# How to chain multiple input in Logstash

**URL:** <https://discuss.elastic.co/t/how-to-chain-multiple-input-in-logstash/315179>\
**Category:** Logstash\
**Tags:** jdbc\
**Created:** [September 26, 2022, 2:41pm UTC](https://discuss.elastic.co/t/how-to-chain-multiple-input-in-logstash/315179 "2022-09-26T14:41:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![anand\_tripathi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anand_tripathi/32/107286_2.png) [@anand\_tripathi](https://discuss.elastic.co/u/anand_tripathi)\
**Post date:** [September 26, 2022, 2:41pm UTC](https://discuss.elastic.co/t/how-to-chain-multiple-input-in-logstash/315179/1 "2022-09-26T14:41:06Z")

</div>

My use case is something like below

**First Input(Mysql JDBC)**  
I'm selecting some data from MySQL like

```auto
select pk_id, score, other_id from <some_table>

```

**Second Chained Input (Elasticsearch)**  
Then I want to pass the data `pk_id` list got from the first input to elasticsearch to get other information from it

```auto
Not exactly like this but just to fetch other data from es
some_index/_search
{
    "query": {
         "terms": {
                "values": []
         }
    }
}

```

Then combine the response from elasticsearch to the records obtained from the first input with the corresponding `pk_id`

```auto
<pk_id>, score, other_id, <other_info_from_elasticsearch>

```

**Output Elasticsearch**  
Output the above records to the elasticsearch document

Can I do this using some plugin in logstash? or I have to do that using custom ruby script in logstash

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 26, 2022, 4:40pm UTC](https://discuss.elastic.co/t/how-to-chain-multiple-input-in-logstash/315179/2 "2022-09-26T16:40:44Z")

</div>

You cannot reference events from one input in another, but you can use an [elasticsearch](https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html) filter to do this.

---

<div class="post-metadata">

**Author:** ![anand\_tripathi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anand_tripathi/32/107286_2.png) [@anand\_tripathi](https://discuss.elastic.co/u/anand_tripathi)\
**Post date:** [September 27, 2022, 8:45am UTC](https://discuss.elastic.co/t/how-to-chain-multiple-input-in-logstash/315179/3 "2022-09-27T08:45:13Z")

</div>

Thanks Badger, it solved the issue but I have one more question.  
It is calling elasticsearch for single events. So let's say I'm getting 1000 records at once from JDBC input then filter will process them one by one and will make 1000 calls to elasticasearch and then it is going to output plugin.  
But somehow the output plugin uses the bulk API for it can I do something so that filter plugin will also call it in bulk to avoid huge number of HTTP calls  
@Badger

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 27, 2022, 12:50pm UTC](https://discuss.elastic.co/t/how-to-chain-multiple-input-in-logstash/315179/4 "2022-09-27T12:50:47Z")

</div>

I do not think logstash can do that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2022, 12:51pm UTC](https://discuss.elastic.co/t/how-to-chain-multiple-input-in-logstash/315179/5 "2022-10-25T12:51:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
