# Docs are stored on same index ¡¡

**URL:** <https://discuss.elastic.co/t/docs-are-stored-on-same-index/169060>\
**Category:** Logstash\
**Created:** [February 19, 2019, 4:05pm UTC](https://discuss.elastic.co/t/docs-are-stored-on-same-index/169060 "2019-02-19T16:05:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pablo\_Repolles](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pablo_repolles/32/40828_2.png) [@Pablo\_Repolles](https://discuss.elastic.co/u/Pablo_Repolles)\
**Post date:** [February 19, 2019, 4:05pm UTC](https://discuss.elastic.co/t/docs-are-stored-on-same-index/169060/1 "2019-02-19T16:05:00Z")

</div>

The trouble is that de docs are stored into both index at the same time. Instead to use each own index, one per diferent input.

input {  
udp {  
host =\> "192.168.254.60"  
port =\> 5001  
type =\> mikrotik  
}  
udp {  
host =\> "192.168.254.60"  
port =\> 5000  
type =\> qnap  
}  
}

filter { ..if [type] == .. }

output {  
elasticsearch { hosts =\> ["192.168.254.50:9200"]  
if [type] == "mikrotik" {  
index =\> "mikrotik-%{+YYYY.MM.dd}"  
else if [type] == "qnap" {  
index =\> "qnap-%{+YYYY.MM.dd}"  
}  
}  
stdout { codec =\> rubydebug }  
}  
}

![indexs](https://us1.discourse-cdn.com/elastic/original/3X/7/a/7a8146f3d18883fc5a644fea24de23dc8aec20b4.png)

I use two diferents inputs - filters and outputs with diferent index too but the documents are stored into both index - the same number of docs. The size its diferent because i use diferent index templates with diferent mappings for especific fields.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 19, 2019, 4:14pm UTC](https://discuss.elastic.co/t/docs-are-stored-on-same-index/169060/2 "2019-02-19T16:14:53Z")

</div>

As you can not have conditionals within a filter the way you do I am surprised anything gets indexed into Elasticsearch.

---

<div class="post-metadata">

**Author:** ![Pablo\_Repolles](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pablo_repolles/32/40828_2.png) [@Pablo\_Repolles](https://discuss.elastic.co/u/Pablo_Repolles)\
**Post date:** [February 19, 2019, 4:29pm UTC](https://discuss.elastic.co/t/docs-are-stored-on-same-index/169060/3 "2019-02-19T16:29:14Z")

</div>

problem solved.  
I was using two different configuration files inside the "config.d" folder - one for each input - filter and output with its specific index. I do not understand it well but on having said this I did not end up squared to logstash - that if I gathered data in both ports udp and created different indexes.

If I use a single configuration file for everything - then every log trace is only stored in its correct index.

Thanks for your time 😉 - Christian

input {  
udp {  
host =\> "192.168.254.60"  
port =\> 5001  
type =\> mikrotik  
}  
udp {  
host =\> "192.168.254.60"  
port =\> 5000  
type =\> qnap  
}  
}

filter {

if [type] == "mikrotik" {

```
# FIREWALL

```

if "firewall" in [message] {  
grok {  
patterns\_dir =\> ["/etc/logstash/conf.d/patterns"]  
match =\> { "message" =\> "%{MIKROTIKFIREWALL}"}  
}  
geoip {  
source =\> "src\_ip"  
target =\> "geoip"  
}  
geoip {  
source =\> "dst\_ip"  
target =\> "geoip"  
}  
}

```
if "2" in [proto] {
mutate {
update => { "proto" => "IGMP" }
}
}

} else if [type] == "qnap" {
grok {
  patterns_dir => ["/etc/logstash/conf.d/patterns"]
  match => { "message" => "%{QNAPSYSLOG}" }
  add_field => ["received_at", "%{@timestamp}"]
}
geoip {
source => "src_ip"
target => "geoip"
}
date {
  match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
}

```

}

}

output {  
if [type] == "mikrotik" {  
elasticsearch { hosts =\> ["192.168.254.50:9200"]  
index =\> "mikrotik-%{+YYYY.MM.dd}"  
}  
} else if [type] == "qnap" {  
elasticsearch { hosts =\> ["192.168.254.50:9200"]  
index =\> "qnap-%{+YYYY.MM.dd}"  
}  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 19, 2019, 4:30pm UTC](https://discuss.elastic.co/t/docs-are-stored-on-same-index/169060/4 "2019-02-19T16:30:53Z")

</div>

All files in the config directory are concatenated, so if you do not use conditional to control flow events from all inputs will go to all outputs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2019, 4:32pm UTC](https://discuss.elastic.co/t/docs-are-stored-on-same-index/169060/5 "2019-03-19T16:32:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
