# \[solved\] Multiple logstash config file

**URL:** <https://discuss.elastic.co/t/solved-multiple-logstash-config-file/51692>\
**Category:** Logstash\
**Created:** [June 2, 2016, 1:12pm UTC](https://discuss.elastic.co/t/solved-multiple-logstash-config-file/51692 "2016-06-02T13:12:20Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Prateek\_Kshtriya](https://avatars.discourse-cdn.com/v4/letter/p/c37758/32.png) [@Prateek\_Kshtriya](https://discuss.elastic.co/u/Prateek_Kshtriya)\
**Post date:** [June 2, 2016, 1:12pm UTC](https://discuss.elastic.co/t/solved-multiple-logstash-config-file/51692/1 "2016-06-02T13:12:20Z")

</div>

Hi All ,

Please suggest how to use multiple logstash config file at a time on single command line or as a service.

Problem Statement- I have multiple logstash config file(As there is differet data configured in each file) for posting data from different machines in cluster which requires to open as many command line instances as number of config files. So is it possible to run all the config files from single instance or anything similar.

Regards,  
Prateek

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 2, 2016, 1:24pm UTC](https://discuss.elastic.co/t/solved-multiple-logstash-config-file/51692/2 "2016-06-02T13:24:44Z")

</div>

Either put all files in a directory and run Logstash with `-f path/to/directory` or use multiple `-f` options that each point to one of the files.

Keep in mind that Logstash has a single event pipeline and that all Logstash filters, no matter what file they're defined in, apply to all events **unless** you wrap the filters in conditionals that exclude them for e.g. certain message types.

---

<div class="post-metadata">

**Author:** ![Prateek\_Kshtriya](https://avatars.discourse-cdn.com/v4/letter/p/c37758/32.png) [@Prateek\_Kshtriya](https://discuss.elastic.co/u/Prateek_Kshtriya)\
**Post date:** [June 10, 2016, 9:59am UTC](https://discuss.elastic.co/t/solved-multiple-logstash-config-file/51692/3 "2016-06-10T09:59:21Z")

</div>

> [@magnusbaeck](#):
>
> use multiple -f options

Hi ,  
I have tried the option but it is picking up the data from last config file only-

Command- logstash -f Sample1.conf -f Sample2.conf

It is picking the path from Sample2.conf only. Please suggest if I am missing something.

Regards,  
Prateek

---

<div class="post-metadata">

**Author:** ![purbon](https://avatars.discourse-cdn.com/v4/letter/p/edb3f5/32.png) [@purbon](https://discuss.elastic.co/u/purbon)\
**Post date:** [June 10, 2016, 10:22am UTC](https://discuss.elastic.co/t/solved-multiple-logstash-config-file/51692/4 "2016-06-10T10:22:15Z")

</div>

Hi,  
one other thing you can do, is use numbers in your file, something like 1-input-foo.config, 2-filter-bar.conf, etc. This will help you debug the configs more clear in the directory.

---

<div class="post-metadata">

**Author:** ![Prateek\_Kshtriya](https://avatars.discourse-cdn.com/v4/letter/p/c37758/32.png) [@Prateek\_Kshtriya](https://discuss.elastic.co/u/Prateek_Kshtriya)\
**Post date:** [June 10, 2016, 10:37am UTC](https://discuss.elastic.co/t/solved-multiple-logstash-config-file/51692/5 "2016-06-10T10:37:27Z")

</div>

The logstash config files have different names.

Problem statement - When executed from command line (logstash -f 1-input-foo.config -f 2-filter-bar.conf)  
It posts the data for 2-filter-bar.conf only.

Please suggest .

Regards,  
Prateek

---

<div class="post-metadata">

**Author:** ![Prateek\_Kshtriya](https://avatars.discourse-cdn.com/v4/letter/p/c37758/32.png) [@Prateek\_Kshtriya](https://discuss.elastic.co/u/Prateek_Kshtriya)\
**Post date:** [June 10, 2016, 1:47pm UTC](https://discuss.elastic.co/t/solved-multiple-logstash-config-file/51692/6 "2016-06-10T13:47:52Z")

</div>

> [@magnusbaeck](#):
>
> -f path/to/directory

I Have tried the option . Yes it is working to post the data but all the data is getting posted for every index i.e Index 1 & Index2 is having mixed data.  
Please suggest where I am missing.

Regards,  
Prateek

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 13, 2016, 5:47am UTC](https://discuss.elastic.co/t/solved-multiple-logstash-config-file/51692/7 "2016-06-13T05:47:07Z")

</div>

I don't know what's in your files, but keep in mind that Logstash has a single pipeline. All filters and outputs will apply to all input events unless you use conditionals to select how they apply. If you use multiple configuration files they will effectively be concatenated and treated as a single big file.

---

<div class="post-metadata">

**Author:** ![Prateek\_Kshtriya](https://avatars.discourse-cdn.com/v4/letter/p/c37758/32.png) [@Prateek\_Kshtriya](https://discuss.elastic.co/u/Prateek_Kshtriya)\
**Post date:** [June 13, 2016, 5:57am UTC](https://discuss.elastic.co/t/solved-multiple-logstash-config-file/51692/8 "2016-06-13T05:57:29Z")

</div>

Agree, this is what currently happening . All the configs are getting applied to each data.  
So how do I suppose to handle this?

Please suggest ,I want individual logstash config file to read different data and apply the filters & groks etc correspondingly, not combined config setting on each data set.

Regards,  
Prateek

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 13, 2016, 5:59am UTC](https://discuss.elastic.co/t/solved-multiple-logstash-config-file/51692/9 "2016-06-13T05:59:14Z")

</div>

You need to use conditionals to select which filters and outputs to apply to which events. You can e.g. use the `type` field and event tags in your conditionals.

---

<div class="post-metadata">

**Author:** ![Prateek\_Kshtriya](https://avatars.discourse-cdn.com/v4/letter/p/c37758/32.png) [@Prateek\_Kshtriya](https://discuss.elastic.co/u/Prateek_Kshtriya)\
**Post date:** [June 15, 2016, 5:39am UTC](https://discuss.elastic.co/t/solved-multiple-logstash-config-file/51692/10 "2016-06-15T05:39:10Z")

</div>

Thank you for the help.  
I added a tag while doing the file "input" and applied "if" condition for those tags .  
PFB the snippet from logstash config file-  
input {  
file {  
path =\> "BatchData\Batch\_Raw\_Data.csv"  
tags =\> ["batchdata"]  
start\_position =\> "beginning"  
}  
}  
output {  
if "batchdata" in [tags]{  
elasticsearch {  
action =\> "index"  
index =\> "IndexName"  
}  
}}

Regards,  
Prateek

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:52am UTC](https://discuss.elastic.co/t/solved-multiple-logstash-config-file/51692/11 "2017-07-06T04:52:53Z")

</div>


