# Logstash

**URL:** <https://discuss.elastic.co/t/logstash/269018>\
**Category:** Logstash\
**Created:** [April 1, 2021, 10:41am UTC](https://discuss.elastic.co/t/logstash/269018 "2021-04-01T10:41:54Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![dddddddddddddddd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dddddddddddddddd/32/86746_2.png) [@dddddddddddddddd](https://discuss.elastic.co/u/dddddddddddddddd)\
**Post date:** [April 1, 2021, 10:41am UTC](https://discuss.elastic.co/t/logstash/269018/1 "2021-04-01T10:41:54Z")

</div>

Hi  
i hope this message find you well , how could to send filtred logs to elasticsearch and in the same time send raw logs to another server (I need this logs for investigation and forensics task)  
regards and thanks

---

<div class="post-metadata">

**Author:** ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)\
**Post date:** [April 1, 2021, 11:04am UTC](https://discuss.elastic.co/t/logstash/269018/2 "2021-04-01T11:04:44Z")

</div>

Hi,

With logstash you could input, then output the logs to one server or index, then do the filters and output again.

First output captures logs direct after sent to logstash.

---

<div class="post-metadata">

**Author:** ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)\
**Post date:** [April 1, 2021, 12:24pm UTC](https://discuss.elastic.co/t/logstash/269018/4 "2021-04-01T12:24:19Z")

</div>

Just one logstash server.  
Input  
Output (raw logs)  
Filter for custom parsing  
Output (custom parsed logs)

---

<div class="post-metadata">

**Author:** ![dddddddddddddddd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dddddddddddddddd/32/86746_2.png) [@dddddddddddddddd](https://discuss.elastic.co/u/dddddddddddddddd)\
**Post date:** [April 1, 2021, 12:50pm UTC](https://discuss.elastic.co/t/logstash/269018/5 "2021-04-01T12:50:43Z")

</div>

so how can I do this operation , if you have any links that can help me for accomplish this task please send them to me

---

<div class="post-metadata">

**Author:** ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)\
**Post date:** [April 1, 2021, 12:53pm UTC](https://discuss.elastic.co/t/logstash/269018/6 "2021-04-01T12:53:06Z")

</div>

You need to look at logstash configurations, ie - [Logstash Configuration Examples | Logstash Reference [7.12] | Elastic](https://www.elastic.co/guide/en/logstash/current/config-examples.html)

ie  
server A raw logs, then filter, then output to server B for processed logs

```auto
input { stdin { } }
output {
  elasticsearch { hosts => ["servera:9200"] }
  stdout { codec => rubydebug }
}
filter {
  grok {
    match => { "message" => "%{COMBINEDAPACHELOG}" }
  }
  date {
    match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]
  }
}

output {
  elasticsearch { hosts => ["serverb:9200"] }
  stdout { codec => rubydebug }
}

```

---

<div class="post-metadata">

**Author:** ![dddddddddddddddd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dddddddddddddddd/32/86746_2.png) [@dddddddddddddddd](https://discuss.elastic.co/u/dddddddddddddddd)\
**Post date:** [April 1, 2021, 12:56pm UTC](https://discuss.elastic.co/t/logstash/269018/7 "2021-04-01T12:56:26Z")

</div>

Thank you very much

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 1, 2021, 1:06pm UTC](https://discuss.elastic.co/t/logstash/269018/8 "2021-04-01T13:06:58Z")

</div>

> [@probson](#):
>
> Input  
> Output (raw logs)  
> Filter for custom parsing  
> Output (custom parsed logs)

This does not work that way, Logstash groups inputs, filters and outputs together and runs the pipeline in that order, every field added by a filter will be present in the document and in both outputs.

To send a raw message you need to change the use the `plain` codec in your output and specify only the message field.

```auto
output {
    elasticsearch {
        hosts => ["hostname"]
        codec => plain { format => "%{message}" } 
    }
}

```

This will make you send a message to elasticsearch with only the `message` field, if this is what you want.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 29, 2021, 1:07pm UTC](https://discuss.elastic.co/t/logstash/269018/9 "2021-04-29T13:07:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
