# Several config files for beats in logstash

**URL:** <https://discuss.elastic.co/t/several-config-files-for-beats-in-logstash/47749>\
**Category:** Logstash\
**Created:** [April 19, 2016, 6:15am UTC](https://discuss.elastic.co/t/several-config-files-for-beats-in-logstash/47749 "2016-04-19T06:15:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Adir](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@Adir](https://discuss.elastic.co/u/Adir)\
**Post date:** [April 19, 2016, 6:15am UTC](https://discuss.elastic.co/t/several-config-files-for-beats-in-logstash/47749/1 "2016-04-19T06:15:09Z")

</div>

Hi,  
We just started to work with logstash recently and i have a few questions about beats config files.

We currently have 2 configuration files on our logstash - one for filebeat and another one for winlogbeat .  
Each config file configured to listen on different port (5044/5045) and configured to write to different index in elasticsearch.  
It seems that every message is being processed by these two config files and all the messages, both from winlogbeat and filebeat, are being written to these 2 indices.

should it work this way? When logstash gets messages from beats application it's processing it in all the config files with beats input logstash has?

Our logstash version is 2.3.1 and these are the config files:

config1(winglogbeat):

input {  
beats {  
port =\> 5044  
}  
}

filter {  
if [type] == "wineventlog" and [source\_name] != "Test" {  
drop { }  
}  
}

output {  
elasticsearch {  
hosts =\> "SERVER\_IP"  
manage\_template =\> false  
index =\> "winlogbeat-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

config2(filesbeat):  
input {  
beats {  
port =\> 5045  
}  
}

filter {  
grok {  
match =\> { "message" =\> "%{DATESTAMP:date} %{WORD:timezone}] %{GREEDYDATA:data}" }  
}  
date {  
match =\> ["date", "MM/dd/YY HH:mm:ss:SSS"]  
}  
}

output {  
elasticsearch {  
hosts =\> "SERVER\_IP"  
manage\_template =\> false  
index =\> "filebeat-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 19, 2016, 6:27am UTC](https://discuss.elastic.co/t/several-config-files-for-beats-in-logstash/47749/2 "2016-04-19T06:27:09Z")

</div>

This is expected. Logstash has a single event pipeline even if you split your configuration into multiple files. If you don't want all filters and output to apply to all events I suggest you use conditionals (e.g. based on the `type` field).

---

<div class="post-metadata">

**Author:** ![Adir](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@Adir](https://discuss.elastic.co/u/Adir)\
**Post date:** [April 19, 2016, 7:12am UTC](https://discuss.elastic.co/t/several-config-files-for-beats-in-logstash/47749/3 "2016-04-19T07:12:08Z")

</div>

> [@magnusbaeck](#):
>
> This is expected. Logstash has a single event pipeline even if you split your configuration into multiple files. If you don't want all filters and output to apply to all events I suggest you use conditionals (e.g. based on the type field).

OK.  
So, it should work as i expect if i'll delete output section on the files i mentioned and create new config file named beats\_output.conf with this:

output {  
if [type] == "wineventlog"  
{  
elasticsearch {  
hosts =\> "SERVER\_IP"  
manage\_template =\> false  
index =\> "winlogbeat-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

if [type] == "OTHERFILEBEAT"  
{  
elasticsearch {  
hosts =\> "SERVER\_IP"  
manage\_template =\> false  
index =\> "filebeat-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}  
}

correct?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 19, 2016, 8:27am UTC](https://discuss.elastic.co/t/several-config-files-for-beats-in-logstash/47749/4 "2016-04-19T08:27:06Z")

</div>

Yes, although you probably want to use the same conditionals for your filters.

---

<div class="post-metadata">

**Author:** ![Adir](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@Adir](https://discuss.elastic.co/u/Adir)\
**Post date:** [April 19, 2016, 1:13pm UTC](https://discuss.elastic.co/t/several-config-files-for-beats-in-logstash/47749/5 "2016-04-19T13:13:03Z")

</div>

Thanks! it works 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:01am UTC](https://discuss.elastic.co/t/several-config-files-for-beats-in-logstash/47749/6 "2017-07-06T05:01:35Z")

</div>


