# Logstash sending to all output hosts

**URL:** <https://discuss.elastic.co/t/logstash-sending-to-all-output-hosts/100583>\
**Category:** Logstash\
**Created:** [September 14, 2017, 6:01pm UTC](https://discuss.elastic.co/t/logstash-sending-to-all-output-hosts/100583 "2017-09-14T18:01:14Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![criddock](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@criddock](https://discuss.elastic.co/u/criddock)\
**Post date:** [September 14, 2017, 6:01pm UTC](https://discuss.elastic.co/t/logstash-sending-to-all-output-hosts/100583/1 "2017-09-14T18:01:14Z")

</div>

So, here is a really odd situation. I have two pipeline files:

1. Receive "Beats" fwd'ed logs over 5044 - send to ElasticSearch (x.x.x.164)

```
 input {
    beats {
        port => "5044"
    }
}
output {
  elasticsearch {
    hosts => ["x.x.x.164:9200"]
    user => "xxxx"
    password => "xxxx"
  }
  #stdout { codec => rubydebug }
}

```

1. Receive Splunk "uncooked" log fwds over 2026, send to Splunk server (x.x.x.153) over UDP port 5014

```
input {
        udp{
                port => 2026
        }

        tcp{
                port => 2026
        }
}

output {
                udp {

                                        host => ["x.x.x.153"]
                                        port => "5014"

                        }
                }

```

Soooo....Both Elastic and Splunk are getting the same logs....if I delete the "Beats" pipeline and restart Logstash, Splunk just gets the "uncooked" log data coming in over 2026 and Elastic gets nothing (makes sense).

What is a mystery is why is Logstash is ignoring the "Beats" Pipeline directive (only logs coming in over 5044) and sending "Beats" logs over to Splunk as well?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 14, 2017, 6:08pm UTC](https://discuss.elastic.co/t/logstash-sending-to-all-output-hosts/100583/2 "2017-09-14T18:08:40Z")

</div>

Unless specifically configured otherwise Logstash has a single event pipeline. All files in the conf.d directory are concatenated. All events from all inputs get passed to all filters and all outputs. If that's not desirable you need to add conditionals to route events the way you want.

---

<div class="post-metadata">

**Author:** ![criddock](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@criddock](https://discuss.elastic.co/u/criddock)\
**Post date:** [September 14, 2017, 6:12pm UTC](https://discuss.elastic.co/t/logstash-sending-to-all-output-hosts/100583/3 "2017-09-14T18:12:43Z")

</div>

Ah...that makes a ton of sense....

Not asking for a solution (as I need to learn this stuff), but a nod in the right direction would be appreciated greatly.

---

<div class="post-metadata">

**Author:** ![criddock](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@criddock](https://discuss.elastic.co/u/criddock)\
**Post date:** [September 14, 2017, 6:37pm UTC](https://discuss.elastic.co/t/logstash-sending-to-all-output-hosts/100583/4 "2017-09-14T18:37:43Z")

</div>

I put the following directive in the Splunk pipeline conf file and it seemed to do the trick...

```

filter{
    if "beats_input_codec_plain_applied" in [tags] { drop {}}

```

Will ping back if it also stops the logs going to Elastic....

---

<div class="post-metadata">

**Author:** ![criddock](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@criddock](https://discuss.elastic.co/u/criddock)\
**Post date:** [September 14, 2017, 7:21pm UTC](https://discuss.elastic.co/t/logstash-sending-to-all-output-hosts/100583/5 "2017-09-14T19:21:11Z")

</div>

So, here is what finally worked for anyone that runs across this...

```

input {
        udp{
                port => 2026
        }

        tcp{
                port => 2026
        }
}

output {

if "beats_input_codec_plain_applied" in [tags] {

elasticsearch {
    hosts => ["x.x.x.164:9200"]
    user => "elastic"
    password => "changeme"
  }

} else {
                udp {

                                        host => ["x.x.x.153"]
                                        port => "5014"

                        }
                }
        }

```

Only "Beats" logs are going to ES and the HF stuff is the only thing showing up in Splunk.....

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 12, 2017, 7:21pm UTC](https://discuss.elastic.co/t/logstash-sending-to-all-output-hosts/100583/6 "2017-10-12T19:21:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
