# Logstash always output input event type as log

**URL:** <https://discuss.elastic.co/t/logstash-always-output-input-event-type-as-log/46554>\
**Category:** Logstash\
**Created:** [April 6, 2016, 3:21pm UTC](https://discuss.elastic.co/t/logstash-always-output-input-event-type-as-log/46554 "2016-04-06T15:21:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![blnprasad](https://avatars.discourse-cdn.com/v4/letter/b/fbc32d/32.png) [@blnprasad](https://discuss.elastic.co/u/blnprasad)\
**Post date:** [April 6, 2016, 3:21pm UTC](https://discuss.elastic.co/t/logstash-always-output-input-event-type-as-log/46554/1 "2016-04-06T15:21:55Z")

</div>

Hi,  
I've configured logstash input for different type. but when it ouputs elastic search, value of type filed is coming as "log". No matter what i configure type value in input section, it's being outputted as "log". my configuration look like this without filter like below. can you please let me know what's going wrong with this?

input {  
beats {  
port =\> 10044  
type =\> "hotfix"  
ssl =\> false

# ssl\_certificate =\> "/etc/pki/tls/certs/logstash/logstash.crt"

# ssl\_key =\> "/etc/pki/tls/certs/logstash/logstash.key"

}  
}  
output {  
elasticsearch {  
hosts =\> "localhost:9200"  
sniffing =\> true  
manage\_template =\> false  
index =\> "logstash-%{type}-%{+YYYY.MM.dd}" --\> type coming as "log"  
document\_type =\> "%{[@metadata][type]}"  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 7, 2016, 5:56am UTC](https://discuss.elastic.co/t/logstash-always-output-input-event-type-as-log/46554/2 "2016-04-07T05:56:01Z")

</div>

The "log" type comes from the Beats side and it appears Logstash won't overwrite any existing type with the one listed in the input plugin. How about you configure the type in Beats instead?

---

<div class="post-metadata">

**Author:** ![mick66](https://avatars.discourse-cdn.com/v4/letter/m/d2c977/32.png) [@mick66](https://discuss.elastic.co/u/mick66)\
**Post date:** [April 7, 2016, 8:10am UTC](https://discuss.elastic.co/t/logstash-always-output-input-event-type-as-log/46554/3 "2016-04-07T08:10:13Z")

</div>

Further to @magnusbaeck comment

On your source server, edit the filebeat.yml and add `document_type: hotfix` to your prospector. Remove `type => "hotfix"` from your input filter and that should give you what you need.

---

<div class="post-metadata">

**Author:** ![blnprasad](https://avatars.discourse-cdn.com/v4/letter/b/fbc32d/32.png) [@blnprasad](https://discuss.elastic.co/u/blnprasad)\
**Post date:** [April 7, 2016, 9:00am UTC](https://discuss.elastic.co/t/logstash-always-output-input-event-type-as-log/46554/4 "2016-04-07T09:00:06Z")

</div>

Thanks, a lot. that helped.  
I'm also facing an issue when I configure multiple beats(on different ports) in the input section. Each beat receives the same set of logs but from different setups.  
Some reason only one beat at a time working. Another beat connection is being closed with error

```
Beats::Connection::ConnectionClosed wrapping: EOFError, End of file reached>, :level=>:warn}

```

Do I need to add any configuration apart for adding one more beat in input section?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:03am UTC](https://discuss.elastic.co/t/logstash-always-output-input-event-type-as-log/46554/5 "2017-07-06T05:03:21Z")

</div>


