# How to raw logs to logstash default index and filtered log to another index

**URL:** <https://discuss.elastic.co/t/how-to-raw-logs-to-logstash-default-index-and-filtered-log-to-another-index/86517>\
**Category:** Logstash\
**Created:** [May 20, 2017, 7:56am UTC](https://discuss.elastic.co/t/how-to-raw-logs-to-logstash-default-index-and-filtered-log-to-another-index/86517 "2017-05-20T07:56:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![shamimgeek](https://avatars.discourse-cdn.com/v4/letter/s/ba8739/32.png) [@shamimgeek](https://discuss.elastic.co/u/shamimgeek)\
**Post date:** [May 20, 2017, 7:56am UTC](https://discuss.elastic.co/t/how-to-raw-logs-to-logstash-default-index-and-filtered-log-to-another-index/86517/1 "2017-05-20T07:56:39Z")

</div>

Hi All,  
How can i configure logstash which can send all logs to default logstash-xxxx index and filtered log { i want only specific fields} will go to analytics index.

But I also want to have all raw logs in logstash index. Kindly help me.

Thanks  
Shamim Akhtar

input {

# 

# This will allow for health check from Marathon

# 

http {  
port =\> 31210  
type =\> "elb-healthcheck"  
}

# Default port is 12201/udp

gelf { port =\> 31212 }

}

filter {

some filter

}

output {

// here i want filterd log  
elasticsearch {  
hosts =\> ["host:port"]  
index =\> "business-%{+YYYY.MM.dd}"  
document\_type =\> "analytics"  
}  
// here i want all raw log  
elasticsearch {  
hosts =\> ["host:port"]  
index =\> "logstash-%{+YYYY.MM.dd}"  
document\_type =\> "log"  
}

}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 20, 2017, 8:39am UTC](https://discuss.elastic.co/t/how-to-raw-logs-to-logstash-default-index-and-filtered-log-to-another-index/86517/2 "2017-05-20T08:39:27Z")

</div>

You can do that using this method - [https://www.elastic.co/guide/en/logstash/current/config-examples.html#using-conditionals](https://www.elastic.co/guide/en/logstash/current/config-examples.html#using-conditionals)

---

<div class="post-metadata">

**Author:** ![shamimgeek](https://avatars.discourse-cdn.com/v4/letter/s/ba8739/32.png) [@shamimgeek](https://discuss.elastic.co/u/shamimgeek)\
**Post date:** [May 20, 2017, 9:25am UTC](https://discuss.elastic.co/t/how-to-raw-logs-to-logstash-default-index-and-filtered-log-to-another-index/86517/3 "2017-05-20T09:25:31Z")

</div>

@warkolm :

Thanks for your reply.

if i do condition and output to different index. filtered log goes to business-index but raw log for login activity then does not go to default index.

what i want to do all login activity filtered log will go to business index and everything without filtered log will go to default logstash-xxx index

Thanks for your support.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 24, 2017, 9:25am UTC](https://discuss.elastic.co/t/how-to-raw-logs-to-logstash-default-index-and-filtered-log-to-another-index/86517/4 "2017-05-24T09:25:37Z")

</div>

```nohighlight
if ... {
  elasticsearch {
    index => "business"
    ...
  }
}
elasticsearch {
  ...
}

```

Replace the first `...` with whatever condition that matches login activity.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2017, 9:26am UTC](https://discuss.elastic.co/t/how-to-raw-logs-to-logstash-default-index-and-filtered-log-to-another-index/86517/5 "2017-06-21T09:26:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
