# Logstash 5.3.2 multiple conf files

**URL:** <https://discuss.elastic.co/t/logstash-5-3-2-multiple-conf-files/106021>\
**Category:** Logstash\
**Created:** [November 1, 2017, 11:00am UTC](https://discuss.elastic.co/t/logstash-5-3-2-multiple-conf-files/106021 "2017-11-01T11:00:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![teejayuu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teejayuu/32/18356_2.png) [@teejayuu](https://discuss.elastic.co/u/teejayuu)\
**Post date:** [November 1, 2017, 11:00am UTC](https://discuss.elastic.co/t/logstash-5-3-2-multiple-conf-files/106021/1 "2017-11-01T11:00:43Z")

</div>

Good morning

I have setup my ELK stack (5.3.2) to gather Exchange Message Tracking logs from my Exchange Cluster with a conf file in `D:\ELK\logstash-5.3.2\01-inputs.conf\exchange_msg_trk.conf` and this is working well.

I have been tasked with monitoring Windows logons and have used [https://www.elastic.co/blog/monitoring-windows-logons-with-winlogbeat](https://www.elastic.co/blog/monitoring-windows-logons-with-winlogbeat) as a guide. I have a conf file in the same location called `winlogbeat_logons.conf`. This is working as well...except I have to start logstash manually (using `bin/logstash -f D:\ELK\logstash-5.3.2\01-inputs.conf\winlogbeat_logons.conf`) for it to accept the data. I am using NSSM to manage the logstash service.

Is it possible to have the logstash service start using muliple conf files i.e. `-f D:\ELK\logstash-5.3.2\01-inputs.conf\exchange_msg_trk.conf, D:\ELK\logstash-5.3.2\01-inputs.conf\winlogbeat_logons.conf`?

Thanks  
Tony

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 1, 2017, 12:39pm UTC](https://discuss.elastic.co/t/logstash-5-3-2-multiple-conf-files/106021/2 "2017-11-01T12:39:47Z")

</div>

I don't recall how Logstash behaves with multiple `-f` options, but the typical solution to the problem is to put all the files in a directory and point to that directory with `-f` (in your case `-f D:\ELK\logstash-5.3.2\01-inputs.conf` I suppose).

---

<div class="post-metadata">

**Author:** ![teejayuu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teejayuu/32/18356_2.png) [@teejayuu](https://discuss.elastic.co/u/teejayuu)\
**Post date:** [November 1, 2017, 3:05pm UTC](https://discuss.elastic.co/t/logstash-5-3-2-multiple-conf-files/106021/3 "2017-11-01T15:05:47Z")

</div>

> [@magnusbaeck](#):
>
> how Logstash behaves with multiple -f options, but

Thanks. That worked

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2017, 3:06pm UTC](https://discuss.elastic.co/t/logstash-5-3-2-multiple-conf-files/106021/4 "2017-11-29T15:06:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
