# How to handle multiple syslog inputs with Logstash to different indices

**URL:** <https://discuss.elastic.co/t/how-to-handle-multiple-syslog-inputs-with-logstash-to-different-indices/181414>\
**Category:** Logstash\
**Created:** [May 16, 2019, 1:53pm UTC](https://discuss.elastic.co/t/how-to-handle-multiple-syslog-inputs-with-logstash-to-different-indices/181414 "2019-05-16T13:53:27Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![colix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colix/32/46274_2.png) [@colix](https://discuss.elastic.co/u/colix)\
**Post date:** [May 16, 2019, 1:53pm UTC](https://discuss.elastic.co/t/how-to-handle-multiple-syslog-inputs-with-logstash-to-different-indices/181414/1 "2019-05-16T13:53:27Z")

</div>

Hi, in input I use 2 ports by 2 project, I want handle them to different indices. But now all input go to prd.rnis-\* index. Can you help?

```
input {
        syslog {
                port => 5001
                tags => ["prd.rnis"]
                grok_pattern => "<%{NONNEGINT:syslog_pri}>%{NONNEGINT:version}%{SPACE}(?:-|%{TIMESTAMP_ISO8601:syslog_timestamp})%{SPACE}(?:-|%{IPORHOST:hostname})%{SPACE}(?:%{SYSLOG5424PRINTASCII:program}|-)%{SPACE}(?:-|%{SYSLOG5424PRINTASCII:process_id})%{SPACE}(?:-|%{SYSLOG5424PRINTASCII:message_id})%{SPACE}(?:-|(?<structured_data>(\[.*?[^\\]\])+))(?:%{SPACE}%{GREEDYDATA:syslog_message}|)"
        }
        syslog {
                port => 5002
                tags => ["dem.nisr"]
                grok_pattern => "<%{NONNEGINT:syslog_pri}>%{NONNEGINT:version}%{SPACE}(?:-|%{TIMESTAMP_ISO8601:syslog_timestamp})%{SPACE}(?:-|%{IPORHOST:hostname})%{SPACE}(?:%{SYSLOG5424PRINTASCII:program}|-)%{SPACE}(?:-|%{SYSLOG5424PRINTASCII:process_id})%{SPACE}(?:-|%{SYSLOG5424PRINTASCII:message_id})%{SPACE}(?:-|(?<structured_data>(\[.*?[^\\]\])+))(?:%{SPACE}%{GREEDYDATA:syslog_message}|)"
        }
}
filter {

                json {
                   source => "syslog_message"
                     }
                }

output {
        if "prd.rnis" in [tags] {
            elasticsearch {
                hosts => ["elasticsearch:9200"]
                index => "prd.rnis-%{+YYYY.MM.dd}"
                }}
        if "dem.nisr" in [tags] {
            elasticsearch {
                hosts => ["elasticsearch:9200"]
                index => "dem.nisr-%{+YYYY.MM.dd}"
                }}

  stdout { codec => rubydebug }

}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 16, 2019, 2:51pm UTC](https://discuss.elastic.co/t/how-to-handle-multiple-syslog-inputs-with-logstash-to-different-indices/181414/2 "2019-05-16T14:51:54Z")

</div>

Are you saying that there are documents in the prd.rnis index that do not have a prd.rnis tag?

---

<div class="post-metadata">

**Author:** ![colix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colix/32/46274_2.png) [@colix](https://discuss.elastic.co/u/colix)\
**Post date:** [May 16, 2019, 3:14pm UTC](https://discuss.elastic.co/t/how-to-handle-multiple-syslog-inputs-with-logstash-to-different-indices/181414/3 "2019-05-16T15:14:21Z")

</div>

No, I say, that I don't have documents in index dem.nisr. Documents in prd.rnis index only.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 16, 2019, 3:18pm UTC](https://discuss.elastic.co/t/how-to-handle-multiple-syslog-inputs-with-logstash-to-different-indices/181414/4 "2019-05-16T15:18:25Z")

</div>

That suggests nothing is arriving on port 5002.

---

<div class="post-metadata">

**Author:** ![colix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colix/32/46274_2.png) [@colix](https://discuss.elastic.co/u/colix)\
**Post date:** [May 17, 2019, 8:23am UTC](https://discuss.elastic.co/t/how-to-handle-multiple-syslog-inputs-with-logstash-to-different-indices/181414/5 "2019-05-17T08:23:58Z")

</div>

Hmm.. But I see traffic in tcpdump..  
Ok, I wanted be sure, that my config is good.  
I try fix it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2019, 8:24am UTC](https://discuss.elastic.co/t/how-to-handle-multiple-syslog-inputs-with-logstash-to-different-indices/181414/6 "2019-06-14T08:24:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
