# Getting logs in other index

**URL:** <https://discuss.elastic.co/t/getting-logs-in-other-index/110016>\
**Category:** Logstash\
**Created:** [December 2, 2017, 5:19pm UTC](https://discuss.elastic.co/t/getting-logs-in-other-index/110016 "2017-12-02T17:19:50Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [December 2, 2017, 5:19pm UTC](https://discuss.elastic.co/t/getting-logs-in-other-index/110016/1 "2017-12-02T17:19:50Z")

</div>

Hi Guys,

I am kinda facing weird issue! I have configured two config file and have created two different indices which are indexing my bind and Apache logs.

However my bind logs are getting successfully parsed and even logstash-apache is showing Bind logs not sure why.

Here are the config

bind config

```
input {

```

##############STDIN

# stdin {

# type =\> "dnsmaldef"

# }

##########STIN

```
   file {
   path => ["/var/log/named/queries.*"]
            start_position => "beginning"
            type => "dnsmaldef"
   }

```

}  
output {  
if [type] == "dnsmaldef" {

# stdout {

# codec =\> rubydebug

# }

```
            elasticsearch {
                    hosts => ["dnsdf.isnlab.in:9200"]
                    index => "logstash-dnsmaldef-%{+YYYY.MM.dd}"
                    template => "/etc/logstash/logstash-template.json"
    }
            }

```

}

* * *

Apache config

input {  
# add necessary input parameters

# stdin {

# 

# }

```
           file {
   path => ["/var/log/httpd/access*"]
            start_position => "beginning"
   }

```

}

output {  
# add necessary output parameters

# stdout {

# codec =\> rubydebug

# }

```
                    elasticsearch {
                    hosts => ["dnsdf.isnlab.in:9200"]
                    index => "logstash-apache-%{+YYYY.MM.dd}"
                    template => "/etc/logstash/logstash-template.json"
    }

```

}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 2, 2017, 6:34pm UTC](https://discuss.elastic.co/t/getting-logs-in-other-index/110016/2 "2017-12-02T18:34:18Z")

</div>

See [Logstash sending to all output hosts](https://discuss.elastic.co/t/logstash-sending-to-all-output-hosts/100583). Since that post was made Logstash 6 which supports multiple pipelines (if explicitly configured) is available.

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [December 2, 2017, 6:44pm UTC](https://discuss.elastic.co/t/getting-logs-in-other-index/110016/3 "2017-12-02T18:44:21Z")

</div>

I am sorry I did not get anything out of that.. i am still not sure what went wrong with my pipeline.

Can you please elaborate more on this?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 2, 2017, 8:49pm UTC](https://discuss.elastic.co/t/getting-logs-in-other-index/110016/4 "2017-12-02T20:49:01Z")

</div>

You have a conditional wrapping the elasticsearch output in your Bind configuration file:

> ```
> if [type] == "dnsmaldef" {
> ...
> }
> 
> ```

You don't have that kind of conditional wrapping the elasticsearch output in your Apache configuration file. Hence, events from the other file will be routed to that output.

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [December 3, 2017, 2:12am UTC](https://discuss.elastic.co/t/getting-logs-in-other-index/110016/5 "2017-12-03T02:12:20Z")

</div>

OK - I disabled it and restarted the logstash and recreated the index-pattern but is the same ☹

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 4, 2017, 6:20am UTC](https://discuss.elastic.co/t/getting-logs-in-other-index/110016/6 "2017-12-04T06:20:45Z")

</div>

Please show your configuration and an example of an event that ended up in the wrong index. You can copy/paste the raw JSON document from Kibana's JSON tab.

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [December 11, 2017, 1:53pm UTC](https://discuss.elastic.co/t/getting-logs-in-other-index/110016/7 "2017-12-11T13:53:20Z")

</div>

here is my config for apache.conf

input {  
# add necessary input parameters

# stdin {

# 

# }

```
           file {
            path => ["/var/log/httpd/access_*"]
            start_position => "beginning"
            type => "apache"
   }

```

}

filter {  
if [type] == "apache" {  
# for Apache Access logs  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }  
}  
}  
}  
output {  
# add necessary output parameters

# stdout {

# codec =\> rubydebug

# }

```
            if [type] == "apache" {
                    elasticsearch {
                    hosts => ["dnsdf.isnlab.in:9200"]
                    index => "logstash-apache-%{+YYYY.MM.dd}"
                                            }
                                    }

```

And here is log  
92.168.5.102 - - [11/Dec/2017:08:58:57 +0530] "GET / HTTP/1.1" 200 44546 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36"

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 11, 2017, 2:23pm UTC](https://discuss.elastic.co/t/getting-logs-in-other-index/110016/8 "2017-12-11T14:23:59Z")

</div>

Please answer my second question (the one about an example event). Also, what other configuration files do you have?

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [December 11, 2017, 2:37pm UTC](https://discuss.elastic.co/t/getting-logs-in-other-index/110016/9 "2017-12-11T14:37:41Z")

</div>

Well you know I was playing with configuration and logs are not even getting indexed with said config file however stdin & stdout are showing proper indexes.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 11, 2017, 3:03pm UTC](https://discuss.elastic.co/t/getting-logs-in-other-index/110016/10 "2017-12-11T15:03:49Z")

</div>

Please answer all questions.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2018, 3:16pm UTC](https://discuss.elastic.co/t/getting-logs-in-other-index/110016/11 "2018-01-08T15:16:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
