# Event routing to indexes not working

**URL:** <https://discuss.elastic.co/t/event-routing-to-indexes-not-working/243349>\
**Category:** Logstash\
**Created:** [July 31, 2020, 12:17pm UTC](https://discuss.elastic.co/t/event-routing-to-indexes-not-working/243349 "2020-07-31T12:17:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bijender\_kr](https://avatars.discourse-cdn.com/v4/letter/b/9de053/32.png) [@bijender\_kr](https://discuss.elastic.co/u/bijender_kr)\
**Post date:** [July 31, 2020, 12:17pm UTC](https://discuss.elastic.co/t/event-routing-to-indexes-not-working/243349/1 "2020-07-31T12:17:28Z")

</div>

```auto
Hi,
I am taking windows and unix logs onto logstash and wanted these event logs to be ingested on two different indexes. Below is by config file. 

```

```auto
input {
    beats {
        port => "5042"
 }
}
filter {
  if "winlogbeat" in [agent][type]
   {
      mutate { 
            add_tag => ["windows_event"]
       }
  }
  if "audit.log" in [log][file][path]
  { mutate {
            add_tag => ["audit_logs"]
       }
  }
  if "Security" in [winlog][channel] {
      if [event][code] not in [472,529,530,531,532,533,534,535,536,537,539,4625,4656,4673,4771] {
          drop {}
         }
  }
  if "Application" in [winlog][channel] {
      if [event][code] not in [2,4,90,18456,4363] {
          drop {}
         }
  }
  if "System" in [winlog][channel] {
      if [event][code] not in [6013] {
          drop {}
        }
  }
}
output {
  if "unix_logs" in [tags] {
   elasticsearch {
     hosts => [""http://x.x.x.x:9250", "http://x.x.x.x:9250""]
     user => "elastic"
     password => "{ES_PWD}"
     index => "unix_logs"
   }
  }
  if "windows_logs" in [tags] or "windows_event" in [tags] {
   elasticsearch {
     hosts => [""http://x.x.x.x:9250", "http://x.x.x.x:9250""]
     user => "elastic"
     password => "{ES_PWD}"
     index => "windows_logs"
   }
  }
  else {
   elasticsearch {
     hosts => ["http://x.x.x.x:9250", "http://x.x.x.x:9250"]
     user => "elastic"
     password => "{ES_PWD}"
     index => "misc"
    }
   }
}

```

```auto
All data which is coming from unix system is having tag "linux_logs" and for windows "windows_logs". 
But data is not routing properly to elasticsearch, I am getting some data with tags "unix_logs" on "misc" index. For windows it's working fine.

Is there anything, into the conf file which i am missing ?

Thanks in advance !

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 31, 2020, 2:21pm UTC](https://discuss.elastic.co/t/event-routing-to-indexes-not-working/243349/2 "2020-07-31T14:21:51Z")

</div>

Your conditionals are

> [@bijender\_kr](#):
>
> ```auto
> if "unix_logs" in [tags] {
> }
> 
> if "windows_logs" in [tags] or "windows_event" in [tags] {
> } else {
> }
> 
> ```

The events with unix\_logs in tags should appear in two indexes. Perhaps you want that to be

```auto
  if "unix_logs" in [tags] {
  } else if "windows_logs" in [tags] or "windows_event" in [tags] {
  } else {
  }

```

---

<div class="post-metadata">

**Author:** ![bijender\_kr](https://avatars.discourse-cdn.com/v4/letter/b/9de053/32.png) [@bijender\_kr](https://discuss.elastic.co/u/bijender_kr)\
**Post date:** [July 31, 2020, 5:58pm UTC](https://discuss.elastic.co/t/event-routing-to-indexes-not-working/243349/3 "2020-07-31T17:58:59Z")

</div>

Thanks, It is working now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 28, 2020, 5:59pm UTC](https://discuss.elastic.co/t/event-routing-to-indexes-not-working/243349/4 "2020-08-28T17:59:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
