# Logstash-multiple inputs one output problem

**URL:** <https://discuss.elastic.co/t/logstash-multiple-inputs-one-output-problem/138417>\
**Category:** Logstash\
**Created:** [July 3, 2018, 3:31pm UTC](https://discuss.elastic.co/t/logstash-multiple-inputs-one-output-problem/138417 "2018-07-03T15:31:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dnastala](https://avatars.discourse-cdn.com/v4/letter/d/7c8e57/32.png) [@dnastala](https://discuss.elastic.co/u/dnastala)\
**Post date:** [July 3, 2018, 3:31pm UTC](https://discuss.elastic.co/t/logstash-multiple-inputs-one-output-problem/138417/1 "2018-07-03T15:31:31Z")

</div>

Hi all,

I have a configuration misery to solve.

In my current setup I have one logstash server version 5.5.1 that takes two inputs(has to be only one logstash server).  
One is from lumberjack and the other one is from brand new filebeat 6.3.0(lumberjack slowly going away but still needed)  
Input config:

#################################################  
input {  
#collect log from lumberjacks  
lumberjack {  
port =\> "5043"  
ssl\_certificate =\> "some.crt"  
ssl\_key =\> "some.key"   
}  
#collect logs from filebeat  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate\_authorities =\> "some\_ca.crt"  
ssl\_certificate =\> "some.crt"  
ssl\_key =\> "some.key"  
}  
}  
#################################################

I need to pipe it into file output on the logstash, here's my config:

##################################################  
file {  
path =\> "/var/log/logstash-export/%{+YYYY-MM-dd}/%{host}/%{source}.log"  
codec =\> line { format =\> "%{message}"}  
}  
##################################################

The problem is that new filebeat gives a host name in the manner:  
{"name":"hostname.fqdn"}

that lives me with a bunch of directories called that way aside to the directories generated by lumberjack output.  
I can fix filebeat output by modifying "path" to be:  
"/var/log/logstash-export/%{+YYYY-MM-dd}/%{host[name]}/%{source}.log"

But on the other hand that is messing up output of lumberjack output since it's putting them into "host[name]" directory.

Is there any way to tag these two inputs to seperate them on the output file plugin level?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 3, 2018, 5:09pm UTC](https://discuss.elastic.co/t/logstash-multiple-inputs-one-output-problem/138417/2 "2018-07-03T17:09:51Z")

</div>

If I understand your question correctly, then [this](https://discuss.elastic.co/t/logstash-errors-after-upgrading-to-filebeat-6-3-0/135984/7?u=badger) might solve your problem.

Alternatively, you can make the output conditional

```
output {
    if [data from lumberjack] {
        file {
            path => "one thing"
        }
    } else {
        file {
            path => "a different thing"
        }
    }
```

---

<div class="post-metadata">

**Author:** ![dnastala](https://avatars.discourse-cdn.com/v4/letter/d/7c8e57/32.png) [@dnastala](https://discuss.elastic.co/u/dnastala)\
**Post date:** [July 4, 2018, 9:40am UTC](https://discuss.elastic.co/t/logstash-multiple-inputs-one-output-problem/138417/3 "2018-07-04T09:40:24Z")

</div>

Thanks Badger, that works good. If for example I wanted to add other inputs like tcp and syslog can I condition different outputs just for filebeat(since it would be the only one that uses json)? "[data from beats]" or "[data from filebeat]" doesn't seems to have any impact and it's treating everything as one input.

---

<div class="post-metadata">

**Author:** ![dnastala](https://avatars.discourse-cdn.com/v4/letter/d/7c8e57/32.png) [@dnastala](https://discuss.elastic.co/u/dnastala)\
**Post date:** [July 4, 2018, 9:59am UTC](https://discuss.elastic.co/t/logstash-multiple-inputs-one-output-problem/138417/4 "2018-07-04T09:59:39Z")

</div>

got it into the perfection.

```
########################################################
output {
   if "name" in [host] {
       file {
            path => "/var/log/logstash-export/%{+YYYY-MM-dd}/%{host[name]}/%{source}.log"
            codec => line { format => "%{message}"}
            }
       }
   else {
       file {
            path => "/var/log/logstash-export/%{+YYYY-MM-dd}/%{host}/%{source}.log"
            codec => line { format => "%{message}"}
            }
       }
}
########################################################
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 1, 2018, 9:59am UTC](https://discuss.elastic.co/t/logstash-multiple-inputs-one-output-problem/138417/5 "2018-08-01T09:59:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
