# Logstash Elasticsearch Output with specific fields to index

**URL:** <https://discuss.elastic.co/t/logstash-elasticsearch-output-with-specific-fields-to-index/140914>\
**Category:** Logstash\
**Created:** [July 20, 2018, 2:31pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-with-specific-fields-to-index/140914 "2018-07-20T14:31:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![chandra0651](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chandra0651/32/30484_2.png) [@chandra0651](https://discuss.elastic.co/u/chandra0651)\
**Post date:** [July 20, 2018, 2:31pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-with-specific-fields-to-index/140914/1 "2018-07-20T14:31:22Z")

</div>

Is there possibility for logstash to ingest whole document to one index and specific fields to other index in the elastic search output.

Example: If i have 10 fields coming in from input , can i write all the fields to one index and some specific fields to other index.

input  
{  
kafka input  
}  
filter  
{  
}  
output  
{

elasticsearch  
{  
hosts=\>[]  
index=\> index for all fields for incoming request  
}  
elasticsearch  
{  
hosts=\>[]  
index=\> index for specific fields from document  
}

}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 20, 2018, 2:39pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-with-specific-fields-to-index/140914/2 "2018-07-20T14:39:31Z")

</div>

Outputs are applied after filters, so to do this could write to elasticsearch in one pipeline and add a second output that writes to a second pipeline. In the second pipeline you can strip off the unwanted fields and write to the second elasticsearch.

You can use tcp output/input bound to localhost to communicate between pipelines (or maybe even the new beta inter-pipeline communications if you are feeling brave).

---

<div class="post-metadata">

**Author:** ![chandra0651](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chandra0651/32/30484_2.png) [@chandra0651](https://discuss.elastic.co/u/chandra0651)\
**Post date:** [July 20, 2018, 2:56pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-with-specific-fields-to-index/140914/3 "2018-07-20T14:56:00Z")

</div>

Thanks this should help will work on and see how does it goes.

---

<div class="post-metadata">

**Author:** ![chandra0651](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chandra0651/32/30484_2.png) [@chandra0651](https://discuss.elastic.co/u/chandra0651)\
**Post date:** [July 26, 2018, 1:37pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-with-specific-fields-to-index/140914/4 "2018-07-26T13:37:50Z")

</div>

This worked with UDP Output/input

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2018, 1:41pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-with-specific-fields-to-index/140914/5 "2018-08-23T13:41:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
