# Having trouble forwarding indexes from Elasticsearch to logstash

**URL:** <https://discuss.elastic.co/t/having-trouble-forwarding-indexes-from-elasticsearch-to-logstash/135395>\
**Category:** Logstash\
**Created:** [June 11, 2018, 2:51pm UTC](https://discuss.elastic.co/t/having-trouble-forwarding-indexes-from-elasticsearch-to-logstash/135395 "2018-06-11T14:51:48Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![StillReclaim](https://avatars.discourse-cdn.com/v4/letter/s/bbce88/32.png) [@StillReclaim](https://discuss.elastic.co/u/StillReclaim)\
**Post date:** [June 11, 2018, 2:51pm UTC](https://discuss.elastic.co/t/having-trouble-forwarding-indexes-from-elasticsearch-to-logstash/135395/1 "2018-06-11T14:51:48Z")

</div>

Hello,

I'm trying to send all information from one elasticsearch node to another in different clusters through logstash. My current inputs.conf is below. It sort of works, but it outputs indexes that are named: %{[@metadata][beat]}-2018.06.01, %{[@metadata][beat]}-2018.05.22, %{[@metadata][beat]}-2018.05.10, rather than metricbeat-2018.06.01, winlogbeat-2018.06.01, heartbeat-2018.06.01, etc. Is there a way to format it so the indexes are copied over correctly in real time?

> input {  
> elasticsearch {  
> hosts =\> ["HOSTNAME:9200"]  
> #query =\> '{ "query": { "match": { "statuscode": 200 } }, "sort": ["\_doc"] }'  
> index =\> "\*"  
> #size =\> 500  
> #scroll =\> "5m"  
> #docinfo =\> true  
> }  
> }
> 
> output {  
> elasticsearch {  
> hosts =\> ["OTHERHOSTNAME:9200"]  
> sniffing =\> false  
> manage\_template =\> false  
> index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"   
> }  
> }

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 11, 2018, 3:28pm UTC](https://discuss.elastic.co/t/having-trouble-forwarding-indexes-from-elasticsearch-to-logstash/135395/2 "2018-06-11T15:28:10Z")

</div>

OK, there is no [@metadata][beat] field in the document, so it is not substituted. Use stdout { codec =\> rubydebug } to see where in the document the beat name occurs, and substitute that field instead.

---

<div class="post-metadata">

**Author:** ![StillReclaim](https://avatars.discourse-cdn.com/v4/letter/s/bbce88/32.png) [@StillReclaim](https://discuss.elastic.co/u/StillReclaim)\
**Post date:** [June 11, 2018, 5:12pm UTC](https://discuss.elastic.co/t/having-trouble-forwarding-indexes-from-elasticsearch-to-logstash/135395/3 "2018-06-11T17:12:36Z")

</div>

I will try that and update you. Thank you.

---

<div class="post-metadata">

**Author:** ![StillReclaim](https://avatars.discourse-cdn.com/v4/letter/s/bbce88/32.png) [@StillReclaim](https://discuss.elastic.co/u/StillReclaim)\
**Post date:** [June 11, 2018, 8:36pm UTC](https://discuss.elastic.co/t/having-trouble-forwarding-indexes-from-elasticsearch-to-logstash/135395/4 "2018-06-11T20:36:41Z")

</div>

@Badger, It worked! thank you. I didn't know you could search through the output like that. Very helpful.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 9, 2018, 8:36pm UTC](https://discuss.elastic.co/t/having-trouble-forwarding-indexes-from-elasticsearch-to-logstash/135395/5 "2018-07-09T20:36:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
