# Best way to configure multiple output block

**URL:** <https://discuss.elastic.co/t/best-way-to-configure-multiple-output-block/231269>\
**Category:** Logstash\
**Created:** [May 6, 2020, 6:04am UTC](https://discuss.elastic.co/t/best-way-to-configure-multiple-output-block/231269 "2020-05-06T06:04:14Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![yj\_h](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yj_h/32/67685_2.png) [@yj\_h](https://discuss.elastic.co/u/yj_h)\
**Post date:** [May 6, 2020, 6:04am UTC](https://discuss.elastic.co/t/best-way-to-configure-multiple-output-block/231269/1 "2020-05-06T06:04:15Z")

</div>

My question is best way to configure multiple output block .

in my case.

```auto
input { beat => {}}
filter {
if [type] {}
else if [type] {}
else if [type] {}
else [type] {}
}
output {
if [type] {}
else if [type] {}
else if [type] {}
else {}
}

```

single input, multiple filter and multiple output.  
The reason that I did not configure separate pipeline is I don't want to make many worker.  
so I wrote as above configuration in one pipeline.

And I met error..

```auto
[ERROR][org.logstash.execution.WorkerLoop][main] Exception in pipelineworker, the pipeline stopped processing new events, please check your filter configuration and restart Logstash.
org.jruby.exceptions.SystemCallError: (SystemCallError) Unknown error (SystemCallError) - <STDOUT>
        at org.jruby.RubyIO.write(org/jruby/RubyIO.java:1477) ~[jruby-complete-9.2.9.0.jar:?]
        at org.jruby.RubyIO.write(org/jruby/RubyIO.java:1432) ~[jruby-complete-9.2.9.0.jar:?]
        at usr.share.logstash.vendor.bundle.jruby.$2_dot_5_dot_0.gems.logstash_minus_output_minus_stdout_minus_3_dot_1_dot_4.lib.logstash.outputs.stdout.multi_receive_encoded(/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-stdout-3.1.4/lib/logstash/outputs/stdout.rb:43) ~[?:?]
        at org.jruby.RubyArray.each(org/jruby/RubyArray.java:1814) ~[jruby-complete-9.2.9.0.jar:?]
        at usr.share.logstash.vendor.bundle.jruby.$2_dot_5_dot_0.gems.logstash_minus_output_minus_stdout_minus_3_dot_1_dot_4.lib.logstash.outputs.stdout.multi_receive_encoded(/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-stdout-3.1.4/lib/logstash/outputs/stdout.rb:42) ~[?:?]
        at usr.share.logstash.logstash_minus_core.lib.logstash.outputs.base.multi_receive(/usr/share/logstash/logstash-core/lib/logstash/outputs/base.rb:87) ~[?:?]
        at org.logstash.config.ir.compiler.OutputStrategyExt$AbstractOutputStrategyExt.multi_receive(org/logstash/config/ir/compiler/OutputStrategyExt.java:118) ~[logstash-core.jar:?]
        at org.logstash.config.ir.compiler.AbstractOutputDelegatorExt.multi_receive(org/logstash/config/ir/compiler/AbstractOutputDelegatorExt.java:101) ~[logstash-core.jar:?]
        at usr.share.logstash.logstash_minus_core.lib.logstash.java_pipeline.start_workers(/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:262) ~[?:?]

```

I think this Error means that to make workers it lack the number of cores.

so.. what is the best way to configure logstash setting in my case ?

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 6, 2020, 11:44am UTC](https://discuss.elastic.co/t/best-way-to-configure-multiple-output-block/231269/2 "2020-05-06T11:44:02Z")

</div>

your last `else` shouldn’t contain any expression as it’s designed to capture anything else. if you want to use expression there, you should change that to `else if`

also, i assume the types are defined in the inputs ?

---

<div class="post-metadata">

**Author:** ![yj\_h](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yj_h/32/67685_2.png) [@yj\_h](https://discuss.elastic.co/u/yj_h)\
**Post date:** [May 6, 2020, 12:39pm UTC](https://discuss.elastic.co/t/best-way-to-configure-multiple-output-block/231269/3 "2020-05-06T12:39:14Z")

</div>

thank you for replying

I wrote wrongly doing explain my case by mistake.  
I fixed my question. thank you

yes, types are defined in the inputs.  
input received filebeat.  
And I set in filebeat config file

```auto
- type: log
  enable: true
  paths:
    - /var/log/*.log
  fields:
    document_type: type_A

```

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 6, 2020, 1:41pm UTC](https://discuss.elastic.co/t/best-way-to-configure-multiple-output-block/231269/4 "2020-05-06T13:41:23Z")

</div>

I hope you're not mixing [filebeat input types](https://www.elastic.co/guide/en/beats/filebeat/master/configuration-filebeat-options.html) with a field [type] in your logstash configuration.

using your filebeat configuration above shouldn't your logstash filter be:

```auto
filter {
 if "document_type" == "type_A" { your filter here }
 else if "document_type" == "type_B" {your filter here} 
}

```

similarly on your output

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [May 6, 2020, 2:37pm UTC](https://discuss.elastic.co/t/best-way-to-configure-multiple-output-block/231269/5 "2020-05-06T14:37:05Z")

</div>

Hi @yj_h,

are all those outputs Elasticsearch with just different `index` names or are the outputs a mix of different output types?

If they are all Elasticsearch outputs and you are only changing `index` you might be able to leverage @metadata fields instead of conditionals.

My Elasticsearch output looks like this

```
output {
  elasticsearch {
        hosts => ["10.0.0.1:9200"]
        index => "%{[@metadata][log_prefix]}-%{[@metadata][index]}-%{[@metadata][rotation]}"
  }
} 

```

This lets me set those @metadata fields on inputs or in the filter section and keeps the output config very simple.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 3, 2020, 2:37pm UTC](https://discuss.elastic.co/t/best-way-to-configure-multiple-output-block/231269/6 "2020-06-03T14:37:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
