# Logstash output by condition

**URL:** <https://discuss.elastic.co/t/logstash-output-by-condition/338376>\
**Category:** Logstash\
**Created:** [July 14, 2023, 7:26am UTC](https://discuss.elastic.co/t/logstash-output-by-condition/338376 "2023-07-14T07:26:51Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![tbs575](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbs575/32/87690_2.png) [@tbs575](https://discuss.elastic.co/u/tbs575)\
**Post date:** [July 14, 2023, 7:26am UTC](https://discuss.elastic.co/t/logstash-output-by-condition/338376/1 "2023-07-14T07:26:51Z")

</div>

Hi Guys,  
I setup logstash with influxdb plugin, and can send metric to influxdb successfully. But now I meet question with output by condition.  
run two filebeat instance onto two pc to capture two different log files, I want send to same logstash server, logstash process these message by different signal (etc, log name) and sent same influxdb by differentment measurement( measurement is influxdb element). I test `if` but not working for me. can you give me any suggestion? thanks

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [July 14, 2023, 9:23am UTC](https://discuss.elastic.co/t/logstash-output-by-condition/338376/2 "2023-07-14T09:23:29Z")

</div>

Hi @tbs575,

Using the [conditional operator](https://discuss.elastic.co/t/if-conditional-with-multiple-outputs/178201), similar to this thread is probably the best approach. It sounds like you've have issues with that approach. Can you give a snippet of what you've tried and if you received a particular error?

---

<div class="post-metadata">

**Author:** ![tbs575](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbs575/32/87690_2.png) [@tbs575](https://discuss.elastic.co/u/tbs575)\
**Post date:** [July 17, 2023, 1:20am UTC](https://discuss.elastic.co/t/logstash-output-by-condition/338376/3 "2023-07-17T01:20:36Z")

</div>

part from logstash.conf, I want output same server (influxdb), just different `measurement` by condition, and met error.

```auto
output {
  influxdb {
    host => ["10.200.101.18"]
    id => "logstash_id"
    user => "logstash"
    password => "logstash"
    if [message] =~ "destination-port" {
      measurement => "energy-log"
    } else {
      measurement => "tttt-log"
    }
    send_as_tags => ["[host][name]"]
    db => "test"
    exclude_fields => ["original"]
    use_event_fields_for_data_points => false
    data_points => {
       "source_ip"=> "%{source_ip}" "source_port"=> "%{source_port}" "dest_ip"=> "%{dest_ip}" "dest_port"=> "%{dest_port}"
    }
  }
}

```

```auto
logstash-influxdb | [2023-07-17T01:19:25,713][ERROR][logstash.agent] Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of [\\t\\r\\n], \"#\", \"=>\" at line 25, column 8 (byte 527) after output {\n influxdb {\n host => [\"10.200.101.18\"]\n id => \"logstash_id\" \n user => \"logstash\"\n password => \"logstash\"\n if ", :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:239:in `initialize'", "org/logstash/execution/AbstractPipelineExt.java:173:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:48:in `initialize'", "org/jruby/RubyClass.java:911:in `new'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:50:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:386:in `block in converge_state'"]}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 17, 2023, 1:51am UTC](https://discuss.elastic.co/t/logstash-output-by-condition/338376/4 "2023-07-17T01:51:17Z")

</div>

You cannot use a conditional inside the output, you need the use two outputs

```
output {
     if [message] =~ "destination-port" {
         influxdb {
             host => ["10.200.101.18"]
             ...
             measurement => "energy-log"
             ...
        }
    } else {
         influxdb {
             host => ["10.200.101.18"]
             ...
             measurement => "tttt-log"
             ...
        }     
    }
}

```

The [very first post](https://discuss.elastic.co/t/problem-with-conditional-in-output-definition/74302) I made on this site was about me making exactly this mistake 🤣

---

<div class="post-metadata">

**Author:** ![tbs575](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbs575/32/87690_2.png) [@tbs575](https://discuss.elastic.co/u/tbs575)\
**Post date:** [July 17, 2023, 2:02am UTC](https://discuss.elastic.co/t/logstash-output-by-condition/338376/5 "2023-07-17T02:02:44Z")

</div>

thanks, fixed. Can I use pipelines? like this link ([Multiple Pipelines | Logstash Reference [8.8] | Elastic](https://www.elastic.co/guide/en/logstash/current/multiple-pipelines.html)), using different file by condition, thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 17, 2023, 2:13am UTC](https://discuss.elastic.co/t/logstash-output-by-condition/338376/6 "2023-07-17T02:13:23Z")

</div>

If I understand your ask correctly then yes, the [distributor pattern](https://www.elastic.co/guide/en/logstash/current/pipeline-to-pipeline.html#distributor-pattern) of pipeline-to-pipeline communication uses conditionals to route to different pipelines.

---

<div class="post-metadata">

**Author:** ![tbs575](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbs575/32/87690_2.png) [@tbs575](https://discuss.elastic.co/u/tbs575)\
**Post date:** [July 17, 2023, 2:19am UTC](https://discuss.elastic.co/t/logstash-output-by-condition/338376/7 "2023-07-17T02:19:05Z")

</div>

yes, thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2023, 2:19am UTC](https://discuss.elastic.co/t/logstash-output-by-condition/338376/8 "2023-08-14T02:19:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
