# Why collect the same log when I set different port?

**URL:** <https://discuss.elastic.co/t/why-collect-the-same-log-when-i-set-different-port/258211>\
**Category:** Logstash\
**Created:** [December 10, 2020, 2:55am UTC](https://discuss.elastic.co/t/why-collect-the-same-log-when-i-set-different-port/258211 "2020-12-10T02:55:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![111418](https://avatars.discourse-cdn.com/v4/letter/1/258eb7/32.png) [@111418](https://discuss.elastic.co/u/111418)\
**Post date:** [December 10, 2020, 2:55am UTC](https://discuss.elastic.co/t/why-collect-the-same-log-when-i-set-different-port/258211/1 "2020-12-10T02:55:07Z")

</div>

I have two conf file in /etc/logstash/conf.d/.  
One is named "nas\_ftp.conf" and include below setting:```

```auto
input {
     tcp {
       port => 10515
     }
   }

   filter { }
   output {
     elasticsearch {
       hosts => ["IP:9200"]
       index => "nas_ftp_log_%{+YYYY.MM.dd}"
     }
   }

```

and the other one is named "ftp\_log.conf" and include :

```auto
input {
  tcp {
    port => 10514
  }
}

filter { }

output {
  elasticsearch {
    hosts => ["IP:9200"]
    index => "ftp_log_%{+YYYY.MM.dd}"
  }
}

```

Why I collect the same log in differents index and ports?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 10, 2020, 3:12am UTC](https://discuss.elastic.co/t/why-collect-the-same-log-when-i-set-different-port/258211/2 "2020-12-10T03:12:25Z")

</div>

Does [this](https://discuss.elastic.co/t/adding-field-creates-an-array-not-a-static-string/258149/5) post help?

---

<div class="post-metadata">

**Author:** ![111418](https://avatars.discourse-cdn.com/v4/letter/1/258eb7/32.png) [@111418](https://discuss.elastic.co/u/111418)\
**Post date:** [December 10, 2020, 6:48am UTC](https://discuss.elastic.co/t/why-collect-the-same-log-when-i-set-different-port/258211/3 "2020-12-10T06:48:21Z")

</div>

hi, I see your post.  
Then I combined my conf file and name "ftp\_log.conf " like this:

```auto
input {
  tcp {
    port => 10514
  }
  tcp {
    port => 10515
  }
}

filter { }

output {
 if[port]==10514{
  elasticsearch {
    hosts => ["10.190.253.47:9200"]
    index => "ftp_log_%{+YYYY.MM.dd}"
  }
  }
   if[port]==10515{
  elasticsearch {
    hosts => ["10.190.253.47:9200"]
    index => "nas_ftp_log_%{+YYYY.MM.dd}"
  }
  }
}

```

But I got error

```auto
[2020-12-10T14:36:57,682][INFO][logstash.config.source.local.configpathloader] No config files found in path {:path=>"/etc/logstash/conf.d/syslog.conf"}
[2020-12-10T14:36:57,689][ERROR][logstash.config.sourceloader] No configuration found in the configured sources.

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 10, 2020, 4:29pm UTC](https://discuss.elastic.co/t/why-collect-the-same-log-when-i-set-different-port/258211/4 "2020-12-10T16:29:08Z")

</div>

It is telling you that /etc/logstash/conf.d/syslog.conf does not exist.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 7, 2021, 4:29pm UTC](https://discuss.elastic.co/t/why-collect-the-same-log-when-i-set-different-port/258211/5 "2021-01-07T16:29:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
