# Logstash - Multiple Logs

**URL:** <https://discuss.elastic.co/t/logstash-multiple-logs/220600>\
**Category:** Logstash\
**Created:** [February 24, 2020, 9:10am UTC](https://discuss.elastic.co/t/logstash-multiple-logs/220600 "2020-02-24T09:10:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![santos1204](https://avatars.discourse-cdn.com/v4/letter/s/b3f665/32.png) [@santos1204](https://discuss.elastic.co/u/santos1204)\
**Post date:** [February 24, 2020, 9:10am UTC](https://discuss.elastic.co/t/logstash-multiple-logs/220600/1 "2020-02-24T09:10:35Z")

</div>

Hi,

I'm just starting to play with ELK, we're looking at shipping different logs with different filters from each server to a centralised place.

filebeat config;

filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so

# you can use different inputs for various configurations.

# Below are the input specific configurations.

- type: log

- type: log

output.logstash:

# The Logstash hosts

hosts: ["10.60.154.69:5044"]

* * *

Logstash config;

input {  
beats {  
port =\> 5044  
}  
}

filter {  
if "guidewire" in [tags] {  
grok {  
match =\> {  
"message" =\> "(?([a-z]{3}[0-9]{2}[a-z]{2}[0-9]{2}){0,1})\s+(?([A-Za-z0-9.@-]\*){0,1})\s+(%{TIMESTAMP\_ISO8601:logdate})?\s+(%{LOGLEVEL:loglevel})\s+%{GREEDYDATA:body}"  
}  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
tag\_on\_failure =\> ["\_not\_interested"]  
}  
if "\_not\_interested" in [tags] {  
drop { }  
}  
else if "aggregator" in [tags] {  
grok {  
match =\> { "message" =\> "%{GREEDYDATA:body}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
}  
}

output {  
if "guidewire" in [tags] {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
index =\> "%{[@metadata]]beat]}-%{+YYYY.MM.dd}"  
}  
if "aggregator" in [tags] {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
}  
}

Doesn't seem to work, any help would be appreciated.

Thanks,

Chris

---

<div class="post-metadata">

**Author:** ![santos1204](https://avatars.discourse-cdn.com/v4/letter/s/b3f665/32.png) [@santos1204](https://discuss.elastic.co/u/santos1204)\
**Post date:** [February 26, 2020, 8:23am UTC](https://discuss.elastic.co/t/logstash-multiple-logs/220600/2 "2020-02-26T08:23:12Z")

</div>

Anyone?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 26, 2020, 2:49pm UTC](https://discuss.elastic.co/t/logstash-multiple-logs/220600/3 "2020-02-26T14:49:57Z")

</div>

> [@santos1204](#):
>
> Doesn't seem to work, any help would be appreciated.

Please edit your post and format it using [markdown](https://github.com/adam-p/markdown-here/wiki/Markdown-Cheatsheet). Also, you have not given any indication of _how_ it does not work. You cannot expect us to guess.

---

<div class="post-metadata">

**Author:** ![santos1204](https://avatars.discourse-cdn.com/v4/letter/s/b3f665/32.png) [@santos1204](https://discuss.elastic.co/u/santos1204)\
**Post date:** [March 9, 2020, 11:06am UTC](https://discuss.elastic.co/t/logstash-multiple-logs/220600/4 "2020-03-09T11:06:21Z")

</div>

Hi,

Sorry - I can't see a way to edit the original post?

I'd like it to take the first batch of the logs and process them using the pattern before passing them to logstash, which seems to work fine in isolation. When I add the second log paths in it seems to ignore them - so was wondering on the correct syntax to add multiple log paths in and process different logs..

Thanks,

Chris

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2020, 11:06am UTC](https://discuss.elastic.co/t/logstash-multiple-logs/220600/5 "2020-04-06T11:06:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
