# "document\_type" on filebeat & "if" and "type" on logstash are not working

**URL:** <https://discuss.elastic.co/t/document-type-on-filebeat-if-and-type-on-logstash-are-not-working/78636>\
**Category:** Logstash\
**Created:** [March 15, 2017, 4:07am UTC](https://discuss.elastic.co/t/document-type-on-filebeat-if-and-type-on-logstash-are-not-working/78636 "2017-03-15T04:07:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![yoshifuji\_tokyo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yoshifuji_tokyo/32/16345_2.png) [@yoshifuji\_tokyo](https://discuss.elastic.co/u/yoshifuji_tokyo)\
**Post date:** [March 15, 2017, 4:07am UTC](https://discuss.elastic.co/t/document-type-on-filebeat-if-and-type-on-logstash-are-not-working/78636/1 "2017-03-15T04:07:20Z")

</div>

# Trouble

I set **"document\_type"** on filebeat, and set **"if" and "type"** on logstash conf.  
I've confirmed these logs are on AWS S3 bucket, however all logs are combined into one bucket "web-app" without separation.

It seems to that **"if [type]" is not correctly working** on logstash.

```
filter{
  if [type] == "web-app" {
```

Could you give me advice to solve this trouble?

Thanks.

# Environment

- logstash 2.3.4
- filebeat 1.2.3
- s3-output-plugin

conf files are below.

#####################

# clinet: filebeat

#####################  
$cat /etc/filebeat/filebeat.yml

```
filebeat:
  prospectors:
    -
      paths:
        - /apphome/MetaData/log/*
      document_type: web-app
      input_type: log
      multiline:
        pattern: "^[[:digit:]]{4}"
        negate: true
        match: after
    -
      paths:
        - /var/log/httpd/intage.access_log
      document_type: http-access
      input_type: log
    -
      paths:
        - /var/log/httpd/intage.error_log
      document_type: http-error
      input_type: log
  registry_file: /var/lib/filebeat/registry
output:
  logstash:
    hosts: ["logstash-srv-01:5044"]
shipper:
logging:
  files:
```

#####################

# server: logstash

#####################  
$cat /etc/logstash/conf.d/logstash-conf.json

```
input {
  beats {
    port => 5044
  }
}

filter {
  if [type] == "web-app" {
    grok {
      patterns_dir => ["/opt/logstash/extra_patterns"]
      match => ["message", "%{TIMESTAMP_4S:timestamp_4s} %{GREEDYDATA}"]
      add_field => ["timestamp", "%{timestamp_4s} +0900"]
    }
    date {
      match => ["timestamp", "yyyy/MM/dd HH:mm:ss Z"]
      remove_field => ["timestamp", "timestamp_4s"]
    }
  }
}

output {
  if [type] == "web-app" {
    s3 {
      access_key_id => "(your-key)"
      secret_access_key => "(your-secret)"
      region => "ap-northeast-1"
      bucket => "web-app"
      prefix => "log/"
      codec => "json_lines"
      time_file => 1
    }
  }
  else if [type] == "http-access" {
    s3 {
      access_key_id => "(your-key)"
      secret_access_key => "(your-secret)"
      region => "ap-northeast-1"
      bucket => "http-access"
      prefix => "log/"
      codec => "json_lines"
      time_file => 1
    }
  }
  else if [type] == "http-error" {
    s3 {
      access_key_id => "(your-key)"
      secret_access_key => "(your-secret)"
      region => "ap-northeast-1"
      bucket => "http-error"
      prefix => "log/"
      codec => "json_lines"
      time_file => 1
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![whyapenny](https://avatars.discourse-cdn.com/v4/letter/w/90db22/32.png) [@whyapenny](https://discuss.elastic.co/u/whyapenny)\
**Post date:** [March 15, 2017, 1:54pm UTC](https://discuss.elastic.co/t/document-type-on-filebeat-if-and-type-on-logstash-are-not-working/78636/2 "2017-03-15T13:54:43Z")

</div>

> [@yoshifuji\_tokyo](#):
>
> if [type] == "web-app" {

try changing to:  
` if "web-app" in [type] {`

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [March 15, 2017, 2:09pm UTC](https://discuss.elastic.co/t/document-type-on-filebeat-if-and-type-on-logstash-are-not-working/78636/3 "2017-03-15T14:09:51Z")

</div>

> [@whyapenny](#):
>
> try changing to:
> 
> ```auto
> if "web-app" in [type] {
> 
> ```

This syntax is for fields that contain arrays. The `type` field should never be an array.

What is in the output? I would recommend not hyphenating the type.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2017, 2:10pm UTC](https://discuss.elastic.co/t/document-type-on-filebeat-if-and-type-on-logstash-are-not-working/78636/4 "2017-04-12T14:10:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
