# How to query 3 indexes in logstash

**URL:** <https://discuss.elastic.co/t/how-to-query-3-indexes-in-logstash/339785>\
**Category:** Logstash\
**Created:** [August 1, 2023, 10:41am UTC](https://discuss.elastic.co/t/how-to-query-3-indexes-in-logstash/339785 "2023-08-01T10:41:50Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![willsy](https://avatars.discourse-cdn.com/v4/letter/w/f17d59/32.png) [@willsy](https://discuss.elastic.co/u/willsy)\
**Post date:** [August 1, 2023, 10:41am UTC](https://discuss.elastic.co/t/how-to-query-3-indexes-in-logstash/339785/1 "2023-08-01T10:41:50Z")

</div>

In logstash i am trying to forward all of the logs in elasticsearch into logstash and then to a third party. What is the correct configuration for the index query?

```auto
# Sample Logstash configuration for creating a simple
# Beats -> Logstash -> Elasticsearch pipeline.

input {
 elasticsearch {
 hosts => "localhost:9200"
 ssl_enabled => true
 ssl_verification_mode => none
 api_key => "XXxxXXxxXX" 
 index => ["logs-cisco_ios.log-default", "logs-windows.powershell-default"]
 query => '{ "query": { "query_string": { "query": "*" } } }'
 size => 10
schedule => "*/1 * * * *"
 scroll => "1m"
 docinfo => true
 docinfo_target => "[@metadata][doc]"
}
}

output {
tcp {
host => "A.B.C.D"
port => XYZ
codec => json_lines
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 29, 2023, 10:42am UTC](https://discuss.elastic.co/t/how-to-query-3-indexes-in-logstash/339785/2 "2023-08-29T10:42:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
