# Multiple logstash conf

**URL:** <https://discuss.elastic.co/t/multiple-logstash-conf/103693>\
**Category:** Logstash\
**Created:** [October 12, 2017, 10:16am UTC](https://discuss.elastic.co/t/multiple-logstash-conf/103693 "2017-10-12T10:16:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ramesh205](https://avatars.discourse-cdn.com/v4/letter/r/5f8ce5/32.png) [@ramesh205](https://discuss.elastic.co/u/ramesh205)\
**Post date:** [October 12, 2017, 10:16am UTC](https://discuss.elastic.co/t/multiple-logstash-conf/103693/1 "2017-10-12T10:16:46Z")

</div>

Hi,  
I created two conf files one to read data from db and store in index(sysjob-index) and another to read data from log file and store in index(jupiterindex3) and i ran both conf file  
bin\>logstash -f logstash\*.conf.  
Problem:We can see db data in jupiterindex3 and log file data in sysjob-index1 in kibana which should be done ideally.  
Please let us what is solution for this.  
logstashSQL.conf:(read data from DB)  
input { jdbc {  
jdbc\_driver\_library =\> "C:\logstash-5.5.2\lib\sql\sqljdbc4-4.0.jar"  
jdbc\_driver\_class =\> "com.microsoft.sqlserver.jdbc.SQLServerDriver"  
jdbc\_connection\_string =\> "jdbc:sqlserver://10.1.4.8:1111;DatabaseName=test1;"  
jdbc\_validate\_connection =\> true  
jdbc\_user =\> "\*\*\*"  
jdbc\_password =\> "\*\*_"  
statement =\> "SELECT \* FROM sysjobhistory where instance\_id \> :sql\_last\_value"  
jdbc\_paging\_enabled =\> "true"  
jdbc\_page\_size =\> "50000"  
schedule =\> "_ \* \* \* \*"  
use\_column\_value =\> true  
tracking\_column =\> "instance\_id"  
tracking\_column\_type =\> "numeric"  
clean\_run =\> true  
last\_run\_metadata\_path =\> "C:\logstash-5.5.2\data.logstash\_jdbc\_last\_run"  
}}  
output { elasticsearch { hosts =\> ["localhost:9200"]  
index =\> "sysjob-index1"  
user =\> "elastic"  
password =\> "test1"  
}}  
logstash.conf(read data from log file):  
input { beats {  
port =\> 5044  
}}  
filter { grok {  
match =\> { "message" =\> "(?%{YEAR}-%{MONTHNUM2}-%{MONTHDAY} %{HOUR}:%{MINUTE}:%{SECOND}) %{LOGLEVEL:loglevel} - 'ApplicationName':%{DATA:ApplicationName}, 'EventStatus':%{DATA:EventStatus}, 'SeverityLevel':%{DATA:SeverityLevel}, 'EventTime':(?%{YEAR}-%{MONTHNUM2}-%{MONTHDAY} %{HOUR}:%{MINUTE}:%{SECOND}), 'ErrorDescription':%{DATA:ErrorDescription} "  
}}}  
output {elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "jupiterindex3"  
user =\> "elastic"  
password =\> "test1"  
}}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 12, 2017, 11:05am UTC](https://discuss.elastic.co/t/multiple-logstash-conf/103693/2 "2017-10-12T11:05:09Z")

</div>

Unless you use the multi pipeline feature in Logstash 6 there is a single event pipeline. All events from all inputs will reach all outputs. If you don't want that you need to add conditionals.

---

<div class="post-metadata">

**Author:** ![ramesh205](https://avatars.discourse-cdn.com/v4/letter/r/5f8ce5/32.png) [@ramesh205](https://discuss.elastic.co/u/ramesh205)\
**Post date:** [October 12, 2017, 11:11am UTC](https://discuss.elastic.co/t/multiple-logstash-conf/103693/3 "2017-10-12T11:11:15Z")

</div>

> [@magnusbaeck](#):
>
> ou use the multi pipeline feature in Logstash 6 there is a single event pipeline. All events from all inputs will reach all outputs. If you don't want that you need to add conditionals.

Hi magnus,i read ur previous blog and understand what u suggest above.  
my doubt is which one is correct.  
1.input {  
type=\>beats  
beats {  
port =\> 5044  
}}

```
or

```

2.input {  
beats {  
port =\> 5044  
type=\>beats  
}}

And i am not able to get where i need to give condition weather after output{ or elastic{

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 12, 2017, 11:36am UTC](https://discuss.elastic.co/t/multiple-logstash-conf/103693/4 "2017-10-12T11:36:25Z")

</div>

> 2.input {  
> beats {  
> port =\> 5044  
> type=\>beats  
> }}

This is correct.

> And i am not able to get where i need to give condition weather after output{ or elastic{

After output {.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2017, 11:36am UTC](https://discuss.elastic.co/t/multiple-logstash-conf/103693/5 "2017-11-09T11:36:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
