# LS - elasticsearch output conditionals

**URL:** <https://discuss.elastic.co/t/ls-elasticsearch-output-conditionals/40637>\
**Category:** Logstash\
**Created:** [February 1, 2016, 2:11pm UTC](https://discuss.elastic.co/t/ls-elasticsearch-output-conditionals/40637 "2016-02-01T14:11:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dustin.liddick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dustin.liddick/32/7390_2.png) [@dustin.liddick](https://discuss.elastic.co/u/dustin.liddick)\
**Post date:** [February 1, 2016, 2:11pm UTC](https://discuss.elastic.co/t/ls-elasticsearch-output-conditionals/40637/1 "2016-02-01T14:11:12Z")

</div>

hello:

I am having some issues with my LS output conditionals for elasticsearch. I have the following below as my output filter. However when I run a '--configtest' on it, it fails...I am wondering if I have my syntax wrong, as i want to send filter output based on "tags". Also, LS started to fail to create indicies on ES...I am not sure why that started? Is that permissions on ES? I see no errors in logs

output {  
if [type] == "syslog" {  
elasticsearch {  
hosts =\> ["ceelkestb-ob-8p:9200", "ceelkesdn-ob-1p:9200", "ceelkesdn-ob-3p:9200", "ceelkesdn-ob-4p:9200", "ceelkesdn-ob-5p:9200", "ceelkesdn-ob-7p:9200"]  
index =\> "redhat-%{+YYYY.MM.dd}"  
flush\_size =\> 1000  
workers =\> 4  
manage\_template =\> true  
template\_overwrite =\> true  
template =\> "/opt/logstash/lib/logstash/outputs/elasticsearch/elasticsearch-redhat-template.json"  
}  
}  
elseif [type] == "eventlog" {  
elasticsearch {  
hosts =\> ["ceelkestb-ob-8p:9200", "ceelkesdn-ob-1p:9200", "ceelkesdn-ob-3p:9200", "ceelkesdn-ob-4p:9200", "ceelkesdn-ob-5p:9200", "ceelkesdn-ob-7p:9200"]  
index =\> "eventlog-%{+YYYY.MM.dd}"  
workers =\> 4  
manage\_template =\> true  
template\_overwrite =\> true  
template =\> "/opt/logstash/lib/logstash/outputs/elasticsearch/elasticsearch-eventlog-template.json"  
}  
}  
elseif [type] == "cisco-asa" {  
elasticsearch {  
hosts =\> ["ceelkestb-ob-8p:9200", "ceelkesdn-ob-1p:9200", "ceelkesdn-ob-3p:9200", "ceelkesdn-ob-4p:9200", "ceelkesdn-ob-5p:9200", "ceelkesdn-ob-7p:9200"]  
index =\> "cisco-asa-%{+YYYY.MM.dd}"  
flush\_size =\> 1000  
workers =\> 4  
manage\_template =\> true  
template\_overwrite =\> true  
template =\> "/opt/logstash/lib/logstash/outputs/elasticsearch/elasticsearch-cisco-asa-template.json"  
}  
}  
else {  
elasticsearch {  
hosts =\> ["ceelkestb-ob-8p:9200", "ceelkesdn-ob-1p:9200", "ceelkesdn-ob-3p:9200", "ceelkesdn-ob-4p:9200", "ceelkesdn-ob-5p:9200", "ceelkesdn-ob-7p:9200"]  
flush\_size =\> 2000  
workers =\> 1  
#manage\_template =\> true  
#template =\> "/opt/logstash/lib/logstash/outputs/elasticsearch/elasticsearch-template.json"  
}

```
}

```

}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 1, 2016, 5:38pm UTC](https://discuss.elastic.co/t/ls-elasticsearch-output-conditionals/40637/2 "2016-02-01T17:38:27Z")

</div>

Looks okay to me. What's the error message from `--configtest`?

---

<div class="post-metadata">

**Author:** ![dustin.liddick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dustin.liddick/32/7390_2.png) [@dustin.liddick](https://discuss.elastic.co/u/dustin.liddick)\
**Post date:** [February 1, 2016, 6:06pm UTC](https://discuss.elastic.co/t/ls-elasticsearch-output-conditionals/40637/3 "2016-02-01T18:06:24Z")

</div>

After running the config test, it seems to be checking out fine. I honestly have no clue what I did to change. According the last '--configtest' that I ran, it showed I had almost like a commenting issue with a bracket around line 17...but not sure what I did to fix, but just ran a test again, and it passed. I then added this config to LS output and restarted...And it seemed like it has created the proper indexes.

Thanks again for taking the time out of your day and looking into this. If I come across anything additional about this error, Ill be sure to add it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:13am UTC](https://discuss.elastic.co/t/ls-elasticsearch-output-conditionals/40637/4 "2017-07-06T05:13:30Z")

</div>


