# 'exec' only once

**URL:** <https://discuss.elastic.co/t/exec-only-once/28945>\
**Category:** Logstash\
**Created:** [September 9, 2015, 3:53pm UTC](https://discuss.elastic.co/t/exec-only-once/28945 "2015-09-09T15:53:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jonathan\_Johnson](https://avatars.discourse-cdn.com/v4/letter/j/ecccb3/32.png) [@Jonathan\_Johnson](https://discuss.elastic.co/u/Jonathan_Johnson)\
**Post date:** [September 9, 2015, 3:53pm UTC](https://discuss.elastic.co/t/exec-only-once/28945/1 "2015-09-09T15:53:08Z")

</div>

Hi -- I'm sure this is simple but I can't figure it out.

my configuration:  
Input: ES query  
Filter: cipher  
Output: File, exec cmd

So I query Elasticsearch and want to write those events to a single local file. That part is working.

However, the 'exec' statement (which uses the AWS S3 cp command to copy the file to a bucket) is called many times (I'm guessing once for each ES document?). How can I configure this so 'exec' is only executed **one time** , after the file output has been completed?

Thanks.

PS - I could not get the S3 Output plugin to work (it worked with stdin, but not with ES as input).

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 9, 2015, 5:31pm UTC](https://discuss.elastic.co/t/exec-only-once/28945/2 "2015-09-09T17:31:29Z")

</div>

There is no "done" concept in Logstash. Events are assumed to be part of an eternal stream. Each event is sent to every output and with the stock plugins there's no way to do what you want inside Logstash.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:29am UTC](https://discuss.elastic.co/t/exec-only-once/28945/3 "2017-07-06T05:29:35Z")

</div>


