# Logstash multiple configuration files

**URL:** <https://discuss.elastic.co/t/logstash-multiple-configuration-files/138566>\
**Category:** Logstash\
**Created:** [July 4, 2018, 1:28pm UTC](https://discuss.elastic.co/t/logstash-multiple-configuration-files/138566 "2018-07-04T13:28:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Khaled\_Saidi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khaled_saidi/32/98636_2.png) [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Post date:** [July 4, 2018, 1:28pm UTC](https://discuss.elastic.co/t/logstash-multiple-configuration-files/138566/1 "2018-07-04T13:28:15Z")

</div>

Hi everybody,

Do you think it is possible to have several configuration for logstash filters files and load only one according to the filebeat agent version ?  
Thanks a lot for your help.

BR,  
Khaled

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 4, 2018, 2:16pm UTC](https://discuss.elastic.co/t/logstash-multiple-configuration-files/138566/2 "2018-07-04T14:16:50Z")

</div>

Filebeat adds a [beat][version] field to events. You could make your processing [conditional](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html) upon that.

---

<div class="post-metadata">

**Author:** ![Khaled\_Saidi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khaled_saidi/32/98636_2.png) [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Post date:** [July 4, 2018, 4:08pm UTC](https://discuss.elastic.co/t/logstash-multiple-configuration-files/138566/3 "2018-07-04T16:08:59Z")

</div>

Thank you for the reply.  
I know that filebeat sends its version so that it is possible to have a conditional processing.  
By convenience, i don't want to have my implementation in the same file.  
So, is it possible to have filter\_1.conf (for filebeat version 1) and filter\_2.conf (for filebeat version 2) included in filter\_conf and make something like this :

```
filter {
    if [version] == 1 {
        process(filter_1.conf)
    }
    else {
        process(filter_2.conf)
    }
} 

```

BR,

Khaled

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 4, 2018, 5:07pm UTC](https://discuss.elastic.co/t/logstash-multiple-configuration-files/138566/4 "2018-07-04T17:07:28Z")

</div>

If you start logstash with "-f /some/directory/" then it will concatenate all of the files in that directory (all of them, including files called things like logstash.conf.backup) and use that as the configuration. So you can have two files. One that has

```
filter {
    if [beat][version] == "some version" {
         processing for that version
    }
}

```

and a second file that has

```
filter {
    if [beat][version] == "some other version" {
         processing for that version
    }
}
```

---

<div class="post-metadata">

**Author:** ![Khaled\_Saidi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khaled_saidi/32/98636_2.png) [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Post date:** [July 5, 2018, 7:15am UTC](https://discuss.elastic.co/t/logstash-multiple-configuration-files/138566/5 "2018-07-05T07:15:31Z")

</div>

Badger,

You're the Boss !  
Thanks a lot for your help.

BR,  
Khaled

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2018, 7:15am UTC](https://discuss.elastic.co/t/logstash-multiple-configuration-files/138566/6 "2018-08-02T07:15:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
