Cross contamination of events in multiple indexes

(141984) #1

I currently have an ELK setup with my web server log events flowing into an index by the name "web-server-logs". When I start pushing metric beat events to this ELK setup, my web server log events and metric beat events end up flowing into each others the indexes.

How can I push both the events to their respective indexes only?

I am pushing the events using filebeat and metricbeat into logstash

(Christian Dahlqvist) #2

It sounds like you may have multiple configuration files for Logstash that lack conditionals. All configuration files made available to Logstash will be concatenated, and if you do not use conditionals all data will go to all outputs.

(141984) #3

Hi @Christian_Dahlqvist,

can I use a if condition in the configuration for the output and specific the index in the output configuration?

If not, then where do I specify the conditional routing?


(Christian Dahlqvist) #4

There are examples in the documentation that show your how they are used.

(system) #5

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.