# On the fly Changes in Logstash config file

**URL:** <https://discuss.elastic.co/t/on-the-fly-changes-in-logstash-config-file/43970>\
**Category:** Logstash\
**Created:** [March 10, 2016, 1:50am UTC](https://discuss.elastic.co/t/on-the-fly-changes-in-logstash-config-file/43970 "2016-03-10T01:50:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![gaurav1424](https://avatars.discourse-cdn.com/v4/letter/g/97f17d/32.png) [@gaurav1424](https://discuss.elastic.co/u/gaurav1424)\
**Post date:** [March 10, 2016, 1:50am UTC](https://discuss.elastic.co/t/on-the-fly-changes-in-logstash-config-file/43970/1 "2016-03-10T01:50:55Z")

</div>

Hello All,

I am aware of that logstash 2.2 introduces new pipeline architecture and auto reload option.

I have following question :  
Static modification in Logstash conf file :

I am using environment filter to add some fields in my logstash config file. Its working perfect. I want to have only one logstash config for my production environment. I dont want devops or dev person to be told to start this logstash instance with this config file. There has to be ONLY one config file.  
Now let us say I have 3 ES clusters  
1: [amer.region.company.com](http://amer.region.company.com)  
2: [europe.region.company.com](http://europe.region.company.com)  
3: [asia.region.company.com](http://asia.region.company.com)

How can I change logstash config file before starting logstash so that I can have one of three ES cluster name / IP address inside ES output plugin for logstash.

I have something like this :  
elasticsearch {  
hosts =\> ["[amer.region.company.com:9200](http://amer.region.company.com:9200)"]  
}

Thanks,  
Gaurav

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 10, 2016, 7:07am UTC](https://discuss.elastic.co/t/on-the-fly-changes-in-logstash-config-file/43970/2 "2016-03-10T07:07:29Z")

</div>

Wouldn't this be a good job for the configuration management system you're using?

Since Logstash nowadays supports environment variable references in strings (not just via the environment filter), perhaps you could use that to pick up a cluster hostname.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [March 10, 2016, 3:36pm UTC](https://discuss.elastic.co/t/on-the-fly-changes-in-logstash-config-file/43970/3 "2016-03-10T15:36:59Z")

</div>

BTW, the feature Magnus is referring to was implemented here: [https://github.com/elastic/logstash/pull/4710](https://github.com/elastic/logstash/pull/4710). It will be available in the next Logstash release, 2.3.0.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:07am UTC](https://discuss.elastic.co/t/on-the-fly-changes-in-logstash-config-file/43970/4 "2017-07-06T05:07:30Z")

</div>


