# Help with logstash output

**URL:** <https://discuss.elastic.co/t/help-with-logstash-output/339469>\
**Category:** Logstash\
**Created:** [July 27, 2023, 5:50pm UTC](https://discuss.elastic.co/t/help-with-logstash-output/339469 "2023-07-27T17:50:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![nach\_usal](https://avatars.discourse-cdn.com/v4/letter/n/c57346/32.png) [@nach\_usal](https://discuss.elastic.co/u/nach_usal)\
**Post date:** [July 27, 2023, 5:50pm UTC](https://discuss.elastic.co/t/help-with-logstash-output/339469/1 "2023-07-27T17:50:05Z")

</div>

Hi guys,

I am trying to capture login and logout events in programs such as TeamViewer and AnyDesk, installed in a Windows virtual machine. Then I send them to my Logstash server via the same Filebeat node, here is the input, filter and output configuration file. The output I'm using is shared for other logs, that's why I try to differentiate the logs of the programs when sending them to their index.

```auto
input {
  beats {
    port => "5047"
    type => "beats_programas"
    ssl => true
    ssl_certificate => "/etc/logstash/filebeat.crt"
    ssl_key => "/etc/logstash/filebeat.key"
    ssl_certificate_authorities => ["/etc/logstash/ca.crt"]
  }
}

filter {
  if [type] == "beats_programas" {
    mutate {
      add_field => { "received_at" => "%{@timestamp}" }
      add_field => { "received_from" => "%{host}" }
    }
    # TEAMVIEWER log in y log out
    if "AccountLogin::HandleLoginFinishedWithOld:" in [message] or "Account::Logout:" in [message] {
      mutate {
        add_tag => "teamviewer"
      }
      grok {
        match => { "message" => "%{DATESTAMP:timestamp} +%{NUMBER} +%{NUMBER} %{WORD} +%{GREEDYDATA:message}" }
      }
    # Not interesting logs
    } else {
        drop { }
    }
  }
}

output {
  elasticsearch {
    hosts => ["192.168.153.7:9200"]
    manage_template => false
    if [type] == "beats_programas" {
      if "teamviewer" in [tags] {
        index => "syslog.soc.beats_teamviewer"
      } else {
          index => "syslog.soc.beats_anydesk"
        }
    } else {
      index => "syslog.soc.%{[type]}"
    }
  }
}

```

The problem is that when I restart Logstash I get this message, but apparently the syntax I have is correct. I receive this error in logstash logs:

[2023-07-27T17:36:18,691][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of [\t\r\n], "#", "=\>" at line 5, column 8 (byte 100) after output {\n elasticsearch {\n hosts =\> ["192.168.153.7:9200"]\n manage\_template =\> false\n if ", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:189:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:72:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:52:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:383:in `block in converge\_state'"]}

I know it may be an absurd query but I would appreciate any help.  
Thanks in advance and best regards,  
Nacho

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [July 27, 2023, 6:02pm UTC](https://discuss.elastic.co/t/help-with-logstash-output/339469/2 "2023-07-27T18:02:44Z")

</div>

Line 5, replace with ssl\_nabled

### Deprecated in 6.6.0.

Replaced by [`ssl_enabled`](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html#plugins-inputs-beats-ssl_enabled)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 27, 2023, 8:05pm UTC](https://discuss.elastic.co/t/help-with-logstash-output/339469/3 "2023-07-27T20:05:32Z")

</div>

> [@nach\_usal](#):
>
> ```auto
> output {
> elasticsearch {
> hosts => ["192.168.153.7:9200"]
> manage_template => false
> if [type] == "beats_programas" {
> if "teamviewer" in [tags] {
> index => "syslog.soc.beats_teamviewer"
> } else {
> index => "syslog.soc.beats_anydesk"
> }
> } else {
> index => "syslog.soc.%{[type]}"
> }
> }
> }
> 
> ```

This will not work, you cannot have conditionals inside the output plugin, in this case, inside the `elasticsearch` output plugin.

You need to move your conditionals.

Something like:

```auto
if [type] == "beats_programas" {
  if "teamviewer" in [tags] {
    elasticsearch { output with the index for this case }
  } else {
    elasticsearch { output with the index for this case } 
  }
} else {
    elasticsearch { output with the index for this case }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 27, 2023, 9:12pm UTC](https://discuss.elastic.co/t/help-with-logstash-output/339469/4 "2023-07-27T21:12:39Z")

</div>

You cannot have a conditional within the configuration of an output. See [this](https://discuss.elastic.co/t/logstash-output-by-condition/338376/4) post.

---

<div class="post-metadata">

**Author:** ![nach\_usal](https://avatars.discourse-cdn.com/v4/letter/n/c57346/32.png) [@nach\_usal](https://discuss.elastic.co/u/nach_usal)\
**Post date:** [July 27, 2023, 9:44pm UTC](https://discuss.elastic.co/t/help-with-logstash-output/339469/5 "2023-07-27T21:44:57Z")

</div>

I see. Thank you very much for the help!

---

<div class="post-metadata">

**Author:** ![nach\_usal](https://avatars.discourse-cdn.com/v4/letter/n/c57346/32.png) [@nach\_usal](https://discuss.elastic.co/u/nach_usal)\
**Post date:** [July 27, 2023, 9:45pm UTC](https://discuss.elastic.co/t/help-with-logstash-output/339469/6 "2023-07-27T21:45:28Z")

</div>

Thank you so much!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2023, 9:45pm UTC](https://discuss.elastic.co/t/help-with-logstash-output/339469/7 "2023-08-24T21:45:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
