# Logstash for multi output

**URL:** <https://discuss.elastic.co/t/logstash-for-multi-output/98650>\
**Category:** Logstash\
**Created:** [August 29, 2017, 8:12am UTC](https://discuss.elastic.co/t/logstash-for-multi-output/98650 "2017-08-29T08:12:14Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![truongdqse03303](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/truongdqse03303/32/22605_2.png) [@truongdqse03303](https://discuss.elastic.co/u/truongdqse03303)\
**Post date:** [August 29, 2017, 8:12am UTC](https://discuss.elastic.co/t/logstash-for-multi-output/98650/1 "2017-08-29T08:12:14Z")

</div>

Hi experts.  
I have this logstash input

```
input {
  beats {
    type => "beat"
    port => 5044
    ssl => false
    #ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
    #ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
  }
  redis {
    host => " *********"
    data_type => "list"
    key => "filebeat"
    type => "app2"
  }
  redis {
    host => " *********"
    data_type => "list"
    key => "app1"
    type => "app1"
  }
}

```

and the output:

```
output {
  if [type] == "beat" {
    elasticsearch {
      hosts => [" ********* :9200"]
      sniffing => true
      manage_template => false
      index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
      document_type => "%{[@metadata][type]}"
    }
  }
  else {
    elasticsearch {
      hosts => [" ********* :9200"]
      sniffing => true
      manage_template => false
      }
  }
}

```

My purpose is beats come to it own index and the other input come to logstash-\* index but when i use the [type], it's not working so i ask is beats have any special condition that i can use to solve my problems?  
Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 29, 2017, 8:19am UTC](https://discuss.elastic.co/t/logstash-for-multi-output/98650/2 "2017-08-29T08:19:28Z")

</div>

> [@truongdqse03303](#):
>
> My purpose is beats come to it own index and the other input come to logstash-\* index but when i use the [type], it’s not working

What does that mean exactly?

---

<div class="post-metadata">

**Author:** ![truongdqse03303](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/truongdqse03303/32/22605_2.png) [@truongdqse03303](https://discuss.elastic.co/u/truongdqse03303)\
**Post date:** [August 29, 2017, 8:24am UTC](https://discuss.elastic.co/t/logstash-for-multi-output/98650/3 "2017-08-29T08:24:50Z")

</div>

I mean with all the beat input like metricbeat, heartbeat, ... it's go to

```
elasticsearch {
      hosts => [" ********* :9200"]
      sniffing => true
      manage_template => false
      index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
      document_type => "%{[@metadata][type]}"
    }

```

and with other input not beats go to

```
elasticsearch {
      hosts => [" ********* :9200"]
      sniffing => true
      manage_template => false
      }

```

which is logtstash-\* as default index

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 29, 2017, 8:46am UTC](https://discuss.elastic.co/t/logstash-for-multi-output/98650/4 "2017-08-29T08:46:51Z")

</div>

Yes, but what's not working?

---

<div class="post-metadata">

**Author:** ![truongdqse03303](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/truongdqse03303/32/22605_2.png) [@truongdqse03303](https://discuss.elastic.co/u/truongdqse03303)\
**Post date:** [August 29, 2017, 8:49am UTC](https://discuss.elastic.co/t/logstash-for-multi-output/98650/5 "2017-08-29T08:49:57Z")

</div>

Hi @warkolm  
The condition if [type] == "beat" is not working, it's cannot cover all the beat, i have check the type of beat output in kibana, even i add the [type] in the beat input but the beat output not have that [type]

> beats {  
> type =\> "beat"

so if i use the condition like my output i just poseted, all come to logstash-\* index

---

<div class="post-metadata">

**Author:** ![truongdqse03303](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/truongdqse03303/32/22605_2.png) [@truongdqse03303](https://discuss.elastic.co/u/truongdqse03303)\
**Post date:** [August 30, 2017, 4:46am UTC](https://discuss.elastic.co/t/logstash-for-multi-output/98650/6 "2017-08-30T04:46:12Z")

</div>

Hi @warkolm  
can you help me with this or i should use 2 logstash, 1 for log and 1 for beat ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2017, 4:46am UTC](https://discuss.elastic.co/t/logstash-for-multi-output/98650/7 "2017-09-27T04:46:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
