# Logs going to the wrong index

**URL:** <https://discuss.elastic.co/t/logs-going-to-the-wrong-index/104955>\
**Category:** Logstash\
**Created:** [October 23, 2017, 6:59pm UTC](https://discuss.elastic.co/t/logs-going-to-the-wrong-index/104955 "2017-10-23T18:59:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![shroh](https://avatars.discourse-cdn.com/v4/letter/s/74df32/32.png) [@shroh](https://discuss.elastic.co/u/shroh)\
**Post date:** [October 23, 2017, 6:59pm UTC](https://discuss.elastic.co/t/logs-going-to-the-wrong-index/104955/1 "2017-10-23T18:59:55Z")

</div>

Hi ,

I have three logstash config files 00\_inputs.conf, 01\_app1.conf, 02\_app2.conf.  
01\_inputs.conf just defines the beats input and thats it, nothing more.

**02\_app1.conf**

filter {  
if [fields][index] == "app\_fischer" {  
mutate {  
replace =\> {  
"[@metadata][index]" =\> "%{[fields][index]}"  
}  
}  
}  
}  
output {  
elasticsearch {  
hosts =\> "[http://elasticco-qa-e.domain.com:80](http://elasticco-qa-e.domain.com:80)"  
#manage\_template =\> false  
index =\> app\_fischer  
user =\> elastic  
password =\> changeme  
}  
stdout { codec =\> rubydebug}

**01\_app.conf**

filter {  
if [fields][source] == "app\_tomcat\_perf" {

```
                  grok {
                       match => {"message" => "%{MONTHDAY} %{MONTH} %{YEAR} %{TIME},%{NUMBER:duration} %{WORD:loglevel} %{WORD:Activity} \[\{%{DATA:foo1}\}\]:(.*) execution time: %{NUMBER:executionTime:float} ms"}
        }

```

}  
output {  
elasticsearch {  
hosts =\> "[http://elasticco-qa-e.domain.com:80](http://elasticco-qa-e.domain.com:80)"  
#manage\_template =\> false  
index =\> harmonic  
user =\> elastic  
password =\> changeme  
}  
stdout { codec =\> rubydebug}  
}

But i see a strange behaviour, the logs are going to the wrong index. I mean the logs which should be going to the index defined in **02\_app1.conf** are actually going to the index defined in **01\_app.conf**.

When i search the elastic search through GET , i can see that \_index has the mismatch. Need to know what could be the reason. Is it that the ordering of the files is wrong and which ever file is first ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 23, 2017, 8:12pm UTC](https://discuss.elastic.co/t/logs-going-to-the-wrong-index/104955/2 "2017-10-23T20:12:22Z")

</div>

With your configuration all events will go to both the harmonic and app\_fischer indexes. You'll have to wrap your elasticsearch outputs in conditionals (similar to your filters) to get another behavior.

---

<div class="post-metadata">

**Author:** ![shroh](https://avatars.discourse-cdn.com/v4/letter/s/74df32/32.png) [@shroh](https://discuss.elastic.co/u/shroh)\
**Post date:** [October 25, 2017, 3:20pm UTC](https://discuss.elastic.co/t/logs-going-to-the-wrong-index/104955/3 "2017-10-25T15:20:51Z")

</div>

Thanks Magnus, it worked.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2017, 3:21pm UTC](https://discuss.elastic.co/t/logs-going-to-the-wrong-index/104955/4 "2017-11-22T15:21:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
