# Logstash sending same message to multiple indexes in ES

**URL:** <https://discuss.elastic.co/t/logstash-sending-same-message-to-multiple-indexes-in-es/92464>\
**Category:** Logstash\
**Created:** [July 10, 2017, 12:18pm UTC](https://discuss.elastic.co/t/logstash-sending-same-message-to-multiple-indexes-in-es/92464 "2017-07-10T12:18:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zeal\_Vora](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zeal_vora/32/3946_2.png) [@Zeal\_Vora](https://discuss.elastic.co/u/Zeal_Vora)\
**Post date:** [July 10, 2017, 12:18pm UTC](https://discuss.elastic.co/t/logstash-sending-same-message-to-multiple-indexes-in-es/92464/1 "2017-07-10T12:18:21Z")

</div>

Hi

We are using Logstash to send application logs to respective index in ElasticSearch.

We have 2 applications which are sending logs to Logstash from filebeat. Each filebeat configuration for application has a respective document\_type associated.

We filter for that document type to send logs to particular index. Somehow I find that any message sent by application 2 ( app2) are being sent to index of both app1 and app2

Here is my logstash configuration :

input {  
beats {  
host =\> "172.17.80.50"  
port =\> "5044"  
client\_inactivity\_timeout =\> "600"  
ssl =\> false  
}  
}

output {  
if [type] == "app1\_app\_log" or "app1\_web\_log" {  
elasticsearch {  
hosts =\> "localhost:9200"  
manage\_template =\> false  
index =\> "index1-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}  
}

output {  
if [type] == "app2\_app\_log" or "app2\_web\_log" {  
elasticsearch {  
hosts =\> "localhost:9200"  
manage\_template =\> false  
index =\> "index2-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}  
}

I am wondering how come logs with app2\_app\_log and app2\_web\_log are being sent to both index1 and index2 ? Am I missing something here? I Any help will be appreciated.

I have also tried to use if and else if based statement, but even with that logs are being sent to both the index which is configured in the above configuration.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 12, 2017, 12:29pm UTC](https://discuss.elastic.co/t/logstash-sending-same-message-to-multiple-indexes-in-es/92464/2 "2017-07-12T12:29:35Z")

</div>

> ```
> if [type] == "app1_app_log" or "app1_web_log" {
> 
> ```

This doesn't mean what you think it means. Use either

```
if [type] in ["app1_app_log", "app1_web_log"] {

```

or

```
if [type] == "app1_app_log" or [type] == "app1_web_log" {

```

instead.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2017, 12:29pm UTC](https://discuss.elastic.co/t/logstash-sending-same-message-to-multiple-indexes-in-es/92464/3 "2017-08-09T12:29:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
