# Multiple config files as logstash service

**URL:** <https://discuss.elastic.co/t/multiple-config-files-as-logstash-service/84556>\
**Category:** Logstash\
**Created:** [May 4, 2017, 12:34pm UTC](https://discuss.elastic.co/t/multiple-config-files-as-logstash-service/84556 "2017-05-04T12:34:37Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kishore](https://avatars.discourse-cdn.com/v4/letter/k/8edcca/32.png) [@Kishore](https://discuss.elastic.co/u/Kishore)\
**Post date:** [May 4, 2017, 12:34pm UTC](https://discuss.elastic.co/t/multiple-config-files-as-logstash-service/84556/1 "2017-05-04T12:34:37Z")

</div>

I am using logstash 2.1 version, my /etc/logstash/conf.d/ directory consist of multiple configuration like below.

unix-shipper.conf, firewall-shipper.conf, windows-shipper.conf,

When i enabled logstash as service, configuration files are not giving the output as expected, where as when i ran as process separately those are working fine.

Please let me know if we run logstash as service do we need to alter the /etc/init.d/logstash file, if yes what are all the changes?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 4, 2017, 12:46pm UTC](https://discuss.elastic.co/t/multiple-config-files-as-logstash-service/84556/2 "2017-05-04T12:46:57Z")

</div>

Even if you use multiple configuration files they are effectively treated as a single large file. Logstash has a single event pipeline where events from all inputs are passed to all filters and outputs unless you use conditionals to restrict which filters and outputs receive which events.

---

<div class="post-metadata">

**Author:** ![Kishore](https://avatars.discourse-cdn.com/v4/letter/k/8edcca/32.png) [@Kishore](https://discuss.elastic.co/u/Kishore)\
**Post date:** [May 4, 2017, 12:53pm UTC](https://discuss.elastic.co/t/multiple-config-files-as-logstash-service/84556/3 "2017-05-04T12:53:27Z")

</div>

Yes true, but my configuration files are sending output to Redis then Logstash indexer( unix-indexer.conf, windows-indexer.conf).

These are developed to recieve the events based on key value type (these types are different for each log source eg: type:unix, type:windows) .

When i run as service all events are marked as same event type (For example windows, vpn events are going to be marked as unix event type).

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 4, 2017, 1:29pm UTC](https://discuss.elastic.co/t/multiple-config-files-as-logstash-service/84556/4 "2017-05-04T13:29:23Z")

</div>

It'll be much easier if you show your configuration files instead of describing them.

---

<div class="post-metadata">

**Author:** ![Kishore](https://avatars.discourse-cdn.com/v4/letter/k/8edcca/32.png) [@Kishore](https://discuss.elastic.co/u/Kishore)\
**Post date:** [May 4, 2017, 1:47pm UTC](https://discuss.elastic.co/t/multiple-config-files-as-logstash-service/84556/5 "2017-05-04T13:47:12Z")

</div>

My two configurations( One is for shipper and other for Indexer) for each logsource looks like below,  
unix-shipper.conf

```
input
 { file { path => ["/var/log/secure", "/var/log/messages"] type => "unix" } }}
filter {}
output {
redis { host => ["host1:7000", "host1:7001", "host2:7002", "host2:7003", "host3:7004", "host3:7005"]
                        data_type => "list" key => "unix" } }}

```

Unix-Indexer.conf

```
input {
redis { host => "host1" port => "7000" data_type => "list" key => "unix" }
redis { host => "host1" port => "7001" data_type => "list" key => "unix" } 
redis { host => "host2" port => "7002" data_type => "list" key => "unix" }
redis { host => "host2" port => "7003" data_type => "list" key => "unix" }
redis { host => "host3" port => "7004" data_type => "list" key => "unix" }
redis { host => "host3" port => "7005" data_type => "list" key => "unix" }
}

output {
elasticsearch { hosts => ["ESnode1:9200", "ESnode2:9200", "ESnode3:9200"] }
email { } 
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 4, 2017, 2:08pm UTC](https://discuss.elastic.co/t/multiple-config-files-as-logstash-service/84556/6 "2017-05-04T14:08:22Z")

</div>

Right. And having these configuration files is equivalent to this:

```nohighlight
input {
file { path => ["/var/log/secure", "/var/log/messages"] type => "unix" } }
redis { host => "host1" port => "7000" data_type => "list" key => "unix" }
redis { host => "host1" port => "7001" data_type => "list" key => "unix" } 
redis { host => "host2" port => "7002" data_type => "list" key => "unix" }
redis { host => "host2" port => "7003" data_type => "list" key => "unix" }
redis { host => "host3" port => "7004" data_type => "list" key => "unix" }
redis { host => "host3" port => "7005" data_type => "list" key => "unix" }
}
output {
redis { host => ["host1:7000", "host1:7001", "host2:7002", "host2:7003", "host3:7004", "host3:7005"]
                        data_type => "list" key => "unix" } }
elasticsearch { hosts => ["ESnode1:9200", "ESnode2:9200", "ESnode3:9200"] }
email { } 
}

```

So all events from the file and redis will be sent to the redis, elasticsearch, and email outputs. As I said, if this isn't what you want you need to use conditionals. However, in your case I'd run multiple Logstash instances.

---

<div class="post-metadata">

**Author:** ![Kishore](https://avatars.discourse-cdn.com/v4/letter/k/8edcca/32.png) [@Kishore](https://discuss.elastic.co/u/Kishore)\
**Post date:** [May 4, 2017, 2:16pm UTC](https://discuss.elastic.co/t/multiple-config-files-as-logstash-service/84556/7 "2017-05-04T14:16:32Z")

</div>

Magnus,

unix-shipper.conf and unix-indexer.conf files are already at separate servers, all shipper configuration files are getting marked with same type(eg: type:unix even for windows and vpn )

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 4, 2017, 3:22pm UTC](https://discuss.elastic.co/t/multiple-config-files-as-logstash-service/84556/8 "2017-05-04T15:22:06Z")

</div>

And how do Windows and VPN events get into Logstash?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2017, 3:29pm UTC](https://discuss.elastic.co/t/multiple-config-files-as-logstash-service/84556/9 "2017-06-01T15:29:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
