# About repeating parameters when using if/else conditions

**URL:** <https://discuss.elastic.co/t/about-repeating-parameters-when-using-if-else-conditions/289448>\
**Category:** Logstash\
**Created:** [November 17, 2021, 12:27pm UTC](https://discuss.elastic.co/t/about-repeating-parameters-when-using-if-else-conditions/289448 "2021-11-17T12:27:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![espala](https://avatars.discourse-cdn.com/v4/letter/e/c89c15/32.png) [@espala](https://discuss.elastic.co/u/espala)\
**Post date:** [November 17, 2021, 12:27pm UTC](https://discuss.elastic.co/t/about-repeating-parameters-when-using-if-else-conditions/289448/1 "2021-11-17T12:27:45Z")

</div>

Hello there,

I'm using the config I've added as "original" below on my logstash server. My configuration works fine.

my purpose;  
I have a lot of servers and I collect the general system logs of all of them on elk. I installed filebeat on each client server, I set the log settings and add their hostnames as tags.

I create an index specifically for each server hostname. For each of my servers, I use if/else patterns over and over. Unfortunately I have to.

my problem;  
In every if/else pattern, I am constantly writing other parameters along with the index value. In fact, I aim to do this with less effort and without repeating the same settings.

so I don't want to type parameters like "host", "user", "password" over and over. I want to put the "index" parameter, which can change constantly, into the if/else pattern. I put the if/else sections two columns forward, two columns back, tried all combinations.

* * *

For example, when I run the following configuration, I get an error (below). I may be blinded by spending so much time on the case. I may be missing something very simple. Does anyone have any advice on this?

## test config;

```auto
...

output {
  elasticsearch {
    hosts => ["https://elk.domain.com:9200"]
    manage_template => false
    user => "loguser"
    password => "password"

  if "server1" in [tags] {
    index => "server1-logs-%{+yyyy.MM.dd}"
  }

  if "server2" in [tags] {
    index => "server2-logs-%{+yyyy.MM.dd}"
  }

...
...
...

  else {
    index => "noindex-%{+yyyy.MM.dd}"
  }

  }  
}

```

Error messages;  
`Nov 17 10:33:58 elk-server logstash[19301]: [2021-11-17T10:33:58,092][ERROR][logstash.agent] Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of [\\t\\r\\n], \"#\", \"=>\" at line 24, column 6 (byte 760) after output {\n elasticsearch {\n\n if ", :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile\_imperative'", "org/logstash/execution/AbstractPipelineExt.java:184:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:69:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:52:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:389:in `block in converge_state'"]}`

## original config;

```auto
input {
  beats {
    port => 5044
  }
}

filter {
  if [input][type] == "log" {
    mutate {
      "remove_field" => ['[meta][cloud][availability_zone]','[meta][cloud][instance_id]','[meta][cloud][instance_name]','[meta][cloud][machine_type]','[meta][cloud][project_id]','[meta][cloud][provider]','source','[host][os][codename]','[host][os][family]','[host][os][name]','[host][os][platform]','[host][os][version]','[host][architecture]','[host][containerized]','[beat][hostname]','[beat][timezone]','[beat][version]','[beat][name]','[prospector][type]','[offset]','[host][id]','[error][message]','[event][dataset]','[fileset][name]', '[@version]' ]
      "remove_tag" => ["beats_input_codec_plain_applied"]
    }
  }
}

output {

  if "server1" in [tags] {
    elasticsearch {
      hosts => ["https://elk.domain.com:9200"]
      index => "server1-logs-%{+yyyy.MM.dd}"
      manage_template => false
      user => "loguser"
      password => "password"
    }
  }
  elseif "server2" in [tags] {
    elasticsearch {
      hosts => ["https://elk.domain.com:9200"]
      index => "server2-logs-%{+yyyy.MM.dd}"
      manage_template => false
      user => "loguser"
      password => "password"
    }
  }

...
...
...

  else {
    elasticsearch {
      hosts => ["https://elk.domain.com:9200"]
      index => "noindex-%{+yyyy.MM.dd}"
      manage_template => false
      user => "loguser"
      password => "password"
    }
  }

}

```

---

<div class="post-metadata">

**Author:** ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)\
**Post date:** [November 17, 2021, 12:53pm UTC](https://discuss.elastic.co/t/about-repeating-parameters-when-using-if-else-conditions/289448/2 "2021-11-17T12:53:26Z")

</div>

Since filebeat includes the name of the server in the `host.name` field (iirc) you can put the server name field in the index output.

This will save you a lot of if statements 🙂

```auto
elasticsearch {
      hosts => ["https://elk.domain.com:9200"]
      index => "%{[host][name]}-logs-%{+yyyy.MM.dd}"
      manage_template => false
      user => "loguser"
      password => "password"
    }

```

EDIT: FIXED %{host.name} to %{[host][name]}

---

<div class="post-metadata">

**Author:** ![espala](https://avatars.discourse-cdn.com/v4/letter/e/c89c15/32.png) [@espala](https://discuss.elastic.co/u/espala)\
**Post date:** [November 18, 2021, 9:46am UTC](https://discuss.elastic.co/t/about-repeating-parameters-when-using-if-else-conditions/289448/3 "2021-11-18T09:46:00Z")

</div>

First of, thank you for your answer and interest.

Actually I'm tried this but failed. Unfortunately I must to create a noindex with an if/else in all cases. But now I tried without if/else, it seems to fail.

Actually, I don't delete this field with "remove\_tag", it should find it. I could not find information about same standard environment variables in the articles. I also define node name in filebeat config.

I tried the config you sent. It creates an index directly with the name "%{host.name}-logs-..." 🙂

 ![Screen Shot 2021-11-18 at 12.24.03](https://us1.discourse-cdn.com/elastic/original/3X/8/a/8a1c02d8bbe9ab88162d11dcc12b793d1a5165ff.png)

The config I tried to do with if/else before;

```auto
output {
# I tried "host.name" and "tags" fields. and I also used "==" statements, replacing "in" with strings. I also changed the strings.

  if %{host.name} in [host][name] {  
    elasticsearch {
      hosts => ["https://elk.domain.com:9200"]
      index => "%{host.name}-logs-%{+yyyy.MM.dd}"
      manage_template => false
      user => "loguser"
      password => "password"
    }
  }

  elseif {
    elasticsearch {
      hosts => ["https://elk.domain.com:9200"]
      index => "noindexes-%{+yyyy.MM.dd}"
      manage_template => false
      user => "loguser"
      password => "password"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 18, 2021, 3:16pm UTC](https://discuss.elastic.co/t/about-repeating-parameters-when-using-if-else-conditions/289448/4 "2021-11-18T15:16:46Z")

</div>

> [@espala](#):
>
> `index => "%{host.name}-logs-%{+yyyy.MM.dd}"`

That refers to a field that has a stop in its name. If [host] is an object that contains a [name] field then this should be `index => "%{[host][name]}-logs-%{+yyyy.MM.dd}"`

---

<div class="post-metadata">

**Author:** ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)\
**Post date:** [November 18, 2021, 5:04pm UTC](https://discuss.elastic.co/t/about-repeating-parameters-when-using-if-else-conditions/289448/5 "2021-11-18T17:04:44Z")

</div>

Yep! My bad. @espala Badgers correction should work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 16, 2021, 5:04pm UTC](https://discuss.elastic.co/t/about-repeating-parameters-when-using-if-else-conditions/289448/6 "2021-12-16T17:04:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
