# Logstash service behaving different than command line

**URL:** <https://discuss.elastic.co/t/logstash-service-behaving-different-than-command-line/63104>\
**Category:** Logstash\
**Created:** [October 15, 2016, 12:54pm UTC](https://discuss.elastic.co/t/logstash-service-behaving-different-than-command-line/63104 "2016-10-15T12:54:30Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 15, 2016, 2:20pm UTC](https://discuss.elastic.co/t/logstash-service-behaving-different-than-command-line/63104/2 "2016-10-15T14:20:24Z")

</div>

When you run Logstash as a service, it will concatenate both configuration files into one and all events will go through all filters as you are not using [conditionals](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#conditionals). Add a tag in each input so you can use this to apply the correct filters and output to each event using conditionals.

There are quite a few examples of this type of configuration in these forums, e.g. [this one](https://discuss.elastic.co/t/log-in-wrong-index/62740/6).

---

_[View the full topic](https://discuss.elastic.co/t/logstash-service-behaving-different-than-command-line/63104)._
