# How to integrate multiple config files in Logstash?

**URL:** <https://discuss.elastic.co/t/how-to-integrate-multiple-config-files-in-logstash/174763>\
**Category:** Logstash\
**Created:** [April 1, 2019, 11:04am UTC](https://discuss.elastic.co/t/how-to-integrate-multiple-config-files-in-logstash/174763 "2019-04-01T11:04:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vignesh.s2](https://avatars.discourse-cdn.com/v4/letter/v/bc8723/32.png) [@vignesh.s2](https://discuss.elastic.co/u/vignesh.s2)\
**Post date:** [April 1, 2019, 11:04am UTC](https://discuss.elastic.co/t/how-to-integrate-multiple-config-files-in-logstash/174763/1 "2019-04-01T11:04:24Z")

</div>

As there are 2 config files in Logstash, logs are not received and forwarded to Kibana. I need to know whether i can have more than one conf file for logstash and if so, How to integrate the conf files.

I have mentioned the conf files below for reference

1. /etc/logstash/logstash.conf

> input {  
> udp {  
> host =\> "10.100.10.30"  
> port =\> 10514  
> codec =\> "json"  
> type =\> "rsyslog"  
> }  
> }

> This is an empty filter block. You can later add other filters here to further process your log lines

> filter { }

> This output block will send all events of type "rsyslog" to Elasticsearch at the configured host and port into daily indices of the pattern, "rsyslog-YYYY.MM.DD"  
> output {  
> if [type] == "rsyslog" {  
> elasticsearch {  
> hosts =\> ["10.100.10.30:9200"]  
> }  
> }  
> }

1. /etc/logstash/wazuh.conf

> input {  
> beats {  
> host =\> "10.100.10.29"  
> port =\> 5000  
> codec =\> "json"  
> #\> ssl =\> true  
> #\> ssl\_certificate =\> "/etc/logstash/logstash.crt"  
> #\> ssl\_key =\> "/etc/logstash/logstash.key"  
> }  
> }  
> filter {  
> if [data][srcip] {  
> mutate {  
> add\_field =\> ["@src\_ip", "%{[data][srcip]}" ]  
> }  
> }  
> if [data][aws][sourceIPAddress] {  
> mutate {  
> add\_field =\> ["@src\_ip", "%{[data][aws][sourceIPAddress]}" ]  
> }  
> }  
> }  
> filter {  
> geoip {  
> source =\> "@src\_ip"  
> target =\> "GeoLocation"  
> fields =\> ["city\_name", "country\_name", "region\_name", "location"]  
> }  
> date {  
> match =\> ["timestamp", "ISO8601"]  
> target =\> "@timestamp"  
> }  
> mutate {  
> remove\_field =\> ["timestamp", "beat", "input\_type", "tags", "count", "@version", "log", "offset", "type", "@src\_ip", "host"]  
> }  
> }  
> output {  
> elasticsearch {  
> hosts =\> ["10.100.10.30:9200"]  
> index =\> "wazuh-alerts-3.x-%{+YYYY.MM.dd}"  
> document\_type =\> "wazuh"  
> }  
> }

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 1, 2019, 1:59pm UTC](https://discuss.elastic.co/t/how-to-integrate-multiple-config-files-in-logstash/174763/2 "2019-04-01T13:59:30Z")

</div>

> [@vignesh.s2](#):
>
> I need to know whether i can have more than one conf file for logstash and if so, How to integrate the conf files.

If you set -f or path.config to a directory, then logstash will read any files in that directory as part of the configuration. The files are not independent. Events will be read from all of the inputs, passed through all of the filters, and written to all of the outputs. If you want the files to be independent then use [pipelines](https://www.elastic.co/guide/en/logstash/current/multiple-pipelines.html).

---

<div class="post-metadata">

**Author:** ![vignesh.s2](https://avatars.discourse-cdn.com/v4/letter/v/bc8723/32.png) [@vignesh.s2](https://discuss.elastic.co/u/vignesh.s2)\
**Post date:** [April 8, 2019, 12:53pm UTC](https://discuss.elastic.co/t/how-to-integrate-multiple-config-files-in-logstash/174763/3 "2019-04-08T12:53:01Z")

</div>

Thanks for the reply, I would like to know how to integrate these two config files together by your solution, if you can show that too, it will be more helpful.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 6, 2019, 12:53pm UTC](https://discuss.elastic.co/t/how-to-integrate-multiple-config-files-in-logstash/174763/4 "2019-05-06T12:53:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
