# How to send multiple log files to Kibana through logstash?

**URL:** <https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101>\
**Category:** Logstash\
**Created:** [May 16, 2016, 8:02am UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101 "2016-05-16T08:02:28Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![tashinfrus](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@tashinfrus](https://discuss.elastic.co/u/tashinfrus)\
**Post date:** [May 16, 2016, 8:02am UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/1 "2016-05-16T08:02:28Z")

</div>

I am new to ELK and I want to send multiple files to Kibana using Logstash like apache access logs of different servers. How can I do that?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 17, 2016, 6:57pm UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/2 "2016-05-17T18:57:37Z")

</div>

What part are you finding hard to understand? A single Logstash instance can have multiple inputs that listens on multiple ports or reads multiple files or whatever you use Logstash for. Nothing special needs to be done for reading multiple files. Without further details about your situation it's impossible to give more specific help.

---

<div class="post-metadata">

**Author:** ![tashinfrus](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@tashinfrus](https://discuss.elastic.co/u/tashinfrus)\
**Post date:** [May 18, 2016, 5:29am UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/3 "2016-05-18T05:29:24Z")

</div>

I am able to get the single input file readings into Kibana from Logstash. But as I add another file into the configuration file of Logstash, it didn't work and it shows only logs of only single file. Please find the below configuration file for the same.

input {  
file {  
type =\> "app01\_apache\_access\_log"  
path =\> "/apps\_data/logs/app01/apache2/access.log"  
start\_position =\> "end"  
}  
file {  
type =\> "app02\_apache\_access\_log"  
path =\> "/apps\_log/logs/app02/apache2/access.log"  
}  
}  
filter {  
if [type] == "app01\_apache\_access\_log" {  
grok{  
match =\> ["message", "(?\<session\_id\>[A-Z0-9]{32}-[a-z0-9]+.[a-z0-9]+)" ]  
remove\_tag =\> ["\_grokparsefailure"]  
named\_captures\_only =\> true  
}  
grok{  
match =\> ["message", "%{WORD:method} %{URIPATH:request}"]  
remove\_tag =\> ["\_grokparsefailure"]  
named\_captures\_only =\> true  
}

```
            grok{
                    match => ["message", "%{NUMBER:duration}"]
                    remove_tag => ["_grokparsefailure"]
                    named_captures_only => true
            }
    }
    if [type] == "app02_apache_access_log" {
            grok{
                    match => ["message", "(?<session_id>[A-Z0-9]{32}-[a-z0-9]+\.[a-z0-9]+)" ]
                    remove_tag => ["_grokparsefailure"]
                    named_captures_only => true
            }
            grok{
                    match => ["message", "%{WORD:method} %{URIPATH:request}"]
                    remove_tag => ["_grokparsefailure"]
                    named_captures_only => true
            }

            grok{
                    match => ["message", "%{NUMBER:duration}"]
                    remove_tag => ["_grokparsefailure"]
                    named_captures_only => true
            }

    }

```

}

output {  
elasticsearch {  
hosts =\> "[search-test-elk-qrxqhiyz6vqwck2xnyu3qhdjsu.us-east-1.es.amazonaws.com:443](http://search-test-elk-qrxqhiyz6vqwck2xnyu3qhdjsu.us-east-1.es.amazonaws.com:443)"  
ssl =\> true  
}  
stdout {  
codec =\> rubydebug  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 18, 2016, 5:33am UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/4 "2016-05-18T05:33:17Z")

</div>

> But as I add another file into the configuration file of Logstash, it didn't work and it shows only logs of only single file.

What does "show only logs of only single file" mean, _exactly_? And what makes you reach that conclusion? Since you've configured Logstash to tail both access.log files, is data actually being appended to both files?

I strongly suggest that you leave out the elasticsearch output for now and use the stdout output you have to debug things.

---

<div class="post-metadata">

**Author:** ![tashinfrus](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@tashinfrus](https://discuss.elastic.co/u/tashinfrus)\
**Post date:** [May 18, 2016, 5:51am UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/5 "2016-05-18T05:51:23Z")

</div>

Hi,  
I can see logs from "/apps\_data/logs/app01/apache2/access.log" file which is my first input file. I see no output from another file. Also, I am using the stdout output only for this.

Also, I would like to mention that I am using Elastic Search Service of AWS so using multiple ports for Elastic search is kind of not applicable to me.

Please help me tackle this situation.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 18, 2016, 6:17am UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/6 "2016-05-18T06:17:37Z")

</div>

Again, since you've configured Logstash to tail both access.log files, is data actually being appended to both files? As currently configured Logstash will _not_ read the files from the beginning.

---

<div class="post-metadata">

**Author:** ![tashinfrus](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@tashinfrus](https://discuss.elastic.co/u/tashinfrus)\
**Post date:** [May 18, 2016, 7:37am UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/7 "2016-05-18T07:37:28Z")

</div>

How to confirm whether the data is appended or not? I think it is not appended as I see only the first log file data into Kibana. The logstash server is an EC2 instance on AWS and we are using ElasticSearch service of AWS cloud.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 18, 2016, 8:31pm UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/8 "2016-05-18T20:31:25Z")

</div>

> How to confirm whether the data is appended or not?

I think you're missing the point. We're talking about the file that Logstash is _reading_ from. But as you've configured Logstash it's tailing the fail, i.e. it's reading data from the end of the file. Unless new data is added to the end of the file Logstash won't pick up anything. So, is some other application writing data to that file?

---

<div class="post-metadata">

**Author:** ![tashinfrus](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@tashinfrus](https://discuss.elastic.co/u/tashinfrus)\
**Post date:** [May 19, 2016, 10:50am UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/9 "2016-05-19T10:50:28Z")

</div>

No other application is writing the data to that file as it is a file of access logs of one server of my product which is being copied to the logfile I give as input to Kibana. Also, I added the stat\_position as "end" to reduce the reading of whole log file from the beginning and processing of the whole file. Would you please tell me how I can confirm the data appended or not? Please help me.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 19, 2016, 1:04pm UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/10 "2016-05-19T13:04:08Z")

</div>

I'm not sure what you expect from Logstash. You're deliberately tailing the file but you're also not adding any new lines, correct? So why would you expect Logstash to read anything from the file and pass on to ES?

---

<div class="post-metadata">

**Author:** ![tashinfrus](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@tashinfrus](https://discuss.elastic.co/u/tashinfrus)\
**Post date:** [May 19, 2016, 1:14pm UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/11 "2016-05-19T13:14:08Z")

</div>

I am adding new lines to the files using rsync for log files are being continuously copied from webservers to Logstash server. So, I thought that would make logstash configuration take up new changes only as we are tailing the file. But only one file is being read and not other. As per the convention, both the files should be concatenated to make a whole new file so that logstash reads it. But here I don't think that is happening.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 19, 2016, 1:18pm UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/12 "2016-05-19T13:18:10Z")

</div>

When rsyncing files I'd assume that the existing file isn't updated in-place but that a new file is created and renamed into place. When that happens the original file gets a new inode number and Logstash will consider it new, and with `start_position => end` it'll start tailing it from the current end.

---

<div class="post-metadata">

**Author:** ![tashinfrus](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@tashinfrus](https://discuss.elastic.co/u/tashinfrus)\
**Post date:** [May 20, 2016, 5:51am UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/13 "2016-05-20T05:51:34Z")

</div>

Nope. The same file with the same inode number is updated in rsync. So I see the inode number is same as the first file. So, only the new logs which are there in the original log file are updated to the file on Logstash server. The question is, why is the second file not being picked up for processing by Logstash server which is access\_log from another apache server?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 20, 2016, 5:55am UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/14 "2016-05-20T05:55:02Z")

</div>

Start Logstash with `--verbose` so that the file input logs more details about what it's doing.

---

<div class="post-metadata">

**Author:** ![tashinfrus](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@tashinfrus](https://discuss.elastic.co/u/tashinfrus)\
**Post date:** [May 20, 2016, 7:28am UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/15 "2016-05-20T07:28:50Z")

</div>

starting the logstash in verbose mode showed nothing different usual stuff

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 20, 2016, 7:34am UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/16 "2016-05-20T07:34:29Z")

</div>

Sure, but it will tell you which files were discovered and which sincedb positions they were at. That information should help here.

---

<div class="post-metadata">

**Author:** ![tashinfrus](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@tashinfrus](https://discuss.elastic.co/u/tashinfrus)\
**Post date:** [May 23, 2016, 6:12am UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/17 "2016-05-23T06:12:42Z")

</div>

I couldn't see any such thing on the terminal. Instead, I saw the following thing,  
starting agent {:level=\>:info}  
starting pipeline {:id=\>"main", :level=\>:info}  
Settings: Default pipeline workers: 1  
Starting pipeline {:id=\>"main", :pipeline\_workers=\>1, :batch\_size=\>125, :batch\_delay=\>5, :max\_inflight=\>125, :level=\>:info}  
Pipeline main started..  
What can i get from these?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 23, 2016, 6:18am UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/18 "2016-05-23T06:18:57Z")

</div>

If you start Logstash with `--verbose` and have a file input in your configuration you should get a lot more than that. What if you start with `--debug`? You should get an avalanche of logs.

---

<div class="post-metadata">

**Author:** ![tashinfrus](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@tashinfrus](https://discuss.elastic.co/u/tashinfrus)\
**Post date:** [May 23, 2016, 6:33am UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/19 "2016-05-23T06:33:53Z")

</div>

I got the same reply for --debug mode.  
I noticed that level:info there..  
How can I change it to debug?? I tried from terminal but no luck.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:56am UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101/20 "2017-07-06T04:56:42Z")

</div>


