# Logstash – Both elasticsearch and email outputs

**URL:** <https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714>\
**Category:** Logstash\
**Created:** [July 16, 2015, 11:01am UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714 "2015-07-16T11:01:55Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ben19](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ben19/32/3745_2.png) [@Ben19](https://discuss.elastic.co/u/Ben19)\
**Post date:** [July 16, 2015, 11:01am UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714/1 "2015-07-16T11:01:56Z")

</div>

Hello,

Please can some provide an example config that provides two  
outputs of the same input (syslog)?

I’m wanting to pass syslogs both to elasticserarch and  
email.

The below is my current output conf, the e-mail section  
works but I’m struggling with including both the elastic one and email:

```
output {
# elasticsearch { host => localhost }
# stdout { codec => rubydebug }
#}
email {
        to => "mysmtp"
        from => "ELK-Alert-Notifs@domain"
        via => "smtp"
        subject => "ELK Syslog Alerting Concerning Host %{host}."
        body => "This syslog has an interesting string and thus picked up on host (%{host}). Via this message: %{message}"
}
}

```

Note I’ve deliberately hashed out the entries above the  
email plugin.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 16, 2015, 11:10am UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714/2 "2015-07-16T11:10:40Z")

</div>

The email output needs to be inside the output block.

```
output {
  elasticsearch {
    ...
  }
  email {
    ..
  }
}
```

---

<div class="post-metadata">

**Author:** ![Ben19](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ben19/32/3745_2.png) [@Ben19](https://discuss.elastic.co/u/Ben19)\
**Post date:** [July 16, 2015, 11:37am UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714/3 "2015-07-16T11:37:03Z")

</div>

I believe I’ve done this as you advised:

```
    output {
      elasticsearch { host => localhost }
      stdout { codec => rubydebug }
    }
    email {
            to => "mysmtp"
            from => "ELK-Alert-Notifs@mydomain"
            via => "smtp"
            subject => "ELK Syslog Alerting Concerning Host %{host}."
            body => "This syslog has an interesting string and thus picked up on host (%{host}). Via this message: %{message}"
    }
 }
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 16, 2015, 11:40am UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714/4 "2015-07-16T11:40:32Z")

</div>

No, you have an extra closing brace on the line right before "email". That brace closes the output block.

---

<div class="post-metadata">

**Author:** ![Ben19](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ben19/32/3745_2.png) [@Ben19](https://discuss.elastic.co/u/Ben19)\
**Post date:** [July 16, 2015, 1:49pm UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714/5 "2015-07-16T13:49:53Z")

</div>

Thanks Magnus that worked.

Just one last question, we'll be wanting to use maybe the IF module to check for strings/REGEX in the syslogs and e-mail them out, everything would be syslogged but only this string/regex would be e-mailed.

I'm guessing `if "string/regex" in [message] {` would be the syntax but where exactly would it go in my config please?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 16, 2015, 1:58pm UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714/6 "2015-07-16T13:58:49Z")

</div>

Yes, you'll want to use a conditional block here. See the documentation for details and examples. Your conditional should surround the email output.

```
if ... {
  email {
    ...
  }
}
```

---

<div class="post-metadata">

**Author:** ![Ben19](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ben19/32/3745_2.png) [@Ben19](https://discuss.elastic.co/u/Ben19)\
**Post date:** [July 16, 2015, 3:34pm UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714/7 "2015-07-16T15:34:26Z")

</div>

> [@magnusbaeck](#):
>
> conditional bloc

I have this config to send emails on if Apache exists in the  
message field, but it sends e-mails out regardless. I’m guessing the IF  
statement is correct but there is no closing such as IF not exist and the email  
plugin is still being used?

```
output {
  elasticsearch { host => localhost }
  stdout { codec => rubydebug }
if [message] in "Apache" {
email {
        to => "mysmtp"
        from => "ELK-Alert-Notifs@mydomain"
        via => "smtp"
        subject => "ELK Syslog Alerting Concerning Host %{host}."
        body => "This syslog has an interesting string and thus picked up on host (%{host}). Via this message: %{message}"
   }
 }
}

```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 16, 2015, 4:57pm UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714/8 "2015-07-16T16:57:44Z")

</div>

Your conditional is backwards. This is what you should use:

```
if "Apache" in [message] {

```

It's surprising that you get any email. I'd imagine that your backwards conditional would never match.

---

<div class="post-metadata">

**Author:** ![Ben19](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ben19/32/3745_2.png) [@Ben19](https://discuss.elastic.co/u/Ben19)\
**Post date:** [July 17, 2015, 9:13am UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714/9 "2015-07-17T09:13:06Z")

</div>

I still seem to get all the e-mails out of both outputs  
rather than one only with a string, this is what the output looks like:

```
output {
  elasticsearch { host => localhost }
  stdout { codec => rubydebug }
if "Apache" in [message] {
email {
        to => "ben.lavender@virtualdcs.co.uk"
        from => "ELK-Alert-Notifs@Nimbox.co.uk"
        via => "smtp"
        subject => "ELK Syslog Alerting Concerning Host %{host}."
        body => "This syslog has an interesting string and thus picked up on host (%{host}). Via this message: %{message}"
   }
 }
}

```

Maybe it's an issue with the grok coding in my filter conf:

```
filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    syslog_pri { }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 17, 2015, 9:52am UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714/10 "2015-07-17T09:52:28Z")

</div>

Are you running Logstash as a daemon or by hand from a shell? In the former case, do you have any additional files in /etc/logstash/conf.d? Logstash will read (almost) all files in that directory.

---

<div class="post-metadata">

**Author:** ![Ben19](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ben19/32/3745_2.png) [@Ben19](https://discuss.elastic.co/u/Ben19)\
**Post date:** [July 17, 2015, 10:51am UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714/11 "2015-07-17T10:51:50Z")

</div>

Good question about other files in that directory, I was  
aware logstash will read files any .conf in that dir, having said that I've  
found a file named ~? and it contained the below:

```
output {
# elasticsearch { host => localhost }
# stdout { codec => rubydebug }
#}
email {
        to => "mysmtp"
        from => "ELK-Alert-Notifs@mydomain"
        via => "smtp"
        subject => "ELK Syslog Alerting Concerning Host %{host}."
        body => "This syslog has an interesting string and thus picked up on host (%{host}). Via this message: %{message}"
}
}

```

So obvisuly that was the problem and it was configured to  
bang it all out via e-mail.

I have been backing up the .confs to ~/ and must have at some  
point just missed the / off and it’s placed it back in the working directly.

I’m testing this now (so far so good) and will  
update you shortly Magnus, thanks so far btw.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 17, 2015, 11:03am UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714/12 "2015-07-17T11:03:28Z")

</div>

If the file really is named ~? (tilde questionmark) you probably accidentally pressed the shift key, causing the slash you intended to become a question mark.

Configuration files whose name ends with a tilde are ignored (below) but this doesn't cover files with an extra question mark at the end.

> <https://github.com/elastic/logstash/blob/0e3b54db64ef2437e224d8bdc79e17c714563634/lib/logstash/agent.rb#L291-L294>

---

<div class="post-metadata">

**Author:** ![Ben19](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ben19/32/3745_2.png) [@Ben19](https://discuss.elastic.co/u/Ben19)\
**Post date:** [July 23, 2015, 2:46pm UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714/13 "2015-07-23T14:46:28Z")

</div>

Thanks Magnus I’ll take note of that. I’ve got an issue that  
has now developmed on one of our single-node clusters, strange as this exact  
output conf resulting in correct opersation during testing but as soon as I  
loaded it onto the other cluster (all /etc/logstash/conf.d/\*.conf files exactly  
the same the server doesn’t generate an e-mail.

I’ve even ran a pcap using TCPdump and no smtp data is even  
generated…

```
output {
  elasticsearch { host => localhost }
  stdout { codec => rubydebug }
if "Apache" in [message] {
email {
        to => "mysmtp"
        from => "Syslog-Alerts@domain.com"
        via => "smtp"
        subject => "ELK Syslog Alerting Concerning Host %{host}."
        body => "This syslog has an interesting string and thus picked up on host (%{host}). Via this message: %{message}"
   }
} else if "[mpm_winnt:notice]" in [message] {
email {
        to => "mysmtp"
        from => "Syslog-Alerts@domain.com"
        via => "smtp"
        subject => "MPM Notice from Web Host %{host}."
        body => "%{message}"
  }
} else if "InstallType: upgrade" in [message] {
email {
        to => "mysmtp"
        from => "Syslog-Alerts@domain.com"
        via => "smtp"
        subject => "An Upgrade Notice on Host: %{host}."
        body => "%{message}"
  }
} else if "[BST]" in [message] {
email {
        to => "mysmtp"
        from => "Syslog-Alerts@domain.com"
        via => "smtp"
        subject => "PostgreSQL System Log from %{host}."
        body => "I would suggest looking into BST logs since we turned off PG debugging, here is the message field: %{message}"
  }
 }
}

```

I’ve edited out the smtps btw

---

<div class="post-metadata">

**Author:** ![DreadPirateRob](https://avatars.discourse-cdn.com/v4/letter/d/b5ac83/32.png) [@DreadPirateRob](https://discuss.elastic.co/u/DreadPirateRob)\
**Post date:** [July 5, 2016, 8:28pm UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714/14 "2016-07-05T20:28:00Z")

</div>

did you get this figured out? if so, can you post up the config files?

I am also working on emailing the log if a certain condition is met.

---

<div class="post-metadata">

**Author:** ![Ben19](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ben19/32/3745_2.png) [@Ben19](https://discuss.elastic.co/u/Ben19)\
**Post date:** [July 20, 2016, 10:59am UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714/15 "2016-07-20T10:59:04Z")

</div>

I can if you still need it?

---

<div class="post-metadata">

**Author:** ![DreadPirateRob](https://avatars.discourse-cdn.com/v4/letter/d/b5ac83/32.png) [@DreadPirateRob](https://discuss.elastic.co/u/DreadPirateRob)\
**Post date:** [August 2, 2016, 1:47pm UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714/16 "2016-08-02T13:47:00Z")

</div>

please do so, thanks.

---

<div class="post-metadata">

**Author:** ![Ben19](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ben19/32/3745_2.png) [@Ben19](https://discuss.elastic.co/u/Ben19)\
**Post date:** [March 24, 2017, 8:38pm UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714/17 "2017-03-24T20:38:00Z")

</div>

Couple of people have contacted me for the code, a simple one is below:

```
output {

```

elasticsearch {  
hosts =\> localhost  
index =\> "syslogs-%{+YYYY.MM.dd}" }  
stdout { codec =\> rubydebug }  
if "string" in [message] {  
email {  
to =\> "smtp\_address"  
from =\> "smtp\_address"  
via =\> "smtp"  
subject =\> "Subject from %{host}."  
body =\> "Body"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:27am UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714/18 "2017-07-06T04:27:33Z")

</div>


