# Logstash gives error while trying to start multiple config files

**URL:** <https://discuss.elastic.co/t/logstash-gives-error-while-trying-to-start-multiple-config-files/60728>\
**Category:** Logstash\
**Created:** [September 16, 2016, 3:13pm UTC](https://discuss.elastic.co/t/logstash-gives-error-while-trying-to-start-multiple-config-files/60728 "2016-09-16T15:13:32Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sri\_ram](https://avatars.discourse-cdn.com/v4/letter/s/3da27b/32.png) [@Sri\_ram](https://discuss.elastic.co/u/Sri_ram)\
**Post date:** [September 16, 2016, 3:13pm UTC](https://discuss.elastic.co/t/logstash-gives-error-while-trying-to-start-multiple-config-files/60728/1 "2016-09-16T15:13:32Z")

</div>

Hi,

We are collecting the application logs generated on one server, sending them to logstash using Filebeat. There are different format/types of log data, we had individual logstash config file to parse the data( i.e. each config file has the input, filter and output section). For all the config files, Filebeat will be the input.

So, i have copied all the logstash config files in to one single directory (config directory). When i started the logstash, it gives the following error:

$ bin/logstash -f ConfigDirPath/

`Pipeline aborted due to error {:exception=>#<Errno::EADDRINUSE: Address already in use - bind - Address already in use>, :backtrace=>["org/jruby/ext/socket/RubyTCPServer.java:118:in`initialize'", "org/jruby/RubyIO.java:853:in `new'", "/home/custom/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-input-beats-2.2.9/lib/lumberjack/beats/server.rb:51:in`initialize'",`

Is there any option to run all the config files at the same time to read events sent by filebeat ?

Again, all the config files has the following in their input section:  
input {  
beats {  
port =\> 5044  
}  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 17, 2016, 5:29am UTC](https://discuss.elastic.co/t/logstash-gives-error-while-trying-to-start-multiple-config-files/60728/2 "2016-09-17T05:29:22Z")

</div>

> [@Sri\_ram](#):
>
> Is there any option to run all the config files at the same time to read events sent by filebeat ?

It will do that by default if it is pointed to a directory.

> [@Sri\_ram](#):
>
> EADDRINUSE: Address already in use - bind - Address already in use

Maybe you have a duplicated config?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 17, 2016, 5:50pm UTC](https://discuss.elastic.co/t/logstash-gives-error-while-trying-to-start-multiple-config-files/60728/3 "2016-09-17T17:50:50Z")

</div>

> We are collecting the application logs generated on one server, sending them to logstash using Filebeat. There are different format/types of log data, we had individual logstash config file to parse the data( i.e. each config file has the input, filter and output section). For all the config files, Filebeat will be the input.

That's not how Logstash works with multiple configuration files. The files won't be independent in the way you think. Logstash has a single event pipeline where filters from _all_ configuration files process events from inputs in _all_ configuration files and then handing off the results to outputs from _all_ configuration files. You can wrap filters and outputs in conditionals to avoid having them apply to every single events.

> Again, all the config files has the following in their input section:  
> input {  
> beats {  
> port =\> 5044  
> }  
> }

Because of the reasons stated above this won't work and will predictably result in exactly the error you're getting.

---

<div class="post-metadata">

**Author:** ![Sri\_ram](https://avatars.discourse-cdn.com/v4/letter/s/3da27b/32.png) [@Sri\_ram](https://discuss.elastic.co/u/Sri_ram)\
**Post date:** [September 19, 2016, 2:20pm UTC](https://discuss.elastic.co/t/logstash-gives-error-while-trying-to-start-multiple-config-files/60728/4 "2016-09-19T14:20:34Z")

</div>

I have " **beats plugin**" in the input section for all the config files (3 files). That is the only duplicate and common config in all config files.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 19, 2016, 2:32pm UTC](https://discuss.elastic.co/t/logstash-gives-error-while-trying-to-start-multiple-config-files/60728/5 "2016-09-19T14:32:32Z")

</div>

> That is the only duplicate and common config in all config files.

Yes, and such duplication won't work.

---

<div class="post-metadata">

**Author:** ![Sri\_ram](https://avatars.discourse-cdn.com/v4/letter/s/3da27b/32.png) [@Sri\_ram](https://discuss.elastic.co/u/Sri_ram)\
**Post date:** [September 19, 2016, 2:32pm UTC](https://discuss.elastic.co/t/logstash-gives-error-while-trying-to-start-multiple-config-files/60728/6 "2016-09-19T14:32:46Z")

</div>

@magnusbaeck Thanks for your response. So, all the config files are using filebeat in the input section. While we start logstash it uses the first config file from the available files, when it's trying to load second config file from the list it's giving error because filebeat is already in use with the first config file.

Is there any option to have common input file for all config files.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 19, 2016, 2:35pm UTC](https://discuss.elastic.co/t/logstash-gives-error-while-trying-to-start-multiple-config-files/60728/7 "2016-09-19T14:35:45Z")

</div>

List the beats input exactly one time in one of the files (or a completely separate file). If messages from different hosts or of different types should be filtered differently you can use conditionals.

[https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:38am UTC](https://discuss.elastic.co/t/logstash-gives-error-while-trying-to-start-multiple-config-files/60728/8 "2017-07-06T04:38:00Z")

</div>


