# How can i start many logstash conf files as service?

**URL:** <https://discuss.elastic.co/t/how-can-i-start-many-logstash-conf-files-as-service/121834>\
**Category:** Logstash\
**Created:** [February 28, 2018, 10:58am UTC](https://discuss.elastic.co/t/how-can-i-start-many-logstash-conf-files-as-service/121834 "2018-02-28T10:58:20Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![linsie](https://avatars.discourse-cdn.com/v4/letter/l/da6949/32.png) [@linsie](https://discuss.elastic.co/u/linsie)\
**Post date:** [February 28, 2018, 10:58am UTC](https://discuss.elastic.co/t/how-can-i-start-many-logstash-conf-files-as-service/121834/1 "2018-02-28T10:58:20Z")

</div>

Logstash version: 5.0.1;

when I have many logstash conf files, how can I start these conf files as soon as quickly?  
not start these conf files like : /path/logstash/bin/logstash -f /path/xxxx.conf

Thx so much !!!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 28, 2018, 12:05pm UTC](https://discuss.elastic.co/t/how-can-i-start-many-logstash-conf-files-as-service/121834/2 "2018-02-28T12:05:01Z")

</div>

Put the files in a directory and pass `-f /path/to/directory` to Logstash.

Keep in mind that except if you use the multi-pipeline feature in Logstash 6 there is a single event pipeline. If you don't want events from config file 1 to "spill over" into config file 2 you need to use conditionals.

---

<div class="post-metadata">

**Author:** ![linsie](https://avatars.discourse-cdn.com/v4/letter/l/da6949/32.png) [@linsie](https://discuss.elastic.co/u/linsie)\
**Post date:** [March 2, 2018, 6:59am UTC](https://discuss.elastic.co/t/how-can-i-start-many-logstash-conf-files-as-service/121834/3 "2018-03-02T06:59:18Z")

</div>

Thx Magnus Bäck so much !

I have another question, how can I monitor all these different conf status? so i can know which conf works nomally or not ???

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 2, 2018, 7:03am UTC](https://discuss.elastic.co/t/how-can-i-start-many-logstash-conf-files-as-service/121834/4 "2018-03-02T07:03:36Z")

</div>

It depends. What does normal mean? How would you as a human determine whether things are working okay?

---

<div class="post-metadata">

**Author:** ![linsie](https://avatars.discourse-cdn.com/v4/letter/l/da6949/32.png) [@linsie](https://discuss.elastic.co/u/linsie)\
**Post date:** [March 2, 2018, 7:17am UTC](https://discuss.elastic.co/t/how-can-i-start-many-logstash-conf-files-as-service/121834/5 "2018-03-02T07:17:39Z")

</div>

I mean that all the input conf , filter conf and output conf files can work normally.

for example, i have windows data source input , filter and relevant output conf file, so how can i know these conf files work normally ? when i have so many different data sources , so in the directory have so many conf files.

I don't know you can understand me now!  
thanks !

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 2, 2018, 7:27am UTC](https://discuss.elastic.co/t/how-can-i-start-many-logstash-conf-files-as-service/121834/6 "2018-03-02T07:27:46Z")

</div>

Oh, okay. Have a look at a tool I wrote, [https://github.com/magnusbaeck/logstash-filter-verifier](https://github.com/magnusbaeck/logstash-filter-verifier). It allows you to write testcases that verify a Logstash configuration.

Apart from that you should of course inspect what the outputs receive to make sure it looks reasonable, but I find that the filters are the hard part. Once you get them right the rest is pretty easy and any problems are immediately visible.

---

<div class="post-metadata">

**Author:** ![linsie](https://avatars.discourse-cdn.com/v4/letter/l/da6949/32.png) [@linsie](https://discuss.elastic.co/u/linsie)\
**Post date:** [March 2, 2018, 7:35am UTC](https://discuss.elastic.co/t/how-can-i-start-many-logstash-conf-files-as-service/121834/7 "2018-03-02T07:35:10Z")

</div>

Got it ! Thank you so much !!!

---

<div class="post-metadata">

**Author:** ![linsie](https://avatars.discourse-cdn.com/v4/letter/l/da6949/32.png) [@linsie](https://discuss.elastic.co/u/linsie)\
**Post date:** [March 26, 2018, 3:21am UTC](https://discuss.elastic.co/t/how-can-i-start-many-logstash-conf-files-as-service/121834/8 "2018-03-26T03:21:30Z")

</div>

Dear magnusbaeck,

I put the logstash files including one input file , some different filter files and one output file in a directory and pass -f /path/to/directory to start them

So i want to know, when to add another filter conf file to the /path/to/directory to process the data source , how can I to restart them ? like : pass -f /path/to/directory to restart them ????

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 26, 2018, 6:11am UTC](https://discuss.elastic.co/t/how-can-i-start-many-logstash-conf-files-as-service/121834/9 "2018-03-26T06:11:57Z")

</div>

You mean you want to process the original files (read via the file input) again? You'll have to clear the sincedb file and make sure your file input includes `start_position => "beginning"`. See the file input documentation for more on sincedb.

---

<div class="post-metadata">

**Author:** ![linsie](https://avatars.discourse-cdn.com/v4/letter/l/da6949/32.png) [@linsie](https://discuss.elastic.co/u/linsie)\
**Post date:** [March 26, 2018, 6:23am UTC](https://discuss.elastic.co/t/how-can-i-start-many-logstash-conf-files-as-service/121834/10 "2018-03-26T06:23:48Z")

</div>

the input file like this :  
input {  
tcp {  
port =\> 514  
}  
}

because i have a few different types of data to send the same tcp port , so i need to use different filter conf to process , after i add the new filter conf file to the /path/to/directory , how can i load this filter to logstash? only to restart it ? can it influence the old data type ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 26, 2018, 6:43am UTC](https://discuss.elastic.co/t/how-can-i-start-many-logstash-conf-files-as-service/121834/11 "2018-03-26T06:43:18Z")

</div>

> only to restart it ?

Yes, unless you have automatic configuration reload enabled.

> can it influence the old data type ?

That depends on exactly what your configuration looks like.

---

<div class="post-metadata">

**Author:** ![linsie](https://avatars.discourse-cdn.com/v4/letter/l/da6949/32.png) [@linsie](https://discuss.elastic.co/u/linsie)\
**Post date:** [March 26, 2018, 7:15am UTC](https://discuss.elastic.co/t/how-can-i-start-many-logstash-conf-files-as-service/121834/12 "2018-03-26T07:15:22Z")

</div>

ok ， thank you !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 23, 2018, 7:15am UTC](https://discuss.elastic.co/t/how-can-i-start-many-logstash-conf-files-as-service/121834/13 "2018-04-23T07:15:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
