# New to Logstash Filter Config file questions

**URL:** <https://discuss.elastic.co/t/new-to-logstash-filter-config-file-questions/198969>\
**Category:** Logstash\
**Created:** [September 10, 2019, 8:05pm UTC](https://discuss.elastic.co/t/new-to-logstash-filter-config-file-questions/198969 "2019-09-10T20:05:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![fastxl](https://avatars.discourse-cdn.com/v4/letter/f/85e7bf/32.png) [@fastxl](https://discuss.elastic.co/u/fastxl)\
**Post date:** [September 10, 2019, 8:05pm UTC](https://discuss.elastic.co/t/new-to-logstash-filter-config-file-questions/198969/1 "2019-09-10T20:05:49Z")

</div>

I am new to ELK and trying to learn. I have setup a "Lab" that has my pfSense firewall sending logs to Logstash. The "how-tos" I followed for this had me create 4 different files, 01-inputs.conf, 10-syslog.conf, 11-pfsense.conf and 30-outputs.conf. I would like to add winlogbeats to my config so I added the beats to my 01-input.conf.

```
#tcp syslog stream via 5140
input {
  tcp {
    type => "syslog"
    port => 5140
  }
}
#udp syslogs stream via 5140
input {
  udp {
    type => "syslog"
    port => 5140
  }
}
#beats 5044
input {
  beats {
    port => 5044
    tags => ["winlogbeat"]
  }
}

```

Do I create another file (say called 11-winlogbeats.conf) for my filter for winlogbeats? I see in most of the winlogbeat "how-tos" that the config is all in one file. I guess I am a little lost on the different files for each config.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 10, 2019, 9:20pm UTC](https://discuss.elastic.co/t/new-to-logstash-filter-config-file-questions/198969/2 "2019-09-10T21:20:09Z")

</div>

If you point path.config to a directory (or a wild card filename) logstash concatenates all of the files into a single configuration. How you divide your configuration across different files is really a matter of personal taste.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 8, 2019, 9:20pm UTC](https://discuss.elastic.co/t/new-to-logstash-filter-config-file-questions/198969/3 "2019-10-08T21:20:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
