# Output to indexes based on \[agent.type\] (or any conditionals) not working

**URL:** <https://discuss.elastic.co/t/output-to-indexes-based-on-agent-type-or-any-conditionals-not-working/231363>\
**Category:** Logstash\
**Created:** [May 6, 2020, 2:32pm UTC](https://discuss.elastic.co/t/output-to-indexes-based-on-agent-type-or-any-conditionals-not-working/231363 "2020-05-06T14:32:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![SteveParker](https://avatars.discourse-cdn.com/v4/letter/s/c5a1d2/32.png) [@SteveParker](https://discuss.elastic.co/u/SteveParker)\
**Post date:** [May 6, 2020, 2:32pm UTC](https://discuss.elastic.co/t/output-to-indexes-based-on-agent-type-or-any-conditionals-not-working/231363/1 "2020-05-06T14:32:37Z")

</div>

Sorry to ask this, I have searched long for an answer but not found anything.  
My winlogbeat, packetbeat and metricbeat are all sent to logstash on 5044. I want logstash to output them to dedicated indexes. I am using the following config for logstash but everything goes to the last index. Please tell me what have I got wrong, thanks!

input {  
beats {  
port =\> "5044"  
}  
}

filter {  
if [agent.type] == "metricbeat" {  
mutate { add\_field =\> { "[@metadata][target\_index]" =\> "metricbeat-%{+YYYY.MM.dd}" } }  
} else if [agent.type] == "packetbeat" {  
mutate { add\_field =\> { "[@metadata][target\_index]" =\> "packetbeat-%{+YYYY.MM.dd}" } }  
} else {  
mutate { add\_field =\> { "[@metadata][target\_index]" =\> "winlogbeat-%{+YYYY.MM.dd}" } }  
}  
}

output {  
elasticsearch {  
hosts =\> [""]  
cacert =\> "C:\logstash\config\certsESSOC\elasticsearch-ca.pem"  
ssl\_certificate\_verification =\> true  
index =\> "%{[@metadata][target\_index]}"

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [May 6, 2020, 2:49pm UTC](https://discuss.elastic.co/t/output-to-indexes-based-on-agent-type-or-any-conditionals-not-working/231363/2 "2020-05-06T14:49:12Z")

</div>

Hi @SteveParker,

this is similar to what I do. I only use `if` statements, no `else if` or `else`. I have a fall back value in case my version of `%{[@metadata][target_index]}`

Here's a couple of my filters

```
  if [event][module] {
    mutate {
      copy => {
       "[event][module]" => "[@metadata][index]"
      }
    }
    alter {
      add_field => {
        "[@metadata][log_prefix]" => "dc"
      }
    }
  }

```

I usually set extra fields in Filebeat inputs (you could do the same in `winlogbeat`).

```
  if [@metadata][beat] {
    # Adding @metadata needed for index sharding to Filebeat logs
    mutate {
      copy => {
       "[fields][log_prefix]" => "[@metadata][log_prefix]"
       "[fields][log_idx]" => "[@metadata][index]"
      }
    }
  }

```

Hope that makes sense 🙂

And my output looks like

```
output {
  elasticsearch {
        hosts => ["10.1.1.1:9200"]
        index => "%{[@metadata][log_prefix]}-%{[@metadata][index]}-%{+YYYY.MM.dd}"
  }
}
```

---

<div class="post-metadata">

**Author:** ![SteveParker](https://avatars.discourse-cdn.com/v4/letter/s/c5a1d2/32.png) [@SteveParker](https://discuss.elastic.co/u/SteveParker)\
**Post date:** [May 6, 2020, 3:35pm UTC](https://discuss.elastic.co/t/output-to-indexes-based-on-agent-type-or-any-conditionals-not-working/231363/3 "2020-05-06T15:35:26Z")

</div>

Thank you, I will give them a try!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 6, 2020, 5:34pm UTC](https://discuss.elastic.co/t/output-to-indexes-based-on-agent-type-or-any-conditionals-not-working/231363/4 "2020-05-06T17:34:27Z")

</div>

> [@SteveParker](#):
>
> if [agent.type] == "metricbeat" {

If agent is an object that contains a type field then in logstash that is called [agent][type]

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [May 7, 2020, 8:57am UTC](https://discuss.elastic.co/t/output-to-indexes-based-on-agent-type-or-any-conditionals-not-working/231363/5 "2020-05-07T08:57:29Z")

</div>

One more thing @SteveParker.

I think all _beats_ already adds the @metadata you need for what you want to do. So you do not need those filters.

E.g. for Metricbeat gives you this out of the box

```
{
    ...
    "@metadata": { 
      "beat": "metricbeat", 
      "version": "7.6.2" 
    }
}

```

And from the same page the suggested output config

```
output {
  elasticsearch {
    hosts => ["http://localhost:9200"]
    index => "%{[@metadata][beat]}-%{[@metadata][version]}" 
  }
}
```

---

<div class="post-metadata">

**Author:** ![SteveParker](https://avatars.discourse-cdn.com/v4/letter/s/c5a1d2/32.png) [@SteveParker](https://discuss.elastic.co/u/SteveParker)\
**Post date:** [May 7, 2020, 10:57am UTC](https://discuss.elastic.co/t/output-to-indexes-based-on-agent-type-or-any-conditionals-not-working/231363/6 "2020-05-07T10:57:26Z")

</div>

Thanks A\_B, I have removed the filters and used the beats @metadata to create the index names. Much cleaner config and the result I was looking for, Cheers!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2020, 10:57am UTC](https://discuss.elastic.co/t/output-to-indexes-based-on-agent-type-or-any-conditionals-not-working/231363/7 "2020-06-04T10:57:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
