# Logstash with multi port nad multi file not work properly

**URL:** <https://discuss.elastic.co/t/logstash-with-multi-port-nad-multi-file-not-work-properly/356144>\
**Category:** Logstash\
**Created:** [March 26, 2024, 6:13am UTC](https://discuss.elastic.co/t/logstash-with-multi-port-nad-multi-file-not-work-properly/356144 "2024-03-26T06:13:09Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 26, 2024, 11:17am UTC](https://discuss.elastic.co/t/logstash-with-multi-port-nad-multi-file-not-work-properly/356144/4 "2024-03-26T11:17:06Z")

</div>

> [@shahrestanaki](#):
>
> At runtime, it seemed that behind the scenes these two files were merged together, and therefore entries to each port were sent to both indexes.

Yes, under a single pipeline, everything is merge. It's by design. Explained [here](https://discuss.elastic.co/t/running-multiple-independent-logstash-config-files-with-input-filter-and-output/29757), [here](https://discuss.elastic.co/t/logstash-setting-up-multiple-config-files-in-one-pipeline/190643) and [here](https://discuss.elastic.co/t/combining-several-logstash-config-files-into-one-how-do-you-do-it/33546).

Your logic has sense when is a case - single node, 3-5 nodes etc. The enterprise environment is a little bit different. You have data transformation for FB, HTTP, syslog, jdbc from a single "source" - department inside biiiig company. When 2-5 different persons are working on the ETL integration, one big .conf file could be mess. Also don't forget, LS supports the ruby code, execution files,... That is mess, I mean a really mess, the single file with more than several hundreds lines in the filter section.

---

_[View the full topic](https://discuss.elastic.co/t/logstash-with-multi-port-nad-multi-file-not-work-properly/356144)._
