# Logstash Multiple File Inputs

**URL:** <https://discuss.elastic.co/t/logstash-multiple-file-inputs/36397>\
**Category:** Logstash\
**Created:** [December 4, 2015, 3:24pm UTC](https://discuss.elastic.co/t/logstash-multiple-file-inputs/36397 "2015-12-04T15:24:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kryten](https://avatars.discourse-cdn.com/v4/letter/k/58956e/32.png) [@Kryten](https://discuss.elastic.co/u/Kryten)\
**Post date:** [December 4, 2015, 3:24pm UTC](https://discuss.elastic.co/t/logstash-multiple-file-inputs/36397/1 "2015-12-04T15:24:40Z")

</div>

Hi,

Would appreciate a pointer with regard to using multiple file inputs.

This works:-

```
input {
	
	file {
		path => [
			"//server_1/Logs/*",
			"//server_2/Logs/*",
			"//server_2/Logs/*",
			"//server_2/Logs/*",
			"//server_2/Logs/*"
		]					
	start_position => "beginning"
	sincedb_path => "E:/LS/logstash-2.0.0/.sincedb"
}
} # END INPUT

```

I am collecting logs from different locations and processing them in a single LS config file.

The downside of this is that every LS document produced ends up with the "host" value set as the LS machine. I need the host value to be the remote machine which created the log in the first place.

Whats best practice here? Should I have multiple file inputs (one per path) and add a type for each message then do a:-

```
if [type] == "server_1" {
    add_field => { "host_server" => "server_1_hostname" }
}

```

Or is there a more efficient way? Would I need to have a .sincedb defined per file input?

Would be grateful for a steer on best practice for monitoring multiple paths, keeping the host values separate and managing .sincedb(s)

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 4, 2015, 3:30pm UTC](https://discuss.elastic.co/t/logstash-multiple-file-inputs/36397/2 "2015-12-04T15:30:25Z")

</div>

Each event will have a `path` field with the path to the log file from which the event was read. Use a grok filter to extract the hostname from that path.

---

<div class="post-metadata">

**Author:** ![Kryten](https://avatars.discourse-cdn.com/v4/letter/k/58956e/32.png) [@Kryten](https://discuss.elastic.co/u/Kryten)\
**Post date:** [December 5, 2015, 9:57am UTC](https://discuss.elastic.co/t/logstash-multiple-file-inputs/36397/3 "2015-12-05T09:57:03Z")

</div>

Thanks Magnus!  
My template LS config which I tend to use for everything new contains a mutate to remove a tonne of stuff. Path was one of them. Once I let the field in I was able to grok what I needed. In fact the end result is better than ever as instead of updating the host field I just made a new 'server\_name' field, so now I get both.

Thanks again - you are doing an incredible job here!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:19am UTC](https://discuss.elastic.co/t/logstash-multiple-file-inputs/36397/4 "2017-07-06T05:19:54Z")

</div>


