# Logstash - configuration with multiple sources

**URL:** <https://discuss.elastic.co/t/logstash-configuration-with-multiple-sources/252017>\
**Category:** Logstash\
**Created:** [October 14, 2020, 9:20am UTC](https://discuss.elastic.co/t/logstash-configuration-with-multiple-sources/252017 "2020-10-14T09:20:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![maria\_lopez\_perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maria_lopez_perez/32/77154_2.png) [@maria\_lopez\_perez](https://discuss.elastic.co/u/maria_lopez_perez)\
**Post date:** [October 14, 2020, 9:20am UTC](https://discuss.elastic.co/t/logstash-configuration-with-multiple-sources/252017/1 "2020-10-14T09:20:23Z")

</div>

Hello,

I try to create a configuration in Logstash in order to have two index in elasticserach relation to two diferentes sources (two files), The configuration is:

input {  
file {  
path =\> "/etc/logstash/ficheros/disco\*"  
tag =\> "serverweb\_disco"  
sincedb\_path =\> "/dev/null"  
start\_position =\> "beginning"  
}  
file {  
path =\> "/etc/logstash/ficheros/conexiones\*"  
tag =\> "serverweb\_conexiones"  
sincedb\_path =\> "/dev/null"  
start\_position =\> "beginning"  
}  
}  
filter{  
if "serverweb\_disco" in [tag]{  
grok{  
match =\> {"message" =\> "%{DATA:Fecha},%{DATA:Nombre\_Servidor},%{DATA:Particion\_disco},%{DATA:Sistema\_ficheros},%{NUMBER:Porcentaje\_usado\>  
}  
}else if "serverweb\_conexiones" in [tag]{  
grok{  
match =\> {"message" =\> "%{DATA:Fecha},%{DATA:Nombre\_Servidor},%{DATA:Estado},%{DATA:Conexion},%{NUMBER:Numero\_conexiones}"}  
}  
}  
}  
output {  
if "serverweb\_disco" in [tag]{  
elasticsearch {  
hosts =\> ["[http://192.168.1.23:9200](http://192.168.1.23:9200)"]  
index =\> "serverweb-disco-%{+YYYY.MM.dd}"  
}  
}else if "serverweb\_conexiones" in [tag]{  
elasticsearch {  
hosts =\> ["[http://192.168.1.23:9200](http://192.168.1.23:9200)"]  
index =\> "serverweb-conexiones-%{+YYYY.MM.dd}"  
}  
}  
}

But when I start Logstash I have the following error:

warning: thread "Converge PipelineAction::Create" terminated with exception (report\_on\_exception is true):  
LogStash::Error: Don't know how to handle `Java::JavaLang::IllegalStateException` for `PipelineAction::Create<main>`  
create at org/logstash/execution/ConvergeResultExt.java:129  
add at org/logstash/execution/ConvergeResultExt.java:57  
converge\_state at /usr/share/logstash/logstash-core/lib/logstash/agent.rb:370  
[ERROR] 2020-10-14 02:08:12.046 [Agent thread] agent - An exception happened when converging configuration {:exception=\>LogStash::Error, :message=\>"Don't know how to handle `Java::JavaLang::IllegalStateException` for `PipelineAction::Create<main>`"}  
[FATAL] 2020-10-14 02:08:12.154 [LogStash::Runner] runner - An unexpected error occurred! {:error=\>#\<LogStash::Error: Don't know how to handle `Java::JavaLang::IllegalStateException` for `PipelineAction::Create<main>`\>, :backtrace=\>["org/logstash/execution/ConvergeResultExt.java:129:in `create'", "org/logstash/execution/ConvergeResultExt.java:57:in `add'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:370:in `block in converge\_state'"]}  
[ERROR] 2020-10-14 02:08:12.227 [LogStash::Runner] Logstash - java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit

I don't know if my configuration is correct or my way of using tag is the best or not. Can anyboday help me?

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 14, 2020, 2:42pm UTC](https://discuss.elastic.co/t/logstash-configuration-with-multiple-sources/252017/2 "2020-10-14T14:42:14Z")

</div>

You seem to be missing a closing double quote in the grok for serverweb\_disco. Try setting log.level to debug, you might get a more informative error message.

---

<div class="post-metadata">

**Author:** ![maria\_lopez\_perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maria_lopez_perez/32/77154_2.png) [@maria\_lopez\_perez](https://discuss.elastic.co/u/maria_lopez_perez)\
**Post date:** [October 14, 2020, 3:18pm UTC](https://discuss.elastic.co/t/logstash-configuration-with-multiple-sources/252017/3 "2020-10-14T15:18:32Z")

</div>

Sorry I put a wrong configuration. My configuration is the following, and the error is the same as I posted.

input {  
file {  
path =\> "/etc/logstash/ficheros/disco\*"  
tag =\> "serverweb\_disco"  
sincedb\_path =\> "/dev/null"  
start\_position =\> "beginning"  
}  
file {  
path =\> "/etc/logstash/ficheros/conexiones\*"  
tag =\> "serverweb\_conexiones"  
sincedb\_path =\> "/dev/null"  
start\_position =\> "beginning"  
}  
}  
filter{  
if "serverweb\_disco" in [tag]{  
grok{  
match =\> {"message" =\> "%{DATA:Fecha},%{DATA:Nombre\_Servidor},%{DATA:Particion\_disco},%{DATA:Sistema\_ficheros},%{NUMBER:Porcentaje\_usado}"}  
}  
}else if "serverweb\_conexiones" in [tag]{  
grok{  
match =\> {"message" =\> "%{DATA:Fecha},%{DATA:Nombre\_Servidor},%{DATA:Estado},%{DATA:Conexion},%{NUMBER:Numero\_conexiones}"}  
}  
}  
}  
output {  
if "serverweb\_disco" in [tag]{  
elasticsearch {  
hosts =\> ["[http://192.168.1.23:9200](http://192.168.1.23:9200)"]  
index =\> "serverweb-disco-%{+YYYY.MM.dd}"  
}  
}else if "serverweb\_conexiones" in [tag]{  
elasticsearch {  
hosts =\> ["[http://192.168.1.23:9200](http://192.168.1.23:9200)"]  
index =\> "serverweb-conexiones-%{+YYYY.MM.dd}"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 11, 2020, 3:18pm UTC](https://discuss.elastic.co/t/logstash-configuration-with-multiple-sources/252017/4 "2020-11-11T15:18:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
