# Two pipelines for single filebeat input | ELK version (6.5.4)

**URL:** <https://discuss.elastic.co/t/two-pipelines-for-single-filebeat-input-elk-version-6-5-4/320950>\
**Category:** Elasticsearch\
**Created:** [December 10, 2022, 2:25pm UTC](https://discuss.elastic.co/t/two-pipelines-for-single-filebeat-input-elk-version-6-5-4/320950 "2022-12-10T14:25:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gyrao\_72](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gyrao_72/32/108254_2.png) [@gyrao\_72](https://discuss.elastic.co/u/gyrao_72)\
**Post date:** [December 10, 2022, 2:25pm UTC](https://discuss.elastic.co/t/two-pipelines-for-single-filebeat-input-elk-version-6-5-4/320950/1 "2022-12-10T14:25:04Z")

</div>

I am trying to create multiple pipelines first-pipeline and second-pipeline in logstash listening to beats events from the same port but getting an error saying the address in use for the second pipeline and the reason why I am using two pipelines is that I want _pipeline.workers: 1_ only for selected indexes in which sequence of log matters.  
**ERROR** :

```auto
Pipeline_id:second-pipeline

Plugin: <LogStash::Inputs::Beats host=>"127.0.0.1", port=>5044, id=>"7c07a66c7959c1734f6aead8ca456bc7c3b086aafb7b5bd4882ee45e0f3c9fc5", enable_metric=>true, codec=><LogStash::Codecs::Plain id=>"plain_4d22b75f-e478-4fbc-b5fe-27ae02ac486b", enable_metric=>true, charset=>"UTF-8">, ssl=>false, add_hostname=>true, ssl_verify_mode=>"none", ssl_peer_metadata=>false, include_codec_tag=>true, ssl_handshake_timeout=>10000, tls_min_version=>1, tls_max_version=>1.2, cipher_suites=>["TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384", "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384", "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256", "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256", "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384", "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384", "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256", "TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256"], client_inactivity_timeout=>60, executor_threads=>8>
Error: Address already in use
Exception: Java::JavaNet::BindException
Stack: sun.nio.ch.Net.bind0(Native Method)
sun.nio.ch.Net.bind(sun/nio/ch/Net.java:438)
sun.nio.ch.Net.bind(sun/nio/ch/Net.java:430)
sun.nio.ch.ServerSocketChannelImpl.bind(sun/nio/ch/ServerSocketChannelImpl.java:225)
io.netty.channel.socket.nio.NioServerSocketChannel.doBind(io/netty/channel/socket/nio/NioServerSocketChannel.java:128)
io.netty.channel.AbstractChannel$AbstractUnsafe.bind(io/netty/channel/AbstractChannel.java:558)
io.netty.channel.DefaultChannelPipeline$HeadContext.bind(io/netty/channel/DefaultChannelPipeline.java:1283)
io.netty.channel.AbstractChannelHandlerContext.invokeBind(io/netty/channel/AbstractChannelHandlerContext.java:501)
io.netty.channel.AbstractChannelHandlerContext.bind(io/netty/channel/AbstractChannelHandlerContext.java:486)
io.netty.channel.DefaultChannelPipeline.bind(io/netty/channel/DefaultChannelPipeline.java:989)
io.netty.channel.AbstractChannel.bind(io/netty/channel/AbstractChannel.java:254)
io.netty.bootstrap.AbstractBootstrap$2.run(io/netty/bootstrap/AbstractBootstrap.java:364)
io.netty.util.concurrent.AbstractEventExecutor.safeExecute(io/netty/util/concurrent/AbstractEventExecutor.java:163)
io.netty.util.concurrent.SingleThreadEventExecutor.runAllTasks(io/netty/util/concurrent/SingleThreadEventExecutor.java:403)
io.netty.channel.nio.NioEventLoop.run(io/netty/channel/nio/NioEventLoop.java:463)
io.netty.util.concurrent.SingleThreadEventExecutor$5.run(io/netty/util/concurrent/SingleThreadEventExecutor.java:858)
io.netty.util.concurrent.FastThreadLocalRunnable.run(io/netty/util/concurrent/FastThreadLocalRunnable.java:30)
java.lang.Thread.run(java/lang/Thread.java:750)

```

**pipelines.yml**

```auto
- pipeline.id: first-pipeline
  path.config: "/Users/gyrao/Documents/ELK/logstash-6.5.4/config/pipelines/api-address.config"
  pipeline.batch.size: 1

- pipeline.id: second-pipeline
  path.config: "/Users/gyrao/Documents/ELK/logstash-6.5.4/config/pipelines/my-config.config"
  pipeline.workers: 1
  pipeline.batch.size: 1
  queue.type: persisted
  path.queue: "/Users/gyrao/Documents/ELK/logstash-6.5.4/config/queue"

```

**my-config.config**

```auto
input {
	beats {
		host => "127.0.0.1"
		port => 5044
	}
}
filter {
	
}
output {
	
}

```

**api-address.config**

```auto
input {
	beats {
		host => "127.0.0.1"
		port => 5044
	}
}
filter {
	
}
output {
  
}

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 10, 2022, 3:29pm UTC](https://discuss.elastic.co/t/two-pipelines-for-single-filebeat-input-elk-version-6-5-4/320950/2 "2022-12-10T15:29:17Z")

</div>

You can not have multiple input plugins listening on the same port. What you can do is set up a single dedicated input pipeline that contains the input plugin and the logic required to determine which pipeline that should process the event. This pipeline can then [send vents to one of your pipelines through pipeline-to-pipeline communication](https://www.elastic.co/guide/en/logstash/6.5/pipeline-to-pipeline.html). It seems this feature was Beta in 6.5 so I would recommend you upgrade to at least version 6.8 to ensure you benefit from any early bugfixes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 7, 2023, 3:30pm UTC](https://discuss.elastic.co/t/two-pipelines-for-single-filebeat-input-elk-version-6-5-4/320950/3 "2023-01-07T15:30:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
