filebeat-yml/240640/4 "2020-07-15T13:48:02Z")

</div>

Hi, can you mark the topic as solved to improve research for the community ?

Can't you just use logstash as an output to elasticsearch ?  
Do you need to run 2 separates pipelines ?

---

<div class="post-metadata">

**Author:** ![Bhavin\_Varsur](https://avatars.discourse-cdn.com/v4/letter/b/ecccb3/32.png) [@Bhavin\_Varsur](https://discuss.elastic.co/u/Bhavin_Varsur)\
**Post date:** [July 16, 2020, 6:13am UTC](https://discuss.elastic.co/t/exiting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-filebeat-yml/240640/5 "2020-07-16T06:13:32Z")

</div>

yeah sure !!

tell me how can I run 2 separate pipeline how can do that , I'm new to this technology so I can't figure out that solution .

here are my first-pipeline.config file.

# Beats -\> Logstash -\> Elasticsearch pipeline.

input {  
beats {  
port =\> 5044  
}  
}  
filter{  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}"}  
}  
}  
output {  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
user =\> "test"  
password =\> "test123"  
}  
}

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [July 16, 2020, 9:28am UTC](https://discuss.elastic.co/t/exiting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-filebeat-yml/240640/6 "2020-07-16T09:28:13Z")

</div>

I dont understand why do you need filebeat to forward to both logstash and elasticsearch, while you already push logs to elasticsearch using logstash ?

I'm actually trying to understand if you need to send the same log 2 times in elastic ?

data --\> filebeat --\> logstash --\> elastic

---

<div class="post-metadata">

**Author:** ![Bhavin\_Varsur](https://avatars.discourse-cdn.com/v4/letter/b/ecccb3/32.png) [@Bhavin\_Varsur](https://discuss.elastic.co/u/Bhavin_Varsur)\
**Post date:** [July 16, 2020, 11:40am UTC](https://discuss.elastic.co/t/exiting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-filebeat-yml/240640/7 "2020-07-16T11:40:45Z")

</div>

I've multiple .net core projects which have logs so i want to show those logs into kibana dashboard in elasticsearch.  
so that i use filebeat to send those logs to logstash.then logstash send those logs to elastic

log files =\> filebeat =\> logstash =\> elasticsearch  
this is what i want to do.

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [July 16, 2020, 2:04pm UTC](https://discuss.elastic.co/t/exiting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-filebeat-yml/240640/8 "2020-07-16T14:04:00Z")

</div>

Ok so you dont really need to have 2 separates pipelines, if you do need to separates projects you can always tag logs depending on their sources.

Tag example :

```auto
# Foo o365
- type: log
  enabled: true
  paths:
    - "/var/log/o365.log"
  encoding: utf-8
  tags: ["foo365"]

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2020, 4:04pm UTC](https://discuss.elastic.co/t/exiting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-filebeat-yml/240640/9 "2020-08-13T16:04:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
