# Can I make two input and output in the logstash config file?

**URL:** <https://discuss.elastic.co/t/can-i-make-two-input-and-output-in-the-logstash-config-file/329933>\
**Category:** Logstash\
**Created:** [April 13, 2023, 1:41pm UTC](https://discuss.elastic.co/t/can-i-make-two-input-and-output-in-the-logstash-config-file/329933 "2023-04-13T13:41:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![lilyyy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lilyyy/32/51129_2.png) [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Post date:** [April 13, 2023, 1:41pm UTC](https://discuss.elastic.co/t/can-i-make-two-input-and-output-in-the-logstash-config-file/329933/1 "2023-04-13T13:41:10Z")

</div>

Hello all.

I want to get the two indexes from two input data in the one logstash config file. (One is from tshark file and the other one is filebeat so each data are different.)

tshark data is changed to json file for input and filebeat is using suricata module.

So my concept was

```auto
input {
 file {
  path => "/path/tshark.json"
  type => "tshark"
}
 beats {
  port => 5044
  type => "filebeat"
 }
}

filter {
 if [type] == "tshark" {
  ~~~
}
 else if [type] == "filebeat" {
 ~~~
 }
}

output{
  if [type] == "tshark" {
   elasticsearch{
    host => ["address:port"]
    index=> "tshark"
   }
 }
 else if [type] == "filebeat" {
  elasticsearch{
    host => ["address:port"]
    index=> "filebeat"
  }
 }
}

```

It doesn't work for me. It didn't make any index. I used [tags] instead of [type], in that case the filtering was not applied each of index.  
So I tried multiple pipeline too, but the result was that two indexes were created with the same data but with different names.

Could you give me some advices?

Thank you.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 13, 2023, 3:20pm UTC](https://discuss.elastic.co/t/can-i-make-two-input-and-output-in-the-logstash-config-file/329933/2 "2023-04-13T15:20:50Z")

</div>

> [@lilyyy](#):
>
> ```auto
> output{
> elasticsearch{
> if [type] == "tshark" {
> host => ["address:port"]
> index=> "tshark"
> }
> else if [type] == "filebeat" {
> host => ["address:port"]
> index=> "filebeat"
> }
> }
> }
> 
> ```

This is wrong, the conditional needs to be _outside_ the output plugin:

```auto
output {
    if [type] == "tshark" {
        elasticsearch { your elasticsearch output }
    } else if [type] == "filebeat" {
        elasticsearch { your elasticsearch output }
    }
}

```

But the best approach is to use different pipelines with `pipelines.yml`, one pipeline you would have the input and output for `tshark` and the other the input and output for `filebeat`.

---

<div class="post-metadata">

**Author:** ![lilyyy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lilyyy/32/51129_2.png) [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Post date:** [April 13, 2023, 3:24pm UTC](https://discuss.elastic.co/t/can-i-make-two-input-and-output-in-the-logstash-config-file/329933/3 "2023-04-13T15:24:35Z")

</div>

Oops, It was a typo. I made the output the same as you wrote. I will change the original post.

I also tried pipeline, but the result was that two indexes were created with the same data but with different names.

Thank you for replying!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 13, 2023, 3:26pm UTC](https://discuss.elastic.co/t/can-i-make-two-input-and-output-in-the-logstash-config-file/329933/4 "2023-04-13T15:26:19Z")

</div>

> [@lilyyy](#):
>
> I also tried pipeline, but the result was that two indexes were created with the same data but with different names.

You need to share your `pipelines.yml` configuration and logstash logs, it is not possible to know what is the issue without it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2023, 3:27pm UTC](https://discuss.elastic.co/t/can-i-make-two-input-and-output-in-the-logstash-config-file/329933/5 "2023-05-11T15:27:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
