# Unable to receive logs from multiple data sources

**URL:** <https://discuss.elastic.co/t/unable-to-receive-logs-from-multiple-data-sources/180463>\
**Category:** Logstash\
**Created:** [May 10, 2019, 1:03am UTC](https://discuss.elastic.co/t/unable-to-receive-logs-from-multiple-data-sources/180463 "2019-05-10T01:03:52Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ThorntonStasher](https://avatars.discourse-cdn.com/v4/letter/t/e9bcb4/32.png) [@ThorntonStasher](https://discuss.elastic.co/u/ThorntonStasher)\
**Post date:** [May 10, 2019, 1:03am UTC](https://discuss.elastic.co/t/unable-to-receive-logs-from-multiple-data-sources/180463/1 "2019-05-10T01:03:52Z")

</div>

I'm trying to get Logstash to receive logs from multiple servers. My attempt at configuring that failed. The UDP input plugin requires a string but I don't know how to implement that. I get the following error with the code shown below:

input {  
udp {  
port =\> 514  
host =\> ["10.0.0.4", "10.0.0.6", "10.0.0.7", "10.0.0.8", "10.0.0.2"]  
tags =\> ["AuditTrail"]  
}  
}

output {stdout {}}

////////////////////////////////////////

Error:  
input {  
udp {

# This setting must be a string

# Expected string, got ["10.0.0.4", "10.0.0.6", "10.0.0.7", "10.0.0.8", "10.0.0.2"]

host =\> ["10.0.0.4", "10.0.0.6", "10.0.0.7", "10.0.0.8", "10.0.0.2"]  
...  
}  
}  
[2019-05-10T00:58:26,277][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Something is wrong with your configuration.", :backtrace=\>["/home/xxxxx/DOWNLOADS/LOGSTASH/logstash-7.0.0/logstash-core/lib/logstash/config/mixin.rb:86:in config\_init'", "/home/xxxxx/DOWNLOADS/LOGSTASH/logstash-7.0.0/logstash-core/lib/logstash/inputs/base.rb:60:ininitialize'", "/home/xxxxx/DOWNLOADS/LOGSTASH/logstash-7.0.0/vendor/bundle/jruby/2.5.0/gems/logstash-input-udp-3.3.4/lib/logstash/inputs/udp.rb:45:in initialize'", "org/logstash/plugins/PluginFactoryExt.java:255:inplugin'", "org/logstash/plugins/PluginFactoryExt.java:117:in buildInput'", "org/logstash/execution/JavaBasePipelineExt.java:50:ininitialize'", "/home/xxxxx/DOWNLOADS/LOGSTASH/logstash-7.0.0/logstash-core/lib/logstash/java\_pipeline.rb:23:in initialize'", "/home/xxxxx/DOWNLOADS/LOGSTASH/logstash-7.0.0/logstash-core/lib/logstash/pipeline\_action/create.rb:36:inexecute'", "/home/xxxxx/DOWNLOADS/LOGSTASH/logstash-7.0.0/logstash-core/lib/logstash/agent.rb:325:in `block in converge\_state'"]}  
[2019-05-10T00:58:26,521][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2019-05-10T00:58:31,589][INFO][logstash.runner] Logstash shut down.  
-sh-4.2$

---

<div class="post-metadata">

**Author:** ![rcrc](https://avatars.discourse-cdn.com/v4/letter/r/ac91a4/32.png) [@rcrc](https://discuss.elastic.co/u/rcrc)\
**Post date:** [May 10, 2019, 2:00am UTC](https://discuss.elastic.co/t/unable-to-receive-logs-from-multiple-data-sources/180463/2 "2019-05-10T02:00:52Z")

</div>

It should be a string. What you provide is an array.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 10, 2019, 12:43pm UTC](https://discuss.elastic.co/t/unable-to-receive-logs-from-multiple-data-sources/180463/3 "2019-05-10T12:43:58Z")

</div>

The host option sets the address on which the udp input should listen on. It does not limit the set of hosts that can write to the input.

---

<div class="post-metadata">

**Author:** ![ThorntonStasher](https://avatars.discourse-cdn.com/v4/letter/t/e9bcb4/32.png) [@ThorntonStasher](https://discuss.elastic.co/u/ThorntonStasher)\
**Post date:** [May 10, 2019, 3:23pm UTC](https://discuss.elastic.co/t/unable-to-receive-logs-from-multiple-data-sources/180463/4 "2019-05-10T15:23:45Z")

</div>

What is the proper syntax for adding multiple host if there is no limit for the set hosts?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 10, 2019, 3:44pm UTC](https://discuss.elastic.co/t/unable-to-receive-logs-from-multiple-data-sources/180463/5 "2019-05-10T15:44:40Z")

</div>

I do not think there is any way to give it a list of IP addresses to listen on unless you have shorthand like "0.0.0.0" (which is the default).

---

<div class="post-metadata">

**Author:** ![ThorntonStasher](https://avatars.discourse-cdn.com/v4/letter/t/e9bcb4/32.png) [@ThorntonStasher](https://discuss.elastic.co/u/ThorntonStasher)\
**Post date:** [May 10, 2019, 3:59pm UTC](https://discuss.elastic.co/t/unable-to-receive-logs-from-multiple-data-sources/180463/6 "2019-05-10T15:59:19Z")

</div>

that is a great point. I started with 0.0.0.0 initially but then wanted to lock it down to just one IP. It's probably frowned upon to have the IP as 0.0.0.0 though. Do I need to add separate pipelines to each server that sends to logstash?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 10, 2019, 4:21pm UTC](https://discuss.elastic.co/t/unable-to-receive-logs-from-multiple-data-sources/180463/7 "2019-05-10T16:21:26Z")

</div>

> [@ThorntonStasher](#):
>
> It's probably frowned upon to have the IP as 0.0.0.0 though. Do I need to add separate pipelines to each server that sends to logstash?

I wouldn't say it is frowned upon, it is the default, after all.

You should not need separate pipelines for each sending server.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2019, 4:21pm UTC](https://discuss.elastic.co/t/unable-to-receive-logs-from-multiple-data-sources/180463/8 "2019-06-07T16:21:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
