# Logstash on kubernetes. Multiple output conditions

**URL:** <https://discuss.elastic.co/t/logstash-on-kubernetes-multiple-output-conditions/205087>\
**Category:** Logstash\
**Created:** [October 24, 2019, 2:16pm UTC](https://discuss.elastic.co/t/logstash-on-kubernetes-multiple-output-conditions/205087 "2019-10-24T14:16:44Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Khuman](https://avatars.discourse-cdn.com/v4/letter/k/ba9def/32.png) [@Khuman](https://discuss.elastic.co/u/Khuman)\
**Post date:** [October 24, 2019, 2:16pm UTC](https://discuss.elastic.co/t/logstash-on-kubernetes-multiple-output-conditions/205087/1 "2019-10-24T14:16:44Z")

</div>

Hi, guys!

I want to manipulate output indexes in my output section. The config example below don't work. I need insert data into one index when host\_name index is present or another if not.  
Field kubernetes.labels.devops\_destination field in both condition should be == "logs"

```
output {
  if [vs-service] == "nameofservice" {
    elasticsearch {
      hosts => ["${ELASTICSEARCH_HOST}:${ELASTICSEARCH_PORT}"]
      manage_template => false
      ssl_certificate_verification => false
      user => "user"
      password => "${PASSWORD}"
      index => "%{[vs_service]}_%{[accountcode]}"
    }
  }
  else if [kubernetes][labels][devops_destination] == "logs" and "" in [host_name] {
    elasticsearch {
      hosts => ["${ELASTICSEARCH_HOST}:${ELASTICSEARCH_PORT}"]
      manage_template => false
      ssl_certificate_verification => false
      user => "user"
      password => "${PASSWORD}"
      index => "%{[kubernetes][labels][devops_destination]}-%{[host_name]}-%{+YYYY.MM.dd}"
    }
  }
  else if [kubernetes][labels][devops_destination] == "logs" {
    elasticsearch {
      hosts => ["${ELASTICSEARCH_HOST}:${ELASTICSEARCH_PORT}"]
      manage_template => false
      ssl_certificate_verification => false
      user => "user"
      password => "${PASSWORD}"
      index => "%{[kubernetes][labels][devops_destination]}-%{[kubernetes][namespace]}-%{+YYYY.MM.dd}"
    }
  }
  else {
    elasticsearch {
      hosts => ["${ELASTICSEARCH_HOST}:${ELASTICSEARCH_PORT}"]
      manage_template => false
      ssl_certificate_verification => false
      user => "user"
      password => "${PASSWORD}"
      index => "recyclebin-%{+YYYY.MM.dd}"
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 25, 2019, 12:46pm UTC](https://discuss.elastic.co/t/logstash-on-kubernetes-multiple-output-conditions/205087/2 "2019-10-25T12:46:13Z")

</div>

> [@Khuman](#):
>
> and "" in [host\_name]

What do you think that means?

---

<div class="post-metadata">

**Author:** ![Khuman](https://avatars.discourse-cdn.com/v4/letter/k/ba9def/32.png) [@Khuman](https://discuss.elastic.co/u/Khuman)\
**Post date:** [October 25, 2019, 12:55pm UTC](https://discuss.elastic.co/t/logstash-on-kubernetes-multiple-output-conditions/205087/3 "2019-10-25T12:55:02Z")

</div>

I think, this field is exist.  
I looking for condition checking existence field and not null

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 25, 2019, 1:06pm UTC](https://discuss.elastic.co/t/logstash-on-kubernetes-multiple-output-conditions/205087/4 "2019-10-25T13:06:53Z")

</div>

I think you want

```
else if [kubernetes][labels][devops_destination] == "logs" and [host_name] {
```

---

<div class="post-metadata">

**Author:** ![Khuman](https://avatars.discourse-cdn.com/v4/letter/k/ba9def/32.png) [@Khuman](https://discuss.elastic.co/u/Khuman)\
**Post date:** [October 25, 2019, 4:17pm UTC](https://discuss.elastic.co/t/logstash-on-kubernetes-multiple-output-conditions/205087/5 "2019-10-25T16:17:54Z")

</div>

But working just this condition:  
`else if [host_name] {`  
If I start using your example - stop working.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2019, 4:18pm UTC](https://discuss.elastic.co/t/logstash-on-kubernetes-multiple-output-conditions/205087/6 "2019-11-22T16:18:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
