# One or more Inputs to One or more Outputs

**URL:** <https://discuss.elastic.co/t/one-or-more-inputs-to-one-or-more-outputs/171906>\
**Category:** Logstash\
**Created:** [March 12, 2019, 9:34am UTC](https://discuss.elastic.co/t/one-or-more-inputs-to-one-or-more-outputs/171906 "2019-03-12T09:34:07Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![samyo](https://avatars.discourse-cdn.com/v4/letter/s/e9c0ed/32.png) [@samyo](https://discuss.elastic.co/u/samyo)\
**Post date:** [March 12, 2019, 9:34am UTC](https://discuss.elastic.co/t/one-or-more-inputs-to-one-or-more-outputs/171906/1 "2019-03-12T09:34:08Z")

</div>

Hello Folks,  
i would like to ask, i have a lot of textfiels(log files) in one folder, each file has his name , and i matched them all in Logstash ,  
is there any possibility after i matched all those textfiles(log files) to send them and save them in **separately** Output files, that mean each input Log file will be sended into separately Output file.  
I will be thankful for any Idea.

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [March 12, 2019, 11:06am UTC](https://discuss.elastic.co/t/one-or-more-inputs-to-one-or-more-outputs/171906/2 "2019-03-12T11:06:28Z")

</div>

> [@samyo](#):
>
> i have a lot of textfiels(log files) in one folder, each file has his name

each log file are same format or diff format

> [@samyo](#):
>
> that mean each input Log file will be sended into separately Output file

yes you could save each file into seperate index depend upon any one unique field from each file

---

<div class="post-metadata">

**Author:** ![samyo](https://avatars.discourse-cdn.com/v4/letter/s/e9c0ed/32.png) [@samyo](https://discuss.elastic.co/u/samyo)\
**Post date:** [March 12, 2019, 11:20am UTC](https://discuss.elastic.co/t/one-or-more-inputs-to-one-or-more-outputs/171906/3 "2019-03-12T11:20:40Z")

</div>

my Log files are all unstructured text Format, they have also all same datatype ".log" but different structure inside, i could match them all , and i could read them all automatically.  
until now i could send them all to one Output "file.log" .  
but i need to send each Input Logfile i have to different Output file . no matter if logstash generate them by its self or not.  
ist that possible ? any Idea?  
my input , out put look like ,  
input  
{ path =\> "C:/Users/samyo/Desktop/ELK/folder/\*\*.log"  
tags =\> "log"  
sincedb\_path =\> "NUL"  
exclude =\> "_.gz"  
}}  
filter {...}  
output {  
file {  
index =\> "%{log}-index"  
path =\> "C:/Users/samyo/Desktop/ELK/_.%{+YYYY-MM-dd}.log"  
codec =\> line { format =\> "text: %{message}"}  
}}

---

<div class="post-metadata">

**Author:** ![samyo](https://avatars.discourse-cdn.com/v4/letter/s/e9c0ed/32.png) [@samyo](https://discuss.elastic.co/u/samyo)\
**Post date:** [March 13, 2019, 8:18am UTC](https://discuss.elastic.co/t/one-or-more-inputs-to-one-or-more-outputs/171906/4 "2019-03-13T08:18:14Z")

</div>

any Update or Suggestions will be thankful ?  
how to save each input logfile to seperate output logfile?  
i do not want to use the if Condetionals , cause it make no sense when i have a lot of input logfiels,and give each input logfile a type.  
Any Other Ideas?  
thanx..

---

<div class="post-metadata">

**Author:** ![samyo](https://avatars.discourse-cdn.com/v4/letter/s/e9c0ed/32.png) [@samyo](https://discuss.elastic.co/u/samyo)\
**Post date:** [March 14, 2019, 10:04am UTC](https://discuss.elastic.co/t/one-or-more-inputs-to-one-or-more-outputs/171906/5 "2019-03-14T10:04:21Z")

</div>

i can read all my input logfiels automatically with this ,  
input  
{ path =\> "C:/Users/samyo/Desktop/ELK/folder/\*\*.log"}

but why i can not use the same line for my output , something like this ,  
output  
{ path =\> "C:/Users/samyo/Desktop/ELK/outputfolder/\*\*.log"}

Does anyone have an Idea, i will appreciate it ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 14, 2019, 1:14pm UTC](https://discuss.elastic.co/t/one-or-more-inputs-to-one-or-more-outputs/171906/6 "2019-03-14T13:14:43Z")

</div>

The file input adds a "path" field to the event. If you want to use the same name in a different directory as the output then you could

```
mutate { add_field => { "filename" => "%{path}" } }
mutate { gsub => ["filename", "^.*/", ""] }

```

and then reference that field in the output

```
output { file { path => "/some/path/%{filename}" } }
```

---

<div class="post-metadata">

**Author:** ![samyo](https://avatars.discourse-cdn.com/v4/letter/s/e9c0ed/32.png) [@samyo](https://discuss.elastic.co/u/samyo)\
**Post date:** [March 15, 2019, 11:01am UTC](https://discuss.elastic.co/t/one-or-more-inputs-to-one-or-more-outputs/171906/7 "2019-03-15T11:01:23Z")

</div>

hello Badger , i could not put dynamic inputsfolder path like follow,  
mutate { add\_field =\> { "textNr1" =\> "%{C:/Users/samyo/Desktop/ELK/inputsfolder/\*\*.log}" } }  
i want from logstash to go inside my inputsfolder and read all the input logfiles (textNr1, textNr2, textNr3, etc) dynamicly and send each of those to seperat output .  
until now i could read dynamic all my inputfiles writing **"\*.log"** in my Input path as i wrote in my Input above but send them to **one** output.  
Because in the output i could put something like **"\*.log"**.  
And the out put as follow,  
output { file { path =\> "C:/Users/samyo/Desktop/ELK/%{textNr1}" } }  
did not work.  
but this ,  
output { file { path =\> "C:/Users/samyo/Desktop/ELK/textNr1" } }  
works and created me a file name "textNr1" and puted all my input logfiles from my inputsfolder  
into this **one** file "textNr1".  
i want logstash take dynamicly every input textfile like (textNr1) into output (textNr1), and input logfile(textNr2) into output file (textNr2) etc. **how to write more than one output file path??**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2019, 11:01am UTC](https://discuss.elastic.co/t/one-or-more-inputs-to-one-or-more-outputs/171906/8 "2019-04-12T11:01:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
