# Logstash config

**URL:** <https://discuss.elastic.co/t/logstash-config/333631>\
**Category:** Logstash\
**Created:** [May 17, 2023, 7:07am UTC](https://discuss.elastic.co/t/logstash-config/333631 "2023-05-17T07:07:38Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![A1i](https://avatars.discourse-cdn.com/v4/letter/a/71c47a/32.png) [@A1i](https://discuss.elastic.co/u/A1i)\
**Post date:** [May 17, 2023, 7:07am UTC](https://discuss.elastic.co/t/logstash-config/333631/1 "2023-05-17T07:07:38Z")

</div>

how can I config logstash to read two log files from local then pass them into two indies

---

<div class="post-metadata">

**Author:** ![cperzrt10](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cperzrt10/32/116152_2.png) [@cperzrt10](https://discuss.elastic.co/u/cperzrt10)\
**Post date:** [May 17, 2023, 8:31am UTC](https://discuss.elastic.co/t/logstash-config/333631/2 "2023-05-17T08:31:33Z")

</div>

Hi, without any more data try this to send into 2 indices

```auto
input {
  file {
	path => ["/var/log/file1.log", "/var/log/file2.log"]
  }
}
filter {
    ##to do filter data
}
output {
#output to file
# file {
# path => "/tmp/localData.log"
# }
#output to elasticsearch
  if [log][file][path] == '/var/log/file2.log' {
    elasticsearch {
      hosts => ["192.168.x.xxx:9200"]
      manage_template => false
      index => "logstash-A-%{+YYYY.MM.dd}"
      ssl => true
      ssl_certificate_verification => false
      api_key => "xxxxxxxxxxxxxxxxxxxx:xxxxxxxxxxxxxxxxxxxxxx"
    }
   else {
    elasticsearch {
      hosts => ["192.168.x.xxx:9200"]
      manage_template => false
      index => "logstash-B-%{+YYYY.MM.dd}"
      ssl => true
      ssl_certificate_verification => false
      api_key => "xxxxxxxxxxxxxxxxxxxx:xxxxxxxxxxxxxxxxxxxxxx"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![A1i](https://avatars.discourse-cdn.com/v4/letter/a/71c47a/32.png) [@A1i](https://discuss.elastic.co/u/A1i)\
**Post date:** [May 17, 2023, 10:15am UTC](https://discuss.elastic.co/t/logstash-config/333631/3 "2023-05-17T10:15:48Z")

</div>

> [@cperzrt10](#):
>
> `if [log][file][path] ==`

Hi, thank you for your response. But it doesn't f\work for me. Here my config file

```auto
input {
  file {
    path => ["C:/nginx/logs/postcode/reverse-access.log", "C:/nginx/logs/behzisti/reverse-access.log"]
    start_position => "beginning"
  }
}

filter {
  grok {
    match => { "message" => '%{IPORHOST:clientip} - %{USERNAME:username} \[%{HTTPDATE:timestamp}\] "%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}" %{NUMBER:response} (?:%{NUMBER:bytes}|-)' }
  }
}

output {
  if [log][file][path] == "C:/nginx/logs/postcode/reverse-access.log" {
    elasticsearch {
      hosts => ["https://localhost:9200"]
      index => "webservices_nginx"
      ssl_certificate_verification => false
    }
  } 
  else if [log][file][path] == "C:/nginx/logs/behzisti/reverse-access.log" {
    elasticsearch {
      hosts => ["https://localhost:9200"]
      index => "behzisti_nginx"
      ssl_certificate_verification => false
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![cperzrt10](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cperzrt10/32/116152_2.png) [@cperzrt10](https://discuss.elastic.co/u/cperzrt10)\
**Post date:** [May 17, 2023, 10:35am UTC](https://discuss.elastic.co/t/logstash-config/333631/4 "2023-05-17T10:35:54Z")

</div>

Try instead

```auto
if [log][file][path] == "C:/nginx/logs/postcode/reverse-access.log" {

```

this

```auto
if [log][file][path] !~ /postcode/ {
  ....
} else if [log][file][path] !~ /behzisti/ {
  ....
}

```

this means that if the log.file.path contains "postcode" do the firts if and if contains "behzisti" do the second if

---

<div class="post-metadata">

**Author:** ![A1i](https://avatars.discourse-cdn.com/v4/letter/a/71c47a/32.png) [@A1i](https://discuss.elastic.co/u/A1i)\
**Post date:** [May 17, 2023, 10:50am UTC](https://discuss.elastic.co/t/logstash-config/333631/5 "2023-05-17T10:50:37Z")

</div>

I tested config for one by one and they worked. but doesn't work for two input together.  
do I need some extra configuration for Elasticsearch?

---

<div class="post-metadata">

**Author:** ![cperzrt10](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cperzrt10/32/116152_2.png) [@cperzrt10](https://discuss.elastic.co/u/cperzrt10)\
**Post date:** [May 17, 2023, 11:02am UTC](https://discuss.elastic.co/t/logstash-config/333631/6 "2023-05-17T11:02:43Z")

</div>

Create 2 logstash configuration files one each one, and name it dinstincts each one.  
This will work. Or you have centraliced pipelines?

---

<div class="post-metadata">

**Author:** ![A1i](https://avatars.discourse-cdn.com/v4/letter/a/71c47a/32.png) [@A1i](https://discuss.elastic.co/u/A1i)\
**Post date:** [May 17, 2023, 11:14am UTC](https://discuss.elastic.co/t/logstash-config/333631/7 "2023-05-17T11:14:03Z")

</div>

actually, this is my main config file. I want analyze data from local logs and from beatfile.

```auto
input {
  file {
    path => ["C:/nginx/logs/postcode/reverse-access.log", "C:/nginx/logs/behzisti/reverse-access.log"]
    start_position => "beginning"
    type => "nginx"
  }
  beats {
    port => 5044
    type => "wso2"
  }
}

filter {
  if [type] == "nginx" {
    if [path] == "C:/nginx/logs/postcode/reverse-access.log" {
      mutate {
        add_field => { "index_name" => "webservices_nginx" }
      }
    } else if [path] == "C:/nginx/logs/behzisti/reverse-access.log" {
      mutate {
        add_field => { "index_name" => "behzisti_nginx" }
      }
    }
    grok {
      match => { "message" => '%{IPORHOST:clientip} - %{USERNAME:username} \[%{HTTPDATE:timestamp}\] "%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}" %{NUMBER:response} (?:%{NUMBER:bytes}|-)' }
    }
  }
  else if [type] == "wso2" {
    grok {
        match => ["message", "%{GREEDYDATA:UNWANTED}\ apimMetrics:%{GREEDYDATA:apimMetrics}\, %{GREEDYDATA:UNWANTED} \:%{GREEDYDATA:properties}"]
    }
  }
}

output {
  if [type] == "nginx" {
    if [index_name] == "webservices_nginx" {
      elasticsearch {
        hosts => ["https://localhost:9200"]
        index => "webservices_nginx"
        ssl_certificate_verification => false
      }
    } else if [index_name] == "behzisti_nginx" {
      elasticsearch {
        hosts => ["https://localhost:9200"]
        index => "behzisti_nginx"
        ssl_certificate_verification => false
      }
    }
  } else if [type] == "wso2" {
    if [apimMetrics] == " apim:response" {
      elasticsearch {
        hosts => ["https://localhost:9200"]
        index => "apim_event_response"
        ssl_certificate_verification => false
      }
    } else if [apimMetrics] == " apim:faulty" {
      elasticsearch {
        hosts => ["https://localhost:9200"]
        index => "apim_event_faulty"
        ssl_certificate_verification => false
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![A1i](https://avatars.discourse-cdn.com/v4/letter/a/71c47a/32.png) [@A1i](https://discuss.elastic.co/u/A1i)\
**Post date:** [May 17, 2023, 11:16am UTC](https://discuss.elastic.co/t/logstash-config/333631/8 "2023-05-17T11:16:35Z")

</div>

Also I tried two config files separately, but just the frist config was apply.

---

<div class="post-metadata">

**Author:** ![cperzrt10](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cperzrt10/32/116152_2.png) [@cperzrt10](https://discuss.elastic.co/u/cperzrt10)\
**Post date:** [May 17, 2023, 11:29am UTC](https://discuss.elastic.co/t/logstash-config/333631/9 "2023-05-17T11:29:05Z")

</div>

You can have two config files for example 00-config.conf and 01-config.conf, when you restart your logstash service it must read all the configs,

I have in logstash multiple config files, i use 001-xxxxx.conf for the input data, 10-xxxxx.conf to filter the data and 30-output-xxxx.conf to configure the multiple indices output

---

<div class="post-metadata">

**Author:** ![A1i](https://avatars.discourse-cdn.com/v4/letter/a/71c47a/32.png) [@A1i](https://discuss.elastic.co/u/A1i)\
**Post date:** [May 22, 2023, 4:28am UTC](https://discuss.elastic.co/t/logstash-config/333631/10 "2023-05-22T04:28:57Z")

</div>

I solved it :  
first I defined three config file separately then I changed pipelines.yml :

```auto
- pipeline.id: nginx
  path.config: "C:\\Elastic\\logstash-8.7.0\\config\\logstash-sample1.conf"

- pipeline.id: nginx_behzisti
  path.config: "C:\\Elastic\\logstash-8.7.0\\config\\logstash-sample2.conf"

- pipeline.id: wso2
  path.config: "C:\\Elastic\\logstash-8.7.0\\config\\logstash-sample3.conf"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 19, 2023, 4:29am UTC](https://discuss.elastic.co/t/logstash-config/333631/11 "2023-06-19T04:29:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
