# Multiple input filebeat to logstash

**URL:** <https://discuss.elastic.co/t/multiple-input-filebeat-to-logstash/230194>\
**Category:** Logstash\
**Created:** [April 28, 2020, 2:19pm UTC](https://discuss.elastic.co/t/multiple-input-filebeat-to-logstash/230194 "2020-04-28T14:19:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![GedeoN](https://avatars.discourse-cdn.com/v4/letter/g/e9c0ed/32.png) [@GedeoN](https://discuss.elastic.co/u/GedeoN)\
**Post date:** [April 28, 2020, 2:19pm UTC](https://discuss.elastic.co/t/multiple-input-filebeat-to-logstash/230194/1 "2020-04-28T14:19:08Z")

</div>

Hi all experts,

I'm trying inject many logs from many files.  
Actually, i receive all logs but in just one index.  
I tried to tags, but it's not working actually, and i don't find my error.

filebeat configuration:

```auto
filebeat.inputs:
  
- type: log
  encoding: utf-8
  enabled: true
  paths:
    - C:/Program Files/Microsoft SQL Server/MSSQL13.MSSQLSERVER/MSSQL/Log/FDLAUNCHERRORLOG*
  tags: ["FDLAUNCHERRORLOG"]
  scan_frequency: 120s
  
- type: log
  encoding: utf-8
  enabled: true
  paths:
    - C:/Program Files/Microsoft SQL Server/MSSQL13.MSSQLSERVER/MSSQL/Log/SQLAGENT*
  tags: ["SQLAGENT"]
  scan_frequency: 120s
  
- type: log
  encoding: utf-8
  enabled: true
  paths:
    - C:/Program Files/Microsoft SQL Server/MSSQL13.MSSQLSERVER/MSSQL/Log/ERRORLOG*
  tags: ["ERRORLOG"]
  scan_frequency: 120s

#============================= Filebeat modules ===============================

#==================== Elasticsearch template setting ==========================

setup.template.settings:
  index.number_of_shards: 1

#----------------------------- Logstash output --------------------------------
output.logstash:
  enabled: true
  # The Logstash hosts
  hosts: ["xxx.xxx.xxx.xxx:5044"]

#================================ Processors =====================================

processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~
  - add_docker_metadata: ~
  - add_kubernetes_metadata: ~

```

input logstash:

```auto
input {
  beats {
    port => 5044
    tags => ["ERRORLOG","FDLAUNCHERRORLOG","SQLAGENT"]
        }
}

```

output logstash:

```auto
output {
  if "ERRORLOG" in [tags] {
    elasticsearch {
      hosts => ["http://sta-elasticsearch:9200"]
      index => "errorlog-%{+YYYY.MM.dd}"
      }
}
  else if "FDLAUNCHERRORLOG" in [tags] {
    elasticsearch {
      hosts => ["http://sta-elasticsearch:9200"]
      index => "fdlauncherrorlog-%{+YYYY.MM.dd}"
      }
}
  else if "SQLAGENT" in [tags] {
    elasticsearch {
      hosts => ["http://sta-elasticsearch:9200"]
      index => "sqlagent-%{+YYYY.MM.dd}"
  }
}
}

```

So i try to tags words like ERRORLOG or SQLAGENT, to redirect logs in thei good index.

Regards.  
Jonathan

---

<div class="post-metadata">

**Author:** ![GedeoN](https://avatars.discourse-cdn.com/v4/letter/g/e9c0ed/32.png) [@GedeoN](https://discuss.elastic.co/u/GedeoN)\
**Post date:** [April 28, 2020, 3:28pm UTC](https://discuss.elastic.co/t/multiple-input-filebeat-to-logstash/230194/2 "2020-04-28T15:28:46Z")

</div>

Well i found my problem, i deleted tag from logstash input, and it's now working fine 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 26, 2020, 3:28pm UTC](https://discuss.elastic.co/t/multiple-input-filebeat-to-logstash/230194/3 "2020-05-26T15:28:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
