# Logstash multiple pipelines going into same index

**URL:** <https://discuss.elastic.co/t/logstash-multiple-pipelines-going-into-same-index/128066>\
**Category:** Logstash\
**Created:** [April 15, 2018, 8:11am UTC](https://discuss.elastic.co/t/logstash-multiple-pipelines-going-into-same-index/128066 "2018-04-15T08:11:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![saargrin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saargrin/32/29993_2.png) [@saargrin](https://discuss.elastic.co/u/saargrin)\
**Post date:** [April 15, 2018, 8:11am UTC](https://discuss.elastic.co/t/logstash-multiple-pipelines-going-into-same-index/128066/1 "2018-04-15T08:11:27Z")

</div>

Hi  
i'm trying to set up a centralized syslog for multiple log sources

so i have a logstash that has two separate inputs and two separate outputs

however for some reason the data from one of the inputs ends up in both indexes

what am i doing wrong?

below both pipelines' configs

input{  
tcp {  
port =\> 5052  
codec =\> "json\_lines"  
}  
}

output {  
elasticsearch {  
hosts =\> "10.50.6.116"  
index =\> "remote"  
}

## file { path =\> "/var/log/logstash/remote-tcp.log" } stdout { codec =\> rubydebug } }

input {  
file {  
path =\> "/data/vmlist/\*.csv"  
start\_position =\> "beginning"  
sincedb\_path =\> "/tmp/sincedb"  
}  
}

filter {  
csv {  
separator =\> ","  
columns =\> ["VM Name","Creation Date","Owner","Type","Message"]  
}  
}

output {  
elasticsearch {  
hosts =\> "[http://10.50.6.116:9200](http://10.50.6.116:9200)"  
index =\> "vms"  
document\_type =\> "csv"  
}  
stdout{ codec=\> rubydebug}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 15, 2018, 12:22pm UTC](https://discuss.elastic.co/t/logstash-multiple-pipelines-going-into-same-index/128066/2 "2018-04-15T12:22:05Z")

</div>

Are you using pipelines.yml? If so please show it to us. If not, this would be expected. Configuration files are not self-contained. logstash concatentates all the configuration files from a directory, reads from all the inputs, puts the events through the filters in order, then sends the events to all of the outputs.

Reading [this](https://discuss.elastic.co/t/send-data-to-right-pipeline-from-two-csv-files/126700) thread or [this one](https://discuss.elastic.co/t/beats-received-on-port-11001-are-being-processed-by-port-11000-config/126603/4) might help you.

---

<div class="post-metadata">

**Author:** ![saargrin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saargrin/32/29993_2.png) [@saargrin](https://discuss.elastic.co/u/saargrin)\
**Post date:** [April 15, 2018, 2:08pm UTC](https://discuss.elastic.co/t/logstash-multiple-pipelines-going-into-same-index/128066/3 "2018-04-15T14:08:35Z")

</div>

thanks, that was the issue

i followed some blog guide that didnt mention the pipelines.yml file

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 13, 2018, 2:08pm UTC](https://discuss.elastic.co/t/logstash-multiple-pipelines-going-into-same-index/128066/4 "2018-05-13T14:08:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
