# Creating single index only

**URL:** <https://discuss.elastic.co/t/creating-single-index-only/48949>\
**Category:** Logstash\
**Created:** [May 2, 2016, 12:34pm UTC](https://discuss.elastic.co/t/creating-single-index-only/48949 "2016-05-02T12:34:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gaurav\_Harsola](https://avatars.discourse-cdn.com/v4/letter/g/ecc23a/32.png) [@Gaurav\_Harsola](https://discuss.elastic.co/u/Gaurav_Harsola)\
**Post date:** [May 2, 2016, 12:34pm UTC](https://discuss.elastic.co/t/creating-single-index-only/48949/1 "2016-05-02T12:34:13Z")

</div>

Hi ,

I have following conf file.

It create only one index (auth1) in my elastisearch not the other one .

input {  
file {  
type =\> "Apache"  
path =\> "/home/test/test1.log"  
start\_position =\> beginning  
}  
file {  
type =\> "Auth"  
path =\> "/var/log/auth.log"  
start\_position =\> beginning  
}  
}

filter {

if [type] == "Apache" {  
grok {  
match =\> { "message" =\> '%{IPORHOST:clientip} %{USER:ident} %{USER:auth} [%{HTTPDATE:timestamp}] "%{WORD:verb} %{DATA:request} HTTP/%{NUMBER:httpversion}" %{N  
UMBER:response:int} (?:-|%{NUMBER:bytes:int}) %{QS:referrer} %{QS:agent}'}  
}

date {  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
}

geoip {  
source =\> "clientip"  
target =\> "geoip"  
database =\> "/home/Downloads/test/GeoLiteCity.dat" # e.g. database =\>"E:/logstash/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}

mutate {  
convert =\> ["[geoip][coordinates]", "float" ]  
}

}

if [type] == "Auth" {  
grok {  
match =\> { "message" =\> '%{SYSLOGBASE} %{GREEDYDATA:logline}' }  
}

}

}

output {  
if [type] == "Apache" {  
stdout { codec =\> rubydebug }  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "apache1"  
}

```
}
if [type] == "Auth" {
stdout { codec => rubydebug }

```

elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "auth1"  
}

}  
}

Please help me in this !!

Thanks  
Gaurav

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [May 2, 2016, 3:14pm UTC](https://discuss.elastic.co/t/creating-single-index-only/48949/2 "2016-05-02T15:14:05Z")

</div>

If you only keep the stdout config in the first elasticsearch block, do you see some output?

---

<div class="post-metadata">

**Author:** ![Gaurav\_Harsola](https://avatars.discourse-cdn.com/v4/letter/g/ecc23a/32.png) [@Gaurav\_Harsola](https://discuss.elastic.co/u/Gaurav_Harsola)\
**Post date:** [May 2, 2016, 3:43pm UTC](https://discuss.elastic.co/t/creating-single-index-only/48949/3 "2016-05-02T15:43:41Z")

</div>

i didn't get you . Can you please elaborate a little

Thanks  
Gaurav

---

<div class="post-metadata">

**Author:** ![Gaurav\_Harsola](https://avatars.discourse-cdn.com/v4/letter/g/ecc23a/32.png) [@Gaurav\_Harsola](https://discuss.elastic.co/u/Gaurav_Harsola)\
**Post date:** [May 3, 2016, 3:40am UTC](https://discuss.elastic.co/t/creating-single-index-only/48949/4 "2016-05-03T03:40:12Z")

</div>

Hi,

output {  
stdout {codec =\> rubydebug}  
if [type] == "Apache" {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "apache2"  
}  
} else {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "auth2"  
}  
}  
}

I have used this syntax .still it is creating only auth2 index

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:59am UTC](https://discuss.elastic.co/t/creating-single-index-only/48949/5 "2017-07-06T04:59:39Z")

</div>


