# Conditional in output filter fails on Linux

**URL:** <https://discuss.elastic.co/t/conditional-in-output-filter-fails-on-linux/224880>\
**Category:** Logstash\
**Created:** [March 24, 2020, 3:54pm UTC](https://discuss.elastic.co/t/conditional-in-output-filter-fails-on-linux/224880 "2020-03-24T15:54:21Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![moderable](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@moderable](https://discuss.elastic.co/u/moderable)\
**Post date:** [March 24, 2020, 3:54pm UTC](https://discuss.elastic.co/t/conditional-in-output-filter-fails-on-linux/224880/1 "2020-03-24T15:54:21Z")

</div>

I have the output filter below. It helps me choose between my development Elasticsearch server and the corporate one. If I set [@metadata][local\_es] to false it will send the events to the corporate server otherwise it sends it to my local development server. On Windows this works beautifully and I can flip it at will and the right server gets the events. On Linux it consistently tries the local server on localhost in spite of the flag. And so , of course since I have nothing listening on localhost port 9200 it consistently fails. Can someone tells me if this is a known issue?

```auto
output {
	if ![@metadata][local_es] {
		elasticsearch {
			hosts => ["http://corporatehost:80"]
			document_id => "%{[@metadata][prefix]}%{[@metadata][fingerprint]}"
			index => "filebeat-log-%{logtype}-%{+YYYY.MM.dd}"
		}
	} else {
		elasticsearch {
			hosts => ["http://localhost:9200"]
			document_id => "%{[@metadata][prefix]}%{[@metadata][fingerprint]}"
			index => "filebeat-log-%{logtype}-%{+YYYY.MM.dd}"
		}
	}
	stdout {
		codec => rubydebug { metadata => true }
	}	  
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 24, 2020, 4:50pm UTC](https://discuss.elastic.co/t/conditional-in-output-filter-fails-on-linux/224880/2 "2020-03-24T16:50:46Z")

</div>

An elasticsearch output establishes a connection at startup, it does not wait for an event to arrive. If nothing is listening on localhost:9200 I would expect logstash to continuously log errors about being unable to connect.

---

<div class="post-metadata">

**Author:** ![moderable](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@moderable](https://discuss.elastic.co/u/moderable)\
**Post date:** [March 24, 2020, 5:14pm UTC](https://discuss.elastic.co/t/conditional-in-output-filter-fails-on-linux/224880/3 "2020-03-24T17:14:47Z")

</div>

Well, all that is fine, except the code tells it what server to talk to and it seems that on Linux there is a break down in communication because although there is a server ready, willing and able to receive events, Logstash latches on localhost and will not let go event its life depended on it ;forgive my humor 😅 😅 😅 😅 😅

---

<div class="post-metadata">

**Author:** ![moderable](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@moderable](https://discuss.elastic.co/u/moderable)\
**Post date:** [March 24, 2020, 6:51pm UTC](https://discuss.elastic.co/t/conditional-in-output-filter-fails-on-linux/224880/4 "2020-03-24T18:51:16Z")

</div>

This seems to be a bug in Logstash to me. I think I need to create a bug report in Github.

---

<div class="post-metadata">

**Author:** ![moderable](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@moderable](https://discuss.elastic.co/u/moderable)\
**Post date:** [March 25, 2020, 4:11am UTC](https://discuss.elastic.co/t/conditional-in-output-filter-fails-on-linux/224880/5 "2020-03-25T04:11:59Z")

</div>

So is this me or something else. I never seem to find an answer to my questions on this forum. I am beginning to wonder.

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [March 25, 2020, 10:01am UTC](https://discuss.elastic.co/t/conditional-in-output-filter-fails-on-linux/224880/6 "2020-03-25T10:01:25Z")

</div>

> [@moderable](#):
>
> all that is fine, except the code tells it what server to talk to

Yes the code tells it which server to talk to, which as @Badger explained, in your case is BOTH of them.

All that your `if` statements achieves is determining for each event to which of the two outputs will the event be sent. That could be different from one event to the next.

What you may want to consider is changing to a single output which is set using an environment variable, e.g. `ELASTICSEARCH_HOSTS`. In your `elasticsearch` output you would then use:

```auto
hosts => ["${ELASTICSEARCH_HOSTS}"]

```

This is especially useful if files are developed locally, where `ELASTICSEARCH_HOSTS=http://localhost:9200`, and then deployed onto the Linux server where `ELASTICSEARCH_HOSTS=http://corporatehost:80`. They will work in both environments without modification.

Environment variables are the key to making Logstash pipelines that are easily customized for multiple environments without modifying the pipelines themselves. For example... [https://github.com/robcowart/elastiflow/blob/master/INSTALL.md#environment-variable-reference](https://github.com/robcowart/elastiflow/blob/master/INSTALL.md#environment-variable-reference)

Rob

[![GitHub](https://us1.discourse-cdn.com/elastic/original/3X/6/f/6f8ae834f16b1a02d31607317669716807844d84.png)](https://github.com/robcowart) [![YouTube](https://us1.discourse-cdn.com/elastic/original/3X/4/3/43b9b81a8c93786219985aeb5335c1c323449053.png)](https://www.youtube.com/channel/UCivWvTx1DwrWNcDLV58kmOg) [![LinkedIn](https://us1.discourse-cdn.com/elastic/original/3X/6/7/674f3370d0f0542ddc5e408516beb1b7edd6c1bf.png)](https://www.linkedin.com/in/robertcowart/)  
**[How to install Elasticsearch & Kibana on Ubuntu - incl. hardware recommendations](https://www.youtube.com/watch?v=gZb7HpVOges)**  
**[What is the best storage technology for Elasticsearch?](https://www.youtube.com/watch?v=nKUpfJCBiS4)**

---

<div class="post-metadata">

**Author:** ![moderable](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@moderable](https://discuss.elastic.co/u/moderable)\
**Post date:** [March 25, 2020, 10:25am UTC](https://discuss.elastic.co/t/conditional-in-output-filter-fails-on-linux/224880/7 "2020-03-25T10:25:09Z")

</div>

Thanks Rob for your detailed answer. I am open to trying out environment variables and forgive me if I belabor the point. I am really thinking there is a bug here because of the following reasons:

1. The code behaves as expected on Windows
2. It cannot be both because I expressly set it at the beginning of each event

Perhaps you need to shed a little more light with respect to how it can be

> different from one event to the next

---

<div class="post-metadata">

**Author:** ![moderable](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@moderable](https://discuss.elastic.co/u/moderable)\
**Post date:** [March 25, 2020, 10:38am UTC](https://discuss.elastic.co/t/conditional-in-output-filter-fails-on-linux/224880/8 "2020-03-25T10:38:21Z")

</div>

I think, I am getting a little light. It tries all servers before it gets any event. Let me verify that.

---

<div class="post-metadata">

**Author:** ![moderable](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@moderable](https://discuss.elastic.co/u/moderable)\
**Post date:** [March 25, 2020, 11:08am UTC](https://discuss.elastic.co/t/conditional-in-output-filter-fails-on-linux/224880/9 "2020-03-25T11:08:26Z")

</div>

Yeah. I have stopped my local server. I set it to send events to the corporate server. It tries repeatedly to contact localhost. I think I am all set. if an event comes it will be routed to the proper server but it is just that it will keep trying to contact the servers listed in the output filter. I took the failure to reach the unreachable server as an inability to function. I will definitely look at the environment variable approach. Thanks @rcowart ob and @Badger.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 22, 2020, 11:08am UTC](https://discuss.elastic.co/t/conditional-in-output-filter-fails-on-linux/224880/10 "2020-04-22T11:08:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
