# Output with condition

**URL:** <https://discuss.elastic.co/t/output-with-condition/206505>\
**Category:** Logstash\
**Created:** [November 5, 2019, 1:46am UTC](https://discuss.elastic.co/t/output-with-condition/206505 "2019-11-05T01:46:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sud0](https://avatars.discourse-cdn.com/v4/letter/s/e5b9ba/32.png) [@sud0](https://discuss.elastic.co/u/sud0)\
**Post date:** [November 5, 2019, 1:46am UTC](https://discuss.elastic.co/t/output-with-condition/206505/1 "2019-11-05T01:46:24Z")

</div>

HI.

I have two businesses that must be separated in two different indexes.

I'm trying to separate them on the output:

```
output {

if [region] == "au" {
        elasticsearch {
        hosts => ["localhost:9200"]
        # Weekly index (for pruning)
        index => "au-log-index-%{+YYYY.'w'ww}"
        }
    }

else {
        elasticsearch {
        hosts => ["localhost:9200"]
        # Weekly index (for pruning)
        index => "nz-log-index-%{+YYYY.'w'ww}"
        }
    }

    stdout { codec => rubydebug }
}

```

I'm adding the `region` field like this; `example.conf`:

```
if [type] == "au_uat_apache_access_log" {
        mutate {
            replace => { 'host' => 'uatweb.datacentre.example.com.au' }
            add_field => { 'environment' => 'uat'
                           'service' => 'apache_access'
                           'region' => 'au'
            }
        }
        grok {
            match => {
                "message" => "%{IPORHOST:clientip}%{SPACE}\[%{HTTPDATE:timestamp}\]%{SPACE}%{NUMBER:port}%{SPACE}%{WORD:method}%{SPACE}%{URIPATHPARAM:request_uri}%{SPACE}%{NOTSPACE}%{SPACE}%{NUMBER:status_code}%{SPACE}%{NOTSPACE:bytes_delivered}%{SPACE}%{NUMBER:duration%}%{SPACE}(?:%{URI:referrer}|.*)%{SPACE}%{QS:agent}%{SPACE}%{GREEDYDATA:general_data}"
            }
        }

        date {
            match => ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z"]
            target => "@timestamp"
        }
    }

```

However from Kibana I am only able to see the `nz*` index, which correspond to the `else` statement.

What am I doing wrong? Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 5, 2019, 5:50am UTC](https://discuss.elastic.co/t/output-with-condition/206505/2 "2019-11-05T05:50:03Z")

</div>

> [@sud0](#):
>
> if [type] == "au\_uat\_apache\_access\_log" {

Is this condition ever true? Where is this type set? Can you show a document that had been indexed into the wrong index?

---

<div class="post-metadata">

**Author:** ![sud0](https://avatars.discourse-cdn.com/v4/letter/s/e5b9ba/32.png) [@sud0](https://discuss.elastic.co/u/sud0)\
**Post date:** [November 5, 2019, 8:24pm UTC](https://discuss.elastic.co/t/output-with-condition/206505/3 "2019-11-05T20:24:07Z")

</div>

> [@Christian\_Dahlqvist](#):
>
> au\_uat\_apache\_access\_log

Yes, it does exist

```
file {
        type => "au_uat_apache_access_log"
        start_position => "beginning"
        path => "/mnt/logs/uatweb/access_log"
    }

```

> Can you show a document that had been indexed into the wrong index?

The problem is that only one index is shown to me; I can only see the index below in Kibana:

```auto
else {
        elasticsearch {
        hosts => ["localhost:9200"]
        # Weekly index (for pruning)
        index => "nz-log-index-%{+YYYY.'w'ww}"
        }
    }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 5, 2019, 8:42pm UTC](https://discuss.elastic.co/t/output-with-condition/206505/4 "2019-11-05T20:42:56Z")

</div>

In Kibana, expand a document that is in the wrong index, go to the JSON tab, and post a copy of what is on that tab for a single document. Make sure you include the type and region fields.

---

<div class="post-metadata">

**Author:** ![sud0](https://avatars.discourse-cdn.com/v4/letter/s/e5b9ba/32.png) [@sud0](https://discuss.elastic.co/u/sud0)\
**Post date:** [November 5, 2019, 8:56pm UTC](https://discuss.elastic.co/t/output-with-condition/206505/5 "2019-11-05T20:56:48Z")

</div>

I can't... I'm getting an error on Kibana so no data is being shown (when creating the index pattern):

```
"f0aa5110-000d-11ea-98c1-51084078b0aa" is not a configured index pattern ID
Showing the default index pattern: "nz*" (a5034ae0-000e-11ea-98c1-51084078b0aa)

```

There is no data being displayed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 3, 2019, 8:56pm UTC](https://discuss.elastic.co/t/output-with-condition/206505/6 "2019-12-03T20:56:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
