# Condition statements output Logstash

**URL:** <https://discuss.elastic.co/t/condition-statements-output-logstash/229508>\
**Category:** Logstash\
**Created:** [April 23, 2020, 3:40pm UTC](https://discuss.elastic.co/t/condition-statements-output-logstash/229508 "2020-04-23T15:40:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![GedeoN](https://avatars.discourse-cdn.com/v4/letter/g/e9c0ed/32.png) [@GedeoN](https://discuss.elastic.co/u/GedeoN)\
**Post date:** [April 23, 2020, 3:40pm UTC](https://discuss.elastic.co/t/condition-statements-output-logstash/229508/1 "2020-04-23T15:40:03Z")

</div>

Hello,

I'm working on possibilities to have many output in logstash.  
I actually don't understand what is wrong.

I have 7.x versions.

If i just use this, it's working.

> Blockquote  
> output {  
> if "ERRORLOG" in [tags] {  
> elasticsearch {  
> hosts =\> ["[http://sta-elasticsearch:9200](http://sta-elasticsearch:9200)"]  
> index =\> "errorlog-%{+YYYY.MM.dd}"  
> }  
> }  
> Blockquote

But if i have more statements like this, i have errors in logstash

> Blockquote  
> output {  
> if "ERRORLOG" in [tags] {  
> elasticsearch {  
> hosts =\> ["[http://sta-elasticsearch:9200](http://sta-elasticsearch:9200)"]  
> index =\> "errorlog-%{+YYYY.MM.dd}"  
> }  
> }  
> else if "FDLAUNCHERRORLOG" in [tags] {  
> elasticsearch {  
> hosts =\> ["[http://sta-elasticsearch:9200](http://sta-elasticsearch:9200)"]  
> index =\> "fdlauncherrorlog-%{+YYYY.MM.dd}"  
> }  
> }  
> else "SQLAGENT" in [tags] {  
> elasticsearch {  
> hosts =\> ["[http://sta-elasticsearch:9200](http://sta-elasticsearch:9200)"]  
> index =\> "sqlagent-%{+YYYY.MM.dd}"  
> }  
> }  
> }  
> Blockquote

Error:

> Blockquote  
> [2020-04-23T15:06:26,168][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:stalog-mssql, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, if, { at line 27, column 8 (byte 773) after output {\n if "ERRORLOG" in [tags] {\n elasticsearch {\n hosts =\> ["[http://sta-elasticsearch:9200](http://sta-elasticsearch:9200)"]\n index =\> "errorlog-%{+YYYY.MM.dd}"\n }\n}\n else if "FDLAUNCHERRORLOG" in [tags] {\n elasticsearch {\n hosts =\> ["[http://sta-elasticsearch:9200](http://sta-elasticsearch:9200)"]\n index =\> "fdlauncherrorlog-%{+YYYY.MM.dd}"\n }\n}\n else ", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:41:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:49:in `compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `block in compile_sources'", "org/jruby/RubyArray.java:2584:in `map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:10:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:153:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:26:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:36:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:326:in `block in converge\_state'"]}  
> Blockquote

I thought it was a problem with indent but finally no.  
What do think about that?

Regards.  
Jonathan

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 23, 2020, 4:19pm UTC](https://discuss.elastic.co/t/condition-statements-output-logstash/229508/2 "2020-04-23T16:19:33Z")

</div>

> [@GedeoN](#):
>
> else "SQLAGENT" in [tags] {

That should be "else if", not just "else".

---

<div class="post-metadata">

**Author:** ![GedeoN](https://avatars.discourse-cdn.com/v4/letter/g/e9c0ed/32.png) [@GedeoN](https://discuss.elastic.co/u/GedeoN)\
**Post date:** [April 23, 2020, 4:32pm UTC](https://discuss.elastic.co/t/condition-statements-output-logstash/229508/3 "2020-04-23T16:32:12Z")

</div>

I will test. Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 21, 2020, 4:32pm UTC](https://discuss.elastic.co/t/condition-statements-output-logstash/229508/4 "2020-05-21T16:32:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
