# ES "merging" indexes

**URL:** <https://discuss.elastic.co/t/es-merging-indexes/63866>\
**Category:** Logstash\
**Created:** [October 25, 2016, 12:09pm UTC](https://discuss.elastic.co/t/es-merging-indexes/63866 "2016-10-25T12:09:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![hgpit](https://avatars.discourse-cdn.com/v4/letter/h/f1d935/32.png) [@hgpit](https://discuss.elastic.co/u/hgpit)\
**Post date:** [October 25, 2016, 12:09pm UTC](https://discuss.elastic.co/t/es-merging-indexes/63866/1 "2016-10-25T12:09:36Z")

</div>

Hello,

Very new to Logstash and ElasticSearch (2.4.1), so am just experimenting at this stage.

We are trying to create two indexes in ES, which are sourced from MySQL in Logstash, then outputted to ES.

At first, it seemed to be working, but then we have realized that the two indexes in ES appear to be identical in size and seem to be "merged" somehow (even though they both have their unique names). Are we misunderstanding how we should create these two separate indexes?

Logstash conf file 1:  
"  
input {  
jdbc {  
jdbc\_connection\_string =\> "jdbc:mysql://localhost:3306/masdata"  
jdbc\_user =\> "username"  
jdbc\_password =\> "userpass"  
jdbc\_driver\_library =\> "/usr/share/java/mysql-connector-java.jar"  
jdbc\_driver\_class =\> "com.mysql.jdbc.Driver"  
jdbc\_paging\_enabled =\> "true"  
jdbc\_page\_size =\> "50000"  
schedule =\> "\*/30 \* \* \* mon-fri"  
statement =\> "SELECT item\_code,part\_no,part\_stock\_no FROM tbl\_products WHERE brand\_id \< 999"  
}  
}  
output {  
elasticsearch {  
hosts =\> "10.11.1.223:9200"  
index =\> "idx\_md-partnos"  
}  
}  
"

Logstash conf file 2:  
"  
input {  
jdbc {  
jdbc\_connection\_string =\> "jdbc:mysql://localhost:3306/masdata"  
jdbc\_user =\> "username"  
jdbc\_password =\> "userpass"  
jdbc\_driver\_library =\> "/usr/share/java/mysql-connector-java.jar"  
jdbc\_driver\_class =\> "com.mysql.jdbc.Driver"  
jdbc\_paging\_enabled =\> "true"  
jdbc\_page\_size =\> "50000"  
schedule =\> "\*/30 \* \* \* mon-fri"  
statement =\> "SELECT item\_code,item\_description,brand\_name FROM tbl\_products p LEFT JOIN tbl\_brands b ON b.brand\_id = p.brand\_id WHERE p.brand\_id \< 999"  
}  
}  
output {  
elasticsearch {  
hosts =\> "10.11.1.223:9200"  
index =\> "idx\_md-descriptions"  
}  
}  
"

Can some kind soul put us on the right path?

Thank you!

Elliot

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 26, 2016, 10:01am UTC](https://discuss.elastic.co/t/es-merging-indexes/63866/2 "2016-10-26T10:01:38Z")

</div>

LS merges config files read from a directory at run time.

You should look at [https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#conditionals](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#conditionals) for splitting things out.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:32am UTC](https://discuss.elastic.co/t/es-merging-indexes/63866/3 "2017-07-06T04:32:41Z")

</div>


