# Multiple outputs for same log entry

**URL:** <https://discuss.elastic.co/t/multiple-outputs-for-same-log-entry/179312>\
**Category:** Logstash\
**Created:** [May 2, 2019, 8:37am UTC](https://discuss.elastic.co/t/multiple-outputs-for-same-log-entry/179312 "2019-05-02T08:37:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![duncOps](https://avatars.discourse-cdn.com/v4/letter/d/c89c15/32.png) [@duncOps](https://discuss.elastic.co/u/duncOps)\
**Post date:** [May 2, 2019, 8:37am UTC](https://discuss.elastic.co/t/multiple-outputs-for-same-log-entry/179312/1 "2019-05-02T08:37:33Z")

</div>

Hi folks,

I've recently written a couple of `email` module output blocks to notify Teams / PagerDuty when errors occur in our live environment.

My Logstash output looks like this:

```
output {
  if "PROD" in [log.environment] {
    # All log.error messages spammed to Alerts & Notifications channel
    if "output-teams" in [tags] {
      # Some of our logs are based on REQUEST/RESPONSE and just include a status. These should always be 500+ errors
      if [app.req.destination] and [app.req.method] {
        email {
          << email stuff >>
        }
      }
      # Our newer logs however use "app.logText" and "app.error.messages/response"
      else if [app.logText] {
        email {
          << email stuff >>
        }
      }
    }

    # 500 errors logged out to PagerDuty
    if "output-pagerduty" in [tags] {
      email {
        << email stuff >>
      }
    }
  }

  elasticsearch {
    hosts => "10.128.x.x"
    index => "xxx-%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
  }

  # comment this out on Pre-Prod and Prod environments
  stdout { codec => rubydebug }
}

```

This works - the e-mails arrive in Teams as expected:

 ![15](https://us1.discourse-cdn.com/elastic/original/3X/1/8/18e3fb3b2e79d678e2234db49483dade6e47d284.png)

However, I can't now see the log entry in Kibana...

 ![03](https://us1.discourse-cdn.com/elastic/original/3X/8/0/803d786b0c3fc9887f39eed42a73a102c388c966.png)

Is it possible that because the log entry has been processed by the `email` plugin, it's then not getting processed by the `elasticsearch` plugin?

---

<div class="post-metadata">

**Author:** ![duncOps](https://avatars.discourse-cdn.com/v4/letter/d/c89c15/32.png) [@duncOps](https://discuss.elastic.co/u/duncOps)\
**Post date:** [May 3, 2019, 9:02am UTC](https://discuss.elastic.co/t/multiple-outputs-for-same-log-entry/179312/2 "2019-05-03T09:02:27Z")

</div>

Little impatient bump (sorry - last day at my current organisation, would like to get some support with this if poss!).

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [May 3, 2019, 10:01am UTC](https://discuss.elastic.co/t/multiple-outputs-for-same-log-entry/179312/3 "2019-05-03T10:01:34Z")

</div>

Hi @duncOps,

I have used several outputs in parallel before. I suspect the `if` statement doens't share messages nicely...

I would either try putting the whole `if` block last (the other outputs would possibly get their "copy" before the `if` block) or add all outputs the each nested `if` statement.

---

<div class="post-metadata">

**Author:** ![duncOps](https://avatars.discourse-cdn.com/v4/letter/d/c89c15/32.png) [@duncOps](https://discuss.elastic.co/u/duncOps)\
**Post date:** [May 3, 2019, 10:02am UTC](https://discuss.elastic.co/t/multiple-outputs-for-same-log-entry/179312/4 "2019-05-03T10:02:48Z")

</div>

Thanks @A_B, I'll give that a go now.

---

<div class="post-metadata">

**Author:** ![duncOps](https://avatars.discourse-cdn.com/v4/letter/d/c89c15/32.png) [@duncOps](https://discuss.elastic.co/u/duncOps)\
**Post date:** [May 3, 2019, 10:11am UTC](https://discuss.elastic.co/t/multiple-outputs-for-same-log-entry/179312/5 "2019-05-03T10:11:48Z")

</div>

Bingo - putting the `elasticsearch` block first appears to have resolved the problem; I can now see the logs in both Teams and Kibana.

How bizarre...

Thanks again!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 3, 2019, 1:42pm UTC](https://discuss.elastic.co/t/multiple-outputs-for-same-log-entry/179312/6 "2019-05-03T13:42:49Z")

</div>

If you can provide a reproduceable configuration where events are not written to an output I would be very interested to see it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2019, 1:42pm UTC](https://discuss.elastic.co/t/multiple-outputs-for-same-log-entry/179312/7 "2019-05-31T13:42:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
