# Having file and elasticsearch output with filtering only the elastic search

**URL:** <https://discuss.elastic.co/t/having-file-and-elasticsearch-output-with-filtering-only-the-elastic-search/36807>\
**Category:** Logstash\
**Created:** [December 9, 2015, 10:18pm UTC](https://discuss.elastic.co/t/having-file-and-elasticsearch-output-with-filtering-only-the-elastic-search/36807 "2015-12-09T22:18:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![shanemgleeson](https://avatars.discourse-cdn.com/v4/letter/s/13edae/32.png) [@shanemgleeson](https://discuss.elastic.co/u/shanemgleeson)\
**Post date:** [December 9, 2015, 10:18pm UTC](https://discuss.elastic.co/t/having-file-and-elasticsearch-output-with-filtering-only-the-elastic-search/36807/1 "2015-12-09T22:18:37Z")

</div>

Hi,

I was hoping to use the ELK stack to take over from an old scp and regex based log centralization we have running. Right now all in house application logs are collecting at a central location using a remote ssh call that gzips the logs, ships them to the central server and creates a path based on application name, date, hostname. There are a number of inhouse applications that search through that log data in it's present location. The data is not filtered.

What I was hoping was we could send the logs to logstash, have logstash output them to the desired location based on appname, date, filename. Then we could also send the data to elastic search.

What a see as a problem is if I have the data filtered then using the output file plugin will lead to outputting filtered data where i want to output unfiltered data.

in hints or interesting work arounds would be appreciated.

-S

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 10, 2015, 6:54am UTC](https://discuss.elastic.co/t/having-file-and-elasticsearch-output-with-filtering-only-the-elastic-search/36807/2 "2015-12-10T06:54:26Z")

</div>

You could run multiple Logstash instances or use the [clone filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-clone.html) to split each event in two and apply the filtering selectively.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:19am UTC](https://discuss.elastic.co/t/having-file-and-elasticsearch-output-with-filtering-only-the-elastic-search/36807/3 "2017-07-06T05:19:11Z")

</div>


