# Logstash config query

**URL:** https://discuss.elastic.co/t/logstash-config-query/36452
**Category:** Logstash
**Created:** [December 5, 2015, 4:16pm UTC](https://discuss.elastic.co/t/logstash-config-query/36452 "2015-12-05T16:16:41Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)
#### Post date: [December 5, 2015, 4:16pm UTC](https://discuss.elastic.co/t/logstash-config-query/36452/1 "2015-12-05T16:16:41Z")

</div>

Till now I had maintain single configuration file in logstash server that is called as logstash-server.conf.

Now I would like to separate the configuration based on input criteria. my logstash service is pointed to default directory [/etc/logstash/conf.d]

My query., each configuration file in the directory will be considered as separate one or will be treated as same file.

Current Config :

> [root@srv conf.d]# pwd  
> /etc/logstash/conf.d  
> [root@srv conf.d]# ls  
> logstash-server.conf  
> [root@srv conf.d]#

Expected config structure:

> [root@srv conf.d]# pwd  
> /etc/logstash/conf.d  
> [root@srv conf.d]# ls  
> production.conf testing.conf  
> [root@srv conf.d]#

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [December 5, 2015, 4:25pm UTC](https://discuss.elastic.co/t/logstash-config-query/36452/2 "2015-12-05T16:25:35Z")

</div>

Having multiple configuration files in a directory is equivalent to concatenating those files in alphabetical filename order and passing the resulting file to Logstash.

---

<div class="post-metadata">

### Author: ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)
#### Post date: [December 5, 2015, 4:47pm UTC](https://discuss.elastic.co/t/logstash-config-query/36452/3 "2015-12-05T16:47:20Z")

</div>

Thanks for your reply.

If I have written else statement in each configuration file, will it be considered to appropriate config or else it will be considered as global ?.

Production output config:

> output {  
> if [type] == "prod" {  
> elasticsearch {  
> host =\> "localhost"  
> protocol =\> http  
> index =\> "prod-%{+YYYY.MM.dd}"  
> }  
> }  
> else {  
> file { path =\> "./prod\_parsemissing.log" }  
> }  
> }

Testing output config:

> output {  
> if [type] == "test" {  
> elasticsearch {  
> host =\> "localhost"  
> protocol =\> http  
> index =\> "test-%{+YYYY.MM.dd}"  
> }  
> }  
> else {  
> file { path =\> "./test\_parsemissing.log" }  
> }  
> }

From the above config, what happen if the conditions fails. entries will be written to appropriate log files or else it will be written on last global else configuration.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [December 5, 2015, 6:50pm UTC](https://discuss.elastic.co/t/logstash-config-query/36452/4 "2015-12-05T18:50:43Z")

</div>

The contents of the two files above is equivalent to having

```auto
output {
  if [type] == "prod" {
    elasticsearch { ... }
  } else {
    file { ... }
  }
  if [type] == "test" {
    elasticsearch { ... }
  } else {
    file { ... }
  }
}

```

in a single file. Hence, messages with `type` equal to "prod" will be sent to a prod-\* index in ES _and_ test\_parsemissing.log, and messages with `type` equal to "test" will be sent to a test-\* index in ES _and_ prod\_parsemissing.log.

---

<div class="post-metadata">

### Author: ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)
#### Post date: [December 5, 2015, 7:21pm UTC](https://discuss.elastic.co/t/logstash-config-query/36452/5 "2015-12-05T19:21:41Z")

</div>

> [@magnusbaeck](#):
>
> in a single file. Hence, messages with type equal to "prod" will be sent to a prod-\* index in ES and test\_parsemissing.log, and messages with type equal to "test" will be sent to a test-\* index in ES and prod\_parsemissing.log.

I just confused here. Please confirm, Below is the correct one or above given statement is correct .

Message with type **"prod"** will be sent to _prod- index_\* and **prod\_parsemissing.log** file right

And Message with type **"test"** will be sent to _test- index_\* and **test\_parsemissing.log** file right

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [December 5, 2015, 7:25pm UTC](https://discuss.elastic.co/t/logstash-config-query/36452/6 "2015-12-05T19:25:33Z")

</div>

No. With the conditions you have set up messages won't be sent to _both_ the prod-\* index in ES _and_ prod\_parsemissing.log. It's either or. Messages with a "prod" or "test" `type` will reach the elasticsearch output in one of the conditionals and the file output in the other conditional. Messages with another `type` value will reach the file output in both conditionals.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 5:19am UTC](https://discuss.elastic.co/t/logstash-config-query/36452/7 "2017-07-06T05:19:52Z")

</div>


