# If more than one condition is met, then the log will be collected only once or more than once

**URL:** <https://discuss.elastic.co/t/if-more-than-one-condition-is-met-then-the-log-will-be-collected-only-once-or-more-than-once/362199>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [June 28, 2024, 9:30am UTC](https://discuss.elastic.co/t/if-more-than-one-condition-is-met-then-the-log-will-be-collected-only-once-or-more-than-once/362199 "2024-06-28T09:30:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![DesireWithin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/desirewithin/32/109865_2.png) [@DesireWithin](https://discuss.elastic.co/u/DesireWithin)\
**Post date:** [June 28, 2024, 9:30am UTC](https://discuss.elastic.co/t/if-more-than-one-condition-is-met-then-the-log-will-be-collected-only-once-or-more-than-once/362199/1 "2024-06-28T09:30:40Z")

</div>

Hello, I'm using `autodiscover` in filebeat, I want to know, if there is a pod, name is `my-app-backend`, does it match only the first condition or all (other) condition ? **Was container's log collected once or twice**? I hope only **once**

Here is my filebeat config:

```auto
filebeat.autodiscover:
  providers:
  - type: kubernetes
    hints.enabled: true
    templates:
    - condition:
       contains:
         kubernetes.pod.name: "-backend"
      config:
      - type: container
        paths:
         - /var/log/containers/${data.kubernetes.pod.name}_${data.kubernetes.namespace}_${data.kubernetes.container.name}-*.log
        format: docker
        multiline.type: pattern
        multiline.pattern: '^[0-9]{4}-[0-9]{2}-[0-9]{2}'
        multiline.negate: true
        multiline.match: after
        max_bytes: 5242880
    - condition:
        contains:
          kubernetes.pod.name: "my-app"
      config:
      - type: container
        paths:
         - /var/log/containers/${data.kubernetes.pod.name}_${data.kubernetes.namespace}_${data.kubernetes.container.name}-*.log
        format: docker
        max_bytes: 5242880
    
processors:
  ...

output.kafka:
  ...

```

---

<div class="post-metadata">

**Author:** ![DesireWithin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/desirewithin/32/109865_2.png) [@DesireWithin](https://discuss.elastic.co/u/DesireWithin)\
**Post date:** [June 28, 2024, 9:37am UTC](https://discuss.elastic.co/t/if-more-than-one-condition-is-met-then-the-log-will-be-collected-only-once-or-more-than-once/362199/2 "2024-06-28T09:37:19Z")

</div>

I asked chatgpt, it said filebeat will collect twice. I hope we can have a `continue` keywork just like alertmanager, it allows us to control the behavior of multiple matches:

> **[Configuration | Prometheus](https://prometheus.io/docs/alerting/latest/configuration/#route)**
>
> An open-source monitoring system with a dimensional data model, flexible query language, efficient time series database and modern alerting approach.

---

<div class="post-metadata">

**Author:** ![DesireWithin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/desirewithin/32/109865_2.png) [@DesireWithin](https://discuss.elastic.co/u/DesireWithin)\
**Post date:** [July 10, 2024, 9:04am UTC](https://discuss.elastic.co/t/if-more-than-one-condition-is-met-then-the-log-will-be-collected-only-once-or-more-than-once/362199/3 "2024-07-10T09:04:41Z")

</div>

I really wish filebeat have this feature
