# Logstash Mixing Throttled and Non-Throttled inputs

**URL:** <https://discuss.elastic.co/t/logstash-mixing-throttled-and-non-throttled-inputs/26548>\
**Category:** Logstash\
**Created:** [July 30, 2015, 8:09am UTC](https://discuss.elastic.co/t/logstash-mixing-throttled-and-non-throttled-inputs/26548 "2015-07-30T08:09:42Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Yarden\_Bar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yarden_bar/32/736_2.png) [@Yarden\_Bar](https://discuss.elastic.co/u/Yarden_Bar)\
**Post date:** [July 30, 2015, 8:12am UTC](https://discuss.elastic.co/t/logstash-mixing-throttled-and-non-throttled-inputs/26548/2 "2015-07-30T08:12:58Z")

</div>

Below is Logstash configuration:

> input {  
> lumberjack {  
> host =\> "10.10.10.10"  
> port =\> 5230  
> ssl\_certificate =\> '/ssl/logstash-forwarder.crt'  
> ssl\_key =\> '/ssl/logstash-forwarder.key'  
> }  
> tcp {  
> port =\> 5514  
> type =\> "CDN"  
> ssl\_cert =\> "/ssl/logstash-forwarder.crt"  
> ssl\_key =\> "/ssl/logstash-forwarder.key"  
> ssl\_enable =\> true  
> codec =\> line {  
> charset =\> "ISO-8859-1"  
> }  
> }  
> }  
> filter {  
> Grok filters for Postfix, CDN, Nginx and application logs  
> General structure is:  
> if [type] == “\<SOME\_TYPE\>” {  
> process message with grok and other filter types.  
> }  
> }  
> output {  
> if [@metadata][type] in ["postfix", "CDN"] {  
> elasticsearch {  
> host =\> ["10.10.0.20"]  
> protocol =\> "transport"  
> port =\> "9300"  
> cluster =\> "elasticsearch"  
> index =\> "%{[@metadata][type]}-%{+YYYY.MM.dd}"  
> document\_type =\> "%{[@metadata][type]}"  
> manage\_template =\> false  
> }  
> }  
> **# 3 more elasticsearch outputs to handle the rest of the event types.**  
> else {  
> file {  
> path =\> "/var/log/logstash/unknown\_messages.log"  
> }  
> }  
> }

---

_[View the full topic](https://discuss.elastic.co/t/logstash-mixing-throttled-and-non-throttled-inputs/26548)._
