# Running multiple endpoints on the same node

**URL:** <https://discuss.elastic.co/t/running-multiple-endpoints-on-the-same-node/127952>\
**Category:** Logstash\
**Created:** [April 13, 2018, 10:22am UTC](https://discuss.elastic.co/t/running-multiple-endpoints-on-the-same-node/127952 "2018-04-13T10:22:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ant/32/33267_2.png) [@Ant](https://discuss.elastic.co/u/Ant)\
**Post date:** [April 13, 2018, 10:22am UTC](https://discuss.elastic.co/t/running-multiple-endpoints-on-the-same-node/127952/1 "2018-04-13T10:22:52Z")

</div>

Big picture I want to run atleast 2 nodes, put a load balancer on the front of them and have the requests fire in across the nodes, not sure if there is anything clever I have to do to ensure what I belive is called atleast-once-delivery but that hurdle is a little down the way for me.

I'm just to get it runing or the moment with just the one node on a proof on concept basis.

I've got logstash setup (5.6.6 so it matches my elastic version) on a VM. On that VM in the `/etc/logstash/conf.d/` I've created 2 configs for end points, these are:

```auto
 input {
 tcp {
     port => 6000
     type => syslog
   }
 udp
  {
     port => 6000
     type => syslog
   }
 
  }
 output {
   elasticsearch {
      hosts => ["192.168.100.4:9200"]
      user => "logstashuser"
      password => "password"
      index => "test_b-%{+YYYY.MM.dd}"
      document_type => "b_request"
   }
 }

```

and

```auto
 input {
 tcp {
     port => 5000
     type => syslog
   }
 udp
  {
     port => 5000
     type => syslog
   }
 
  }
 output {
   elasticsearch {
      hosts => ["192.168.100.4:9200"]
      user => "logstashuser"
      password => "password"
      index => "test_a-%{+YYYY.MM.dd}"
      document_type => "a_request"
   }
 }

```

I've then started logstash as a service

In keeping with some guideance I found I've connected to the logstash box with telnet, one client on port 5000 the other 6000

In elastic I've got 2 new indexes of test\_a-2018.04.13 & test\_b-2018.04.13

I've typed data in to one but not the other but the document count goes up for both, this happens regardless of which I try to interact with.

I've deleted the indexes for both and entered a single line to each and that line gets sent to both indexes. The behavior I'm expecting though is that the traffic sent to port 5000 only appear for test a and the traffic for port 6000 appear for test b

`type => syslog` was on an example I found online so I just coppied and pasted that  
`document_type => "a_request"` & `document_type => "a_request"` were based on a post I found for posting to indexes other than `logstash-[date]` where they used `my_request` without the document type I found nothing was posted to the index and I used different made up documents for each but there are no definitions created for either so I'm of the understaning elastic will auto generate a definition on the first request.

any assistance greatfully recieved

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 13, 2018, 11:05am UTC](https://discuss.elastic.co/t/running-multiple-endpoints-on-the-same-node/127952/2 "2018-04-13T11:05:16Z")

</div>

Logstash reads all configuration files in /etc/logstash/conf.d and concatenates them. Therefore you're effectively loading Logstash with two tcp inputs, two udp inputs, and two elasticsearch outputs. If you're going to run two instances of Logstash you're going to want to have two directories with config files.

---

<div class="post-metadata">

**Author:** ![Ant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ant/32/33267_2.png) [@Ant](https://discuss.elastic.co/u/Ant)\
**Post date:** [April 13, 2018, 12:04pm UTC](https://discuss.elastic.co/t/running-multiple-endpoints-on-the-same-node/127952/3 "2018-04-13T12:04:44Z")

</div>

Thanks Magnus that makes sense with what I'm seeing then, I've treid creating  
`/etc/logstash/conf.d/configa/endpoint5000.conf` and `/etc/logstash/conf.d/configb/endpoint6000.conf` but that didn't work, treid adding both as path.config entired in the `logstash.yml` but that didn't help either. I've found reference to a `pipeline.yml` file but I can't see where it is. do you have any information on how I go about creating multiple directories and getting logstash to recognise them as such?

also to reiterate I'm running 5.6.6 incase that is of relivence

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 13, 2018, 7:54pm UTC](https://discuss.elastic.co/t/running-multiple-endpoints-on-the-same-node/127952/4 "2018-04-13T19:54:39Z")

</div>

Multiple pipelines in a single Logstash instance requires 6.0, but I suppose the whole point of the exercise is to run multiple instances.

> treid adding both as path.config entired in the logstash.yml

What do you mean? Please don't describe what you're doing when concrete and unambiguous examples are possible.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2018, 7:54pm UTC](https://discuss.elastic.co/t/running-multiple-endpoints-on-the-same-node/127952/5 "2018-05-11T19:54:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
