# Logstash with multiple conf files

**URL:** <https://discuss.elastic.co/t/logstash-with-multiple-conf-files/255664>\
**Category:** Logstash\
**Created:** [November 17, 2020, 10:27am UTC](https://discuss.elastic.co/t/logstash-with-multiple-conf-files/255664 "2020-11-17T10:27:42Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kfiro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kfiro/32/46872_2.png) [@Kfiro](https://discuss.elastic.co/u/Kfiro)\
**Post date:** [November 17, 2020, 10:27am UTC](https://discuss.elastic.co/t/logstash-with-multiple-conf-files/255664/1 "2020-11-17T10:27:42Z")

</div>

Hi ELK,  
I'm trying to configure my Logstash to run with 2 "conf" files,

First: winlogbeat.conf

```
input {
  beats {
    port => 5044
  }
}
output {
		elasticsearch {
				hosts=>["https://elk01:9200"]
				index=>"logstash-%{+YYYY.MM.dd}b"
				cacert => '/etc/logstash/config/certs/ca.crt'
				user => 'elastic'
				password => '123456'
		}
}

```

Second: packetbeat.conf

```
input {
  beats {
    port => 5045
  }
}
output {
		elasticsearch {
				hosts=>["https://elk02:9200"]
				index=>"packetbeat-%{+YYYY.MM.dd}b"
				cacert => '/etc/logstash/config/certs/ca.crt'
				user => 'elastic'
				password => '123456'
		}
}

```

This is my logstash.yml:

path.data: /var/lib/logstash  
pipeline.ordered: auto  
path.logs: /var/log/logstash  
log.level: debug  
node.name: logstashp01  
path.config: /etc/logstash/conf.d/\*.conf

and this the pipline.yml:

- pipeline.id: pipeline\_1  
path.config: "/etc/logstash/conf.d/winlogbeat.conf"

- pipeline.id: pipeline\_2  
path.config: "/etc/logstash/conf.d/packetbeat.conf"

Then i'm starting Logstash from command Line:  
/usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/examplelk01.conf,/etc/logstash/conf.d/packetbeat.conf

Logstash's failed to run

can you help me please... what am i missing or any otherway to solve that issue ??

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 17, 2020, 10:42pm UTC](https://discuss.elastic.co/t/logstash-with-multiple-conf-files/255664/2 "2020-11-17T22:42:16Z")

</div>

Please format your code/logs/config using the `</>` button, or markdown style back ticks. It helps to make things easy to read which helps us help you 🙂

You haven't described what problem you are trying to solve, so it's not clear what the issue is here sorry.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 17, 2020, 11:08pm UTC](https://discuss.elastic.co/t/logstash-with-multiple-conf-files/255664/3 "2020-11-17T23:08:03Z")

</div>

You should be getting the warning

```auto
[WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified

```

Remove `-f /etc/logstash/conf.d/examplelk01.conf,/etc/logstash/conf.d/packetbeat.conf` from the command line. logstash will then read pipelines.yml and run each configuration file in its own pipeline.

If you keep the -f then logstash will concatenate the configuration files into a single configuration. It will read events from both beats inputs, and send them all to both elasticsearch outputs.

---

<div class="post-metadata">

**Author:** ![Kfiro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kfiro/32/46872_2.png) [@Kfiro](https://discuss.elastic.co/u/Kfiro)\
**Post date:** [November 18, 2020, 8:50am UTC](https://discuss.elastic.co/t/logstash-with-multiple-conf-files/255664/4 "2020-11-18T08:50:15Z")

</div>

Thanks, I Edited the post.

---

<div class="post-metadata">

**Author:** ![Kfiro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kfiro/32/46872_2.png) [@Kfiro](https://discuss.elastic.co/u/Kfiro)\
**Post date:** [November 18, 2020, 8:52am UTC](https://discuss.elastic.co/t/logstash-with-multiple-conf-files/255664/5 "2020-11-18T08:52:20Z")

</div>

Thank you Badger,  
Its work!!

only needed to add --path.settings /etc/logstash on the command line

---

<div class="post-metadata">

**Author:** ![Kfiro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kfiro/32/46872_2.png) [@Kfiro](https://discuss.elastic.co/u/Kfiro)\
**Post date:** [November 25, 2020, 10:00am UTC](https://discuss.elastic.co/t/logstash-with-multiple-conf-files/255664/6 "2020-11-25T10:00:11Z")

</div>

@Badger  
thank you for the response friend,  
the logstash is running with the 2 config files,  
but both the winlogeat agent and the packetbeat agent are writing events to the 2 indices:  
logstash and packetbeat,  
Although I have set in both Conf Files to send to a separate index as you can see

do you know why?  
Thanks in advance

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 25, 2020, 1:37pm UTC](https://discuss.elastic.co/t/logstash-with-multiple-conf-files/255664/7 "2020-11-25T13:37:41Z")

</div>

As I said, if you use -f then logstash will concatenate the configuration files into a single configuration. It will read events from both beats inputs, and send them all to both elasticsearch outputs. Similarly if you set path.config in pipelines.yml to include both configurations for one pipeline.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 23, 2020, 1:37pm UTC](https://discuss.elastic.co/t/logstash-with-multiple-conf-files/255664/8 "2020-12-23T13:37:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
