# Logstash 2.1.1 - weird results with multiple conf files on WIndows

**URL:** <https://discuss.elastic.co/t/logstash-2-1-1-weird-results-with-multiple-conf-files-on-windows/42043>\
**Category:** Logstash\
**Created:** [February 17, 2016, 3:59pm UTC](https://discuss.elastic.co/t/logstash-2-1-1-weird-results-with-multiple-conf-files-on-windows/42043 "2016-02-17T15:59:33Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![kpdude77](https://avatars.discourse-cdn.com/v4/letter/k/96bed5/32.png) [@kpdude77](https://discuss.elastic.co/u/kpdude77)\
**Post date:** [February 17, 2016, 3:59pm UTC](https://discuss.elastic.co/t/logstash-2-1-1-weird-results-with-multiple-conf-files-on-windows/42043/1 "2016-02-17T15:59:33Z")

</div>

I am running logstash 2.1.1 on a local WIndows system with 2 conf files - one with a jdbc input that defines a custom index in the elasticsearch output, and one with a file input from a log that uses the default index (logstash-DATE). The jdbc input is reading from an Oracle table with 20 rows. I am seeing some really weird results when I run logstash against these 2 conf files simultaneously:

1. All 20 row/documents from the db are being written to stdout twice
2. When I do a \_search all against elasticsearch, all the db documents are showing up twice, once in the default index, and once in the index defined in my jdbc conf.

It's like the conf with the file input is ignoring the input section totally, and copying the created documents from the jdbc conf into the index defined in the file conf. Below are the confs:

file.conf

# The # character at the beginning of a line indicates a comment. Use

# comments to describe your configuration.

input {  
file {  
path =\> "c:\openstream\ICS._"  
exclude =\> ["_.gz", "_.txt", "_.pdf"]  
start\_position =\> beginning  
# codec =\> multiline {  
# pattern =\> "Exception:"  
# negate =\> true  
# what =\> "previous"  
# }  
}  
}

# The filter part of this file is commented out to indicate that it is

# optional.

filter {  
grok {  
match =\> { "message" =\> "%{EXCEPTION:exception}" }  
patterns\_dir =\> ["c:\logstash-2.1.1\patterns"]  
}  
}  
output {  
stdout {codec =\> json\_lines}  
elasticsearch {  
hosts =\> "localhost:9200"  
document\_type =\> "os\_log"  
}  
}

jdbc.conf

# The # character at the beginning of a line indicates a comment. Use

# comments to describe your configuration.

input {  
jdbc {  
jdbc\_connection\_string =\> "jdbc:oracle:thin:@[//10.116.1.46:1521/bmsrpt](https://10.116.1.46:1521/bmsrpt)"  
jdbc\_user =\> "bms\_owner"  
jdbc\_password =\> "bms"  
jdbc\_validate\_connection =\> true  
jdbc\_driver\_library =\> "ojdbc7.jar"  
jdbc\_driver\_class =\> "Java::oracle.jdbc.driver.OracleDriver"  
statement =\> "SELECT \* from SESSIONHISTORY"  
# schedule =\> "\*/5 \* \* \* \*"  
}  
}

# The filter part of this file is commented out to indicate that it is

# optional.

# filter {

# 

# }

output {  
stdout {codec =\> json\_lines}  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "shistory"  
document\_type =\> "session\_history"  
}  
}

---

<div class="post-metadata">

**Author:** ![kpdude77](https://avatars.discourse-cdn.com/v4/letter/k/96bed5/32.png) [@kpdude77](https://discuss.elastic.co/u/kpdude77)\
**Post date:** [February 17, 2016, 6:46pm UTC](https://discuss.elastic.co/t/logstash-2-1-1-weird-results-with-multiple-conf-files-on-windows/42043/2 "2016-02-17T18:46:39Z")

</div>

Update: when I changed the backslashes to forward slashes, I then saw documents being created from the file.conf. However, both sets of documents seem to be conflated among the two indicies; i.e. it appears every document is being created in each index, instead of just the log lines going to the default index and just the db lines going to the db index.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 18, 2016, 2:43am UTC](https://discuss.elastic.co/t/logstash-2-1-1-weird-results-with-multiple-conf-files-on-windows/42043/3 "2016-02-18T02:43:35Z")

</div>

When you start LS with multiple config files it merges them, so you get both stdout.  
You need to use conditionals to only have each input allocated to their respective outputs.

---

<div class="post-metadata">

**Author:** ![shaun1500](https://avatars.discourse-cdn.com/v4/letter/s/258eb7/32.png) [@shaun1500](https://discuss.elastic.co/u/shaun1500)\
**Post date:** [December 2, 2016, 11:33am UTC](https://discuss.elastic.co/t/logstash-2-1-1-weird-results-with-multiple-conf-files-on-windows/42043/4 "2016-12-02T11:33:11Z")

</div>

how do we use conditionals to only have each input allocated to their respective outputs?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 2, 2016, 12:08pm UTC](https://discuss.elastic.co/t/logstash-2-1-1-weird-results-with-multiple-conf-files-on-windows/42043/5 "2016-12-02T12:08:04Z")

</div>

Please start a new thread for your question.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:30am UTC](https://discuss.elastic.co/t/logstash-2-1-1-weird-results-with-multiple-conf-files-on-windows/42043/6 "2017-07-06T04:30:04Z")

</div>


