# Multiple conf files handling issue in logstash

**URL:** https://discuss.elastic.co/t/multiple-conf-files-handling-issue-in-logstash/131278
**Category:** Logstash
**Created:** [May 10, 2018, 9:39am UTC](https://discuss.elastic.co/t/multiple-conf-files-handling-issue-in-logstash/131278 "2018-05-10T09:39:01Z")
**Posts on this page:** 13
**Page:** 1

<div class="post-metadata">

### Author: ![Dazith\_Kj](https://avatars.discourse-cdn.com/v4/letter/d/b77776/32.png) [@Dazith\_Kj](https://discuss.elastic.co/u/Dazith_Kj)
#### Post date: [May 10, 2018, 9:39am UTC](https://discuss.elastic.co/t/multiple-conf-files-handling-issue-in-logstash/131278/1 "2018-05-10T09:39:02Z")

</div>

Hi All,

I have the below setup on my logstash config.

File name : **custom.conf**

```
input {
    beats {
        port => "5044"
        ssl => true
        ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
        ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
    }
}

filter
{

grok {
    match => [
      "message",
      "(?<timestamp>\[[0-9]{4}.[0-9]{2}.[0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2}.[0-9]{3}\]) \s*\-\s*%{LOGLEVEL:log-level}\s*\-\s* (?<ip>[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3})\s*\,\s*(?<corid>[[A-Z][a-z][0-9]]{11}|[[0-9][a-z]]{8}-[[0-9][a-z]]{4}-[[0-9][a-z]]{4}-[[0-9][a-z]]{4}-[[0-9][a-z]]{12})\s*\,\s*(?<interface>[a-z]{2}_[A-Z]{3}[0-9]{4}[a-z]{1}|[A-Z]{3}[0-9]{4}-[A-Z]{2}_[A-Z]{4}|[A-Z]{3}[0-9]{4}[a-z]{1}-[A-Z]{2}_[A-Z]{4}|[A-Z]{3}[0-9]{4}-[A-Z]{2}|[A-Z]{3}[0-9]{4}[a-z]{1}-[A-Z]{2}|[A-Z]{3}[0-9]{4}[a-z]{1}|[a-z]{9})\s*\,\s*(?<sequence>[a-z]{2}_[a-z]{2}_[A-Z]{3}[0-9]{4}[a-z]{1}_[a-z]*_[a-z]*|[a-z]{2}_[A-Z]{3}[0-9]{4}_[a-z]*_[a-z]*|[a-z]{2}_[A-Z]{3}[0-9]{4}_[[a-z][A-Z]]*|[a-z]{2}_[A-Z]{3}[0-9]{4}[a-z]{1}-[0-9]{1}|[a-z]{2}_[a-z]{2}_[A-Z]{3}[0-9]{4}[a-z]{1}-[0-9]{1}|[a-z]{2}\_[a-z]{2}_[A-Z]{3}[0-9]{4}[a-z]{1}_[[A-Z][a-z]]*|[a-z]{2}_[A-Z]{3}[0-9]{4}[a-z]{1}|[a-z]{2}_[a-z]{2}_[A-Z]{3}[0-9]{4}[a-z]{1})\s*\,\s*(?<log_point>[0-9]{4})\s*\,\s*%{GREEDYDATA:message_context}"
    ]
  }

}

output {
  elasticsearch {
    hosts => ["192.168.200.42:9200"]
    sniffing => true
    manage_template => false
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
  }
}

```

This is working as expected. I have added a another config file called stackhealth.conf and added the below content for that/

**FIle name :** stackhealth.conf

```
input {
  beats {
    port => 5044
    ssl => true
    ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
    ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
  }
}

filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    syslog_pri { }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
  }
}

output {
  elasticsearch {
    hosts => ["192.168.200.42:9200"]
    sniffing => true
    manage_template => false
    index => "syshealth-index"
    document_type => "%{[@metadata][type]}"
  }
}

```

After I added bother files to the /etc/logstash/conf.d location still it only processes the custom.conf. How to make both works ?

---

<div class="post-metadata">

### Author: ![ventrca](https://avatars.discourse-cdn.com/v4/letter/v/a87d85/32.png) [@ventrca](https://discuss.elastic.co/u/ventrca)
#### Post date: [May 10, 2018, 9:59am UTC](https://discuss.elastic.co/t/multiple-conf-files-handling-issue-in-logstash/131278/2 "2018-05-10T09:59:30Z")

</div>

Multiple pipelines is the answer. [https://www.elastic.co/guide/en/logstash/current/multiple-pipelines.html](https://www.elastic.co/guide/en/logstash/current/multiple-pipelines.html)

For your problem, maybe you are not modifying pipelines.yml?

---

<div class="post-metadata">

### Author: ![Dazith\_Kj](https://avatars.discourse-cdn.com/v4/letter/d/b77776/32.png) [@Dazith\_Kj](https://discuss.elastic.co/u/Dazith_Kj)
#### Post date: [May 10, 2018, 10:18am UTC](https://discuss.elastic.co/t/multiple-conf-files-handling-issue-in-logstash/131278/3 "2018-05-10T10:18:11Z")

</div>

Hi @ventrca.

I am not seeing pipelines.yml in my logstash setup under /etc/logstash/conf.d. Any idea on this ?

---

<div class="post-metadata">

### Author: ![ventrca](https://avatars.discourse-cdn.com/v4/letter/v/a87d85/32.png) [@ventrca](https://discuss.elastic.co/u/ventrca)
#### Post date: [May 10, 2018, 10:30am UTC](https://discuss.elastic.co/t/multiple-conf-files-handling-issue-in-logstash/131278/4 "2018-05-10T10:30:18Z")

</div>

Which version are you using? I have it in logstash/config

---

<div class="post-metadata">

### Author: ![Dazith\_Kj](https://avatars.discourse-cdn.com/v4/letter/d/b77776/32.png) [@Dazith\_Kj](https://discuss.elastic.co/u/Dazith_Kj)
#### Post date: [May 10, 2018, 10:36am UTC](https://discuss.elastic.co/t/multiple-conf-files-handling-issue-in-logstash/131278/5 "2018-05-10T10:36:03Z")

</div>

Below is the log stash version @ventrca

> root@localhost:/opt/logstash/bin# ./logstash -V  
> logstash 2.2.4

I have only two conf files which I have created under /etc/logstash/conf.d

> root@localhost:/etc/logstash/conf.d# ls  
> stackhealth.conf test.conf

---

<div class="post-metadata">

### Author: ![ventrca](https://avatars.discourse-cdn.com/v4/letter/v/a87d85/32.png) [@ventrca](https://discuss.elastic.co/u/ventrca)
#### Post date: [May 10, 2018, 10:37am UTC](https://discuss.elastic.co/t/multiple-conf-files-handling-issue-in-logstash/131278/6 "2018-05-10T10:37:23Z")

</div>

Sorry, I can't help you with this. I'm using the 6.6.2

---

<div class="post-metadata">

### Author: ![Dazith\_Kj](https://avatars.discourse-cdn.com/v4/letter/d/b77776/32.png) [@Dazith\_Kj](https://discuss.elastic.co/u/Dazith_Kj)
#### Post date: [May 10, 2018, 10:40am UTC](https://discuss.elastic.co/t/multiple-conf-files-handling-issue-in-logstash/131278/7 "2018-05-10T10:40:15Z")

</div>

Thanks @ventrca !

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [May 16, 2018, 8:24pm UTC](https://discuss.elastic.co/t/multiple-conf-files-handling-issue-in-logstash/131278/8 "2018-05-16T20:24:09Z")

</div>

> Multiple pipelines is the answer.

The problem is that you can't have two beats input that listen on the same port. Multiple pipelines won't help there.

---

<div class="post-metadata">

### Author: ![Dazith\_Kj](https://avatars.discourse-cdn.com/v4/letter/d/b77776/32.png) [@Dazith\_Kj](https://discuss.elastic.co/u/Dazith_Kj)
#### Post date: [May 17, 2018, 10:53am UTC](https://discuss.elastic.co/t/multiple-conf-files-handling-issue-in-logstash/131278/9 "2018-05-17T10:53:10Z")

</div>

Thanks @magnusbaeck. Is there any other way to satisfy this requirement ?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [May 17, 2018, 1:53pm UTC](https://discuss.elastic.co/t/multiple-conf-files-handling-issue-in-logstash/131278/10 "2018-05-17T13:53:04Z")

</div>

> Is there any other way to satisfy this requirement ?

What requirement? Multiple configuration files?

---

<div class="post-metadata">

### Author: ![Dazith\_Kj](https://avatars.discourse-cdn.com/v4/letter/d/b77776/32.png) [@Dazith\_Kj](https://discuss.elastic.co/u/Dazith_Kj)
#### Post date: [May 17, 2018, 2:57pm UTC](https://discuss.elastic.co/t/multiple-conf-files-handling-issue-in-logstash/131278/11 "2018-05-17T14:57:27Z")

</div>

@magnusbaeck what I need is publish specific data which matches two patterns to two different indexes in ES. If the requirement is not clear please let me know. Ill explain more with a simple example.

---

<div class="post-metadata">

### Author: ![darkmoon](https://avatars.discourse-cdn.com/v4/letter/d/ecd19e/32.png) [@darkmoon](https://discuss.elastic.co/u/darkmoon)
#### Post date: [May 17, 2018, 7:16pm UTC](https://discuss.elastic.co/t/multiple-conf-files-handling-issue-in-logstash/131278/12 "2018-05-17T19:16:24Z")

</div>

Either have your two sources identify them selves (with a custom field, maybe) and use that to route your documents, or you can have two listeners (on different ports) that add the routing data.

You can set a @metadata field with the name of the index you want a document to be indexed to, then use that field in the output block.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 14, 2018, 7:16pm UTC](https://discuss.elastic.co/t/multiple-conf-files-handling-issue-in-logstash/131278/13 "2018-06-14T19:16:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
