# Logstash indexing all logs to the index of first log

**URL:** <https://discuss.elastic.co/t/logstash-indexing-all-logs-to-the-index-of-first-log/182275>\
**Category:** Logstash\
**Created:** [May 22, 2019, 3:56pm UTC](https://discuss.elastic.co/t/logstash-indexing-all-logs-to-the-index-of-first-log/182275 "2019-05-22T15:56:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![apr589](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/apr589/32/46649_2.png) [@apr589](https://discuss.elastic.co/u/apr589)\
**Post date:** [May 22, 2019, 3:56pm UTC](https://discuss.elastic.co/t/logstash-indexing-all-logs-to-the-index-of-first-log/182275/1 "2019-05-22T15:56:04Z")

</div>

Hi ,I have a log file in which first few events have a timestamp of 2019.01.13 and rest all events have a timestamp of 2019.01.14 . Now I am indexing based on @timestamp but all the events of the file are getting indexed to 2019.01.13 instead of the expected behavior of first few going to 2019.01.13 and rest to 2019.01.14. Can someone point out the issue  
My conf -

> input{  
> file {  
> path =\> "/home/av/Documents/UPI\_LOGS/\*\*/\*.gz"  
> mode =\> read  
> type =\> "upi\_logs"  
> }  
> }
> 
> filter {  
> grok {  
> match =\> { "message" =\>"%{TIMESTAMP\_ISO8601:timestamp} %{NUMBER:num} [%{DATA:module}] \*%{LOGLEVEL:level} %{USERNAME:class} - %{GREEDYDATA:log}"}
> 
> }
> 
> ```
> date{
> 
> match=>["timestamp","YYYY-MM-dd HH:mm:ss.SSS"]
> target => "@timestamp"
> }
> 
> json{
> 
> source => "log"
> target => "parsdlog"
> }
> 
> if "_jsonparsefailure" in [tags]
> 
> ```
> 
> {  
> drop {}  
> }  
> }
> 
> output {  
> stdout{}  
> elasticsearch {  
> hosts =\> ["localhost:9200"]  
> index =\> "upi\_analytics-%{+YYYY.MM.dd}"  
> sniffing =\> true
> 
> ```
> }
> }
> 
> ```

---

<div class="post-metadata">

**Author:** ![apr589](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/apr589/32/46649_2.png) [@apr589](https://discuss.elastic.co/u/apr589)\
**Post date:** [May 27, 2019, 10:02am UTC](https://discuss.elastic.co/t/logstash-indexing-all-logs-to-the-index-of-first-log/182275/2 "2019-05-27T10:02:29Z")

</div>

It was a problem with my indexing . Resolved now .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 24, 2019, 10:02am UTC](https://discuss.elastic.co/t/logstash-indexing-all-logs-to-the-index-of-first-log/182275/3 "2019-06-24T10:02:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
