# IF/THEN in output config not working properly

**URL:** <https://discuss.elastic.co/t/if-then-in-output-config-not-working-properly/117390>\
**Category:** Logstash\
**Created:** [January 29, 2018, 2:19am UTC](https://discuss.elastic.co/t/if-then-in-output-config-not-working-properly/117390 "2018-01-29T02:19:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pvols1979](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pvols1979/32/27053_2.png) [@pvols1979](https://discuss.elastic.co/u/pvols1979)\
**Post date:** [January 29, 2018, 2:19am UTC](https://discuss.elastic.co/t/if-then-in-output-config-not-working-properly/117390/1 "2018-01-29T02:19:59Z")

</div>

I have created an output config for Logstash and attempted to specify which index for a few different feeds to go by using if then else statements in the config file. Reagardless of what I try, Data I do not want in the first filter ends up in that index and the one I specified for it. Data that is supposed to be cause by the first IF statement is nowhere to be found.

I am trying to isolate each data source in its own index without much luck. See the config below:

> output  
> {
> 
> if [type] == "tomato"  
> {  
> elasticsearch  
> {  
> hosts =\> "192.168.1.5:9200"  
> index =\> "tomato-%{+YYYY.MM.dd}"  
> }  
> }
> 
> else if "192.168.1.254" in [host]  
> {  
> elasticsearch  
> {  
> hosts =\> "192.168.1.5:9200"  
> index =\> "pfsense-%{+YYYY.MM.dd}"  
> }  
> }
> 
> else  
> {  
> elasticsearch  
> {  
> hosts =\> "192.168.1.5:9200"  
> index =\> "logstash-%{+YYYY.MM.dd}"  
> }  
> }
> 
> stdout  
> {  
> codec =\> rubydebug  
> }
> 
> }

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 29, 2018, 5:19am UTC](https://discuss.elastic.co/t/if-then-in-output-config-not-working-properly/117390/2 "2018-01-29T05:19:57Z")

</div>

Please give an example of an event that ended up in the wrong place. Copy the raw JSON event from Kibana's JSON tab.

---

<div class="post-metadata">

**Author:** ![pvols1979](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pvols1979/32/27053_2.png) [@pvols1979](https://discuss.elastic.co/u/pvols1979)\
**Post date:** [January 29, 2018, 7:29pm UTC](https://discuss.elastic.co/t/if-then-in-output-config-not-working-properly/117390/3 "2018-01-29T19:29:17Z")

</div>

See below. The expected outcome was for this to end up in the pfsense -"date" index...which it did. However, it is also in the tomato index.

{  
"\_index": "tomato-2018.01.29",  
"\_type": "doc",  
"\_id": "s9LCP2EBkOR6wJ8oDxnP",  
"\_version": 1,  
"\_score": null,  
"\_source": {  
"dest\_ip": "144.76.59.84",  
"action": "pass",  
"proto": "udp",  
"tags": [  
"PFSense",  
"firewall",  
"GeoIP"  
],  
"@version": "1",  
"src\_port": "19318",  
"dest\_port": "25903",  
"src\_ip": "76.73.142.47",  
"geoip": {  
"timezone": "America/Chicago",  
"country\_name": "United States",  
"region\_code": "AL",  
"longitude": -86.5863,  
"location": {  
"lon": -86.5863,  
"lat": 32.5141  
},  
"city\_name": "Prattville",  
"postal\_code": "36067",  
"dma\_code": 698,  
"country\_code2": "US",  
"ip": "76.73.142.47",  
"continent\_code": "NA",  
"country\_code3": "US",  
"region\_name": "Alabama",  
"latitude": 32.5141  
},  
"reason": "match",  
"ip\_ver": "4",  
"tracker": "1000003811",  
"offset": "0",  
"direction": "out",  
"rule": "40",  
"flags": "DF",  
"message": "40,,,1000003811,em0,match,pass,out,4,0x0,,3,18442,0,DF,17,udp,28,76.73.142.47,144.76.59.84,19318,25903,8",  
"evtid": "134",  
"length": "28",  
"ttl": "3",  
"prog": "filterlog",  
"iface": "em0",  
"id": "18442",  
"@timestamp": "2018-01-29T02:32:18.000Z",  
"data\_length": "8",  
"host": "192.168.1.254",  
"type": "syslog",  
"tos": "0x0",  
"proto\_id": "17"  
},  
"fields": {  
"@timestamp": [  
"2018-01-29T02:32:18.000Z"  
]  
},  
"sort": [  
1517193138000  
]  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 29, 2018, 8:56pm UTC](https://discuss.elastic.co/t/if-then-in-output-config-not-working-properly/117390/4 "2018-01-29T20:56:27Z")

</div>

Do you have additional configuration files in /etc/logstash/conf.d (or wherever you keep them)? Do any of those files contain an elasticsearch output pointing to the tomato index?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2018, 8:56pm UTC](https://discuss.elastic.co/t/if-then-in-output-config-not-working-properly/117390/5 "2018-02-26T20:56:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
