# Logstash syslog input from two sources

**URL:** <https://discuss.elastic.co/t/logstash-syslog-input-from-two-sources/374561>\
**Category:** Community Ecosystem\
**Created:** [February 14, 2025, 2:19pm UTC](https://discuss.elastic.co/t/logstash-syslog-input-from-two-sources/374561 "2025-02-14T14:19:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![WisemanIT](https://avatars.discourse-cdn.com/v4/letter/w/91b2a8/32.png) [@WisemanIT](https://discuss.elastic.co/u/WisemanIT)\
**Post date:** [February 14, 2025, 2:19pm UTC](https://discuss.elastic.co/t/logstash-syslog-input-from-two-sources/374561/1 "2025-02-14T14:19:07Z")

</div>

Hi All

I am trying to ingest syslog from two separate sources (one firewall and one Linux based appliance) and forward to log analytics workspace in Azure. I was able to achieve this using two separate conf files each with unique ports (one running on port 514 and other on 515). The problem is when I run two conf together it doesn't work. I am new to logstash and any help with be greatly appreciated.

## My conf files look like this Conf file 1

```auto
input {
     syslog {
         port => 514
    }
}

output {
    microsoft-sentinel-logstash-output {
      managed_identity => true
      tenant_id => "XXX"
	  data_collection_endpoint => "https://XXX1.uksouth-1.ingest.monitor.azure.com"
      dcr_immutable_id => "dcr-XXX1"
      dcr_stream_name => "Custom-XXX1"
    }
}

```

## Conf file 2

```auto
input {
     syslog {
         port => 515
    }
}

output {
    microsoft-sentinel-logstash-output {
      managed_identity => true
      tenant_id => "XXX"
	  data_collection_endpoint => "https://XXX2.uksouth-1.ingest.monitor.azure.com"
      dcr_immutable_id => "dcr-XXX2"
      dcr_stream_name => "Custom-XXX2"
    }
}

```

Question 1: Do I need two separate conf files? can it be combined into 1 file considering the logs are destined to different tables in Log Analytics Workspace?  
Question 2: What causes the issue?

Error Message

```auto

[FATAL][org.logstash.Logstash] Logstash stopped processing because of an error: (SystemExit) exit
org.jruby.exceptions.SystemExit: (SystemExit) exit

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 14, 2025, 2:38pm UTC](https://discuss.elastic.co/t/logstash-syslog-input-from-two-sources/374561/2 "2025-02-14T14:38:34Z")

</div>

How are you running Logstash?

There are a couple of issues here, ports below 1024 are reserved and only a privileged user can bind to them, it is not recommended to run Logstash as root or as a privileged user, so it would be better to change the ports or configure your system to allow the logstash user to bind to those ports.

> [@WisemanIT](#):
>
> Question 1: Do I need two separate conf files? can it be combined into 1 file considering the logs are destined to different tables in Log Analytics Workspace?

You can use only file, but would need to use conditionals, if you do not use conditionals the data received by all inputs will be sent to all outputs, also, even if you use 2 files, but do not configure Logstash to run multiple pipelines, those files would be merged into one configuration.

I recommend to use multiple files and configure the pipelines in `pipelines.yml`, as mentioned in this [documentation](https://www.elastic.co/guide/en/logstash/current/multiple-pipelines.html).

> [@WisemanIT](#):
>
> Question 2: What causes the issue?

You need to provide more context, the error you shared is not enough to troubleshoot the issue.

Please describe how you are running Logstash and share the full error you are getting.

---

<div class="post-metadata">

**Author:** ![WisemanIT](https://avatars.discourse-cdn.com/v4/letter/w/91b2a8/32.png) [@WisemanIT](https://discuss.elastic.co/u/WisemanIT)\
**Post date:** [February 14, 2025, 6:48pm UTC](https://discuss.elastic.co/t/logstash-syslog-input-from-two-sources/374561/3 "2025-02-14T18:48:08Z")

</div>

Hi Leandro

Many thanks for your reply. I seem to find the issue with the pipelines.yml file where I used incorect syntax for the config file path. As it is running on Windows server, it needed double backslashes. I have copied the content below for the reference .

```auto
- pipeline.id: my_first_pipeline
  pipeline.workers: 1
  path.config: "C:\\logstash-8.17.1\\config\\myfirstconfigfile.conf"
- pipeline.id: my_second_pipeline
  pipeline.workers: 1
  path.config: "C:\\logstash-8.17.1\\config\\mysecondconfigfile.conf"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 14, 2025, 6:48pm UTC](https://discuss.elastic.co/t/logstash-syslog-input-from-two-sources/374561/4 "2025-03-14T18:48:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
