# Multiple ELK cluster output

**URL:** <https://discuss.elastic.co/t/multiple-elk-cluster-output/175810>\
**Category:** Logstash\
**Created:** [April 8, 2019, 9:36am UTC](https://discuss.elastic.co/t/multiple-elk-cluster-output/175810 "2019-04-08T09:36:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gidi\_Kalef](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gidi_kalef/32/43651_2.png) [@Gidi\_Kalef](https://discuss.elastic.co/u/Gidi_Kalef)\
**Post date:** [April 8, 2019, 9:36am UTC](https://discuss.elastic.co/t/multiple-elk-cluster-output/175810/1 "2019-04-08T09:36:54Z")

</div>

Hi All,

Is it possible to send to two ELK cluster by the following format:

output {  
elasticsearch {  
hosts=\> ["node1","node2","node3"]  
}  
elasticsearch {  
hosts=\> ["server1","server2","server3"]  
}

}

Thank you alot!

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [April 8, 2019, 10:19am UTC](https://discuss.elastic.co/t/multiple-elk-cluster-output/175810/2 "2019-04-08T10:19:46Z")

</div>

Yes 🙂

---

<div class="post-metadata">

**Author:** ![Gidi\_Kalef](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gidi_kalef/32/43651_2.png) [@Gidi\_Kalef](https://discuss.elastic.co/u/Gidi_Kalef)\
**Post date:** [April 8, 2019, 2:00pm UTC](https://discuss.elastic.co/t/multiple-elk-cluster-output/175810/3 "2019-04-08T14:00:57Z")

</div>

so i added the following output:  
output {

elasticsearch {  
hosts =\> ["[esh-prod-elasticsearch-01.eqx.com:9200](http://esh-prod-elasticsearch-01.eqx.com:9200)" , "[esh-prod-elasticsearch-02.eqx.com:9200](http://esh-prod-elasticsearch-02.eqx.com:9200)" , "[esh-prod-elasticsearch-03.eqx.com:9200](http://esh-prod-elasticsearch-03.eqx.com:9200)" , "[esh-prod-elasticsearch-04.eqx.com:9200](http://esh-prod-elasticsearch-04.eqx.com:9200)" , "[esh-prod-elasticsearch-05.eqx.com:9200](http://esh-prod-elasticsearch-05.eqx.com:9200)" ]  
manage\_template =\> false  
index =\> "%{se\_deployment}-%{se\_site}-%{ix\_profile}-%{+YYYY.MM.dd}"  
user =\> logstash\_inter  
password =\> logstash\_inter  
}

elasticsearch {  
hosts =\> ["esh-sd-elasticsearch01:9200" , "esh-sd-elasticsearch02:9200" , "esh-sd-elasticsearch03:9200"]  
manage\_template =\> false  
index =\> "%{se\_deployment}-%{se\_site}-%{se\_profile}-%{+YYYY.MM.dd}"  
}

# Debugging to file

file { codec =\> rubydebug  
path =\> "/var/log/logstash/logstash-debug.log" }  
}

but i see the logs only in the second output and not the first one although the debugging show everything is correct .

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [April 8, 2019, 2:05pm UTC](https://discuss.elastic.co/t/multiple-elk-cluster-output/175810/4 "2019-04-08T14:05:16Z")

</div>

If there would be a problem with one of the outputs Logstash would shutdown to prevent data loss. This happened to me a few times so that is something to keep in mind.

The `index` name is different in the two outputs. Is that on purpose? The first one has `%{ix_profile}` and the second one has `%{se_profile}`.

---

<div class="post-metadata">

**Author:** ![Gidi\_Kalef](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gidi_kalef/32/43651_2.png) [@Gidi\_Kalef](https://discuss.elastic.co/u/Gidi_Kalef)\
**Post date:** [April 8, 2019, 2:13pm UTC](https://discuss.elastic.co/t/multiple-elk-cluster-output/175810/5 "2019-04-08T14:13:51Z")

</div>

First , thanks for quick respond!  
you are right i change it now and i hope it will be fixed they both should be %{se\_profile}!  
it fixed that!!  
tnx alot\<3

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 6, 2019, 2:14pm UTC](https://discuss.elastic.co/t/multiple-elk-cluster-output/175810/6 "2019-05-06T14:14:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
