# How to handle multiple beats in Logstash

**URL:** <https://discuss.elastic.co/t/how-to-handle-multiple-beats-in-logstash/130469>\
**Category:** Logstash\
**Created:** [May 3, 2018, 2:11pm UTC](https://discuss.elastic.co/t/how-to-handle-multiple-beats-in-logstash/130469 "2018-05-03T14:11:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![charan.gandra](https://avatars.discourse-cdn.com/v4/letter/c/a87d85/32.png) [@charan.gandra](https://discuss.elastic.co/u/charan.gandra)\
**Post date:** [May 3, 2018, 2:11pm UTC](https://discuss.elastic.co/t/how-to-handle-multiple-beats-in-logstash/130469/1 "2018-05-03T14:11:02Z")

</div>

Hello,

I am running winlogbeat for windows event logs and filebeat on Linux for audit logs and syslogs. However I would like to index windows event logs, Linux Audit logs and sys logs separately in Elasticsearch.

My logstash.conf file is something like below.

input {  
beats {  
port =\> 5044  
client\_inactivity\_timeout =\> 599  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}

output {  
if [source] == "/var/log/audit/audit.log" {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "linux-audit-logs"  
}  
}  
else if [source] == "/var/log/messages" {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "linux-sys-logs"  
}  
}  
else if [type] == event\_logs{  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "windows-event-logs"  
}  
}  
}

However I can only see two indices in Elasticsearch linux-sys-logs and linux-audit-logs and not event logs. Not sure what mistake I am making here.

Thanks,

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 3, 2018, 2:54pm UTC](https://discuss.elastic.co/t/how-to-handle-multiple-beats-in-logstash/130469/2 "2018-05-03T14:54:47Z")

</div>

How do you know that the Winlogbeat events actually have "event\_logs" in the `type` field?

---

<div class="post-metadata">

**Author:** ![charan.gandra](https://avatars.discourse-cdn.com/v4/letter/c/a87d85/32.png) [@charan.gandra](https://discuss.elastic.co/u/charan.gandra)\
**Post date:** [May 4, 2018, 2:22pm UTC](https://discuss.elastic.co/t/how-to-handle-multiple-beats-in-logstash/130469/3 "2018-05-04T14:22:13Z")

</div>

Not sure, I though event\_logs is a type. I am looking for a way to index separately based on some field or a tag.

something like this..

if beat is metric  
{}  
else if beat is winlog  
{}  
else if beat is filebeat  
{}

Thanks,  
Charan

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 4, 2018, 5:14pm UTC](https://discuss.elastic.co/t/how-to-handle-multiple-beats-in-logstash/130469/4 "2018-05-04T17:14:52Z")

</div>

I suggest you add

```nohighlight
} else {
  stdout { codec => rubydebug }
}

```

to the end of you output block so that events that don't match any of the conditions are dumped to stdout. Then you'll see which fields you can use in your condition.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2018, 5:14pm UTC](https://discuss.elastic.co/t/how-to-handle-multiple-beats-in-logstash/130469/5 "2018-06-01T17:14:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
