# Ready to throw logstash config file out the window -- help please :)

**URL:** <https://discuss.elastic.co/t/ready-to-throw-logstash-config-file-out-the-window-help-please/42951>\
**Category:** Logstash\
**Created:** [February 28, 2016, 1:08pm UTC](https://discuss.elastic.co/t/ready-to-throw-logstash-config-file-out-the-window-help-please/42951 "2016-02-28T13:08:35Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![timothybward](https://avatars.discourse-cdn.com/v4/letter/t/96bed5/32.png) [@timothybward](https://discuss.elastic.co/u/timothybward)\
**Post date:** [February 28, 2016, 1:08pm UTC](https://discuss.elastic.co/t/ready-to-throw-logstash-config-file-out-the-window-help-please/42951/1 "2016-02-28T13:08:35Z")

</div>

I have the below file and I'm getting the completely useless error message:  
Error: Expected one of #, =\> at line 85, column 5 (byte 1787) after output {  
elasticsearch {  
if  
\_\_\_\_ File below:  
input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}  
input {  
udp {  
host =\> "0.0.0.0"  
port =\> 2055  
codec =\> netflow { versions =\> [5, 9] }  
type =\> "netflow"  
}  
udp {  
host =\> "0.0.0.0"  
port =\> 9995  
codec =\> netflow { versions =\> [5, 9] }  
type =\> "netflow"  
}

```
    udp {
            host => "0.0.0.0"
            port => 1514
            type => "syslog-relay"
            tags => ["netsyslog"]
     }
    tcp {
            host => "0.0.0.0"
            port => 1514
            type => "syslog-relay"
            tags => ["netsyslog"]
     }

```

}

filter {

if [type] == "syslog-relay" {

grok { match =\> { "message" =\> "(?:\<%{INT:priority}\>)?%{SYSLOGBASE2} (?:\s?%{LOGLEVEL:log\_level} )?(?:\s?%{WORD:log\_format}: )?%{GREEDYDATA:syslog\_message}" }}  
date { match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"] }  
syslog\_pri { }

```
if ("_grokparsefailure" in [tags]) { 
    mutate { replace => ["@message", "TOPARSE: %{message}"] }
} else if [log_format] == "json" {
  mutate {
    gsub => ["syslog_message", "@timestamp", "syslog_timestamp"]
  }

  json {
    source => "syslog_message"
  }

  mutate {
    replace => ["@message", "%{message}"]
  }

} else {
  mutate {
    replace => ["@message", "%{syslog_message}"]
  }

}

mutate {
  remove_field => [
    "syslog_hostname", "syslog_message", "syslog_timestamp",
    "syslog_severity_code", "syslog_facility_code",
    "message" #facility_label", "severity_label"
  ]

}

```

}  
}  
-\> part it's complaining about  
output {  
elasticsearch {  
hosts =\> "localhost:9200"  
if [type] == "syslog-relay" {  
index =\> "logstash-%{+YYYY.MM.dd}"  
} else if [type] == "netflow" {  
index =\> "flowstash-%{+YYYY.MM.dd}"  
}  
}

}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 28, 2016, 1:29pm UTC](https://discuss.elastic.co/t/ready-to-throw-logstash-config-file-out-the-window-help-please/42951/2 "2016-02-28T13:29:05Z")

</div>

You can not have conditionals within a filter block like you have for the Elasticsearch output. You will need to configure 2 completely separate Elasticsearch output blocks and select between these based on conditionals.

---

<div class="post-metadata">

**Author:** ![timothybward](https://avatars.discourse-cdn.com/v4/letter/t/96bed5/32.png) [@timothybward](https://discuss.elastic.co/u/timothybward)\
**Post date:** [February 28, 2016, 1:33pm UTC](https://discuss.elastic.co/t/ready-to-throw-logstash-config-file-out-the-window-help-please/42951/3 "2016-02-28T13:33:10Z")

</div>

Thank you so much for the reply.

I was starting to think that may be the case.

So i just move the if's outside like so:  
if [type] == "syslog-relay" {  
output {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "logstash-%{+YYYY.MM.dd}"  
}  
} else if [type] == "netflow" {  
output {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "flowstash-%{+YYYY.MM.dd}"  
}  
}

?

---

<div class="post-metadata">

**Author:** ![timothybward](https://avatars.discourse-cdn.com/v4/letter/t/96bed5/32.png) [@timothybward](https://discuss.elastic.co/u/timothybward)\
**Post date:** [February 28, 2016, 1:41pm UTC](https://discuss.elastic.co/t/ready-to-throw-logstash-config-file-out-the-window-help-please/42951/4 "2016-02-28T13:41:22Z")

</div>

Either I'm doing it completely wrong or it still doesn't like it =(  
Error: Expected one of #, input, filter, output at line 83, column 9 (byte 1766) after  
if [type] == "syslog-relay" {  
output {  
-\>83 elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "logstash-%{+YYYY.MM.dd}"  
}  
} else if [type] == "netflow" {  
output {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "flowstash-%{+YYYY.MM.dd}"  
}  
}

---

<div class="post-metadata">

**Author:** ![timothybward](https://avatars.discourse-cdn.com/v4/letter/t/96bed5/32.png) [@timothybward](https://discuss.elastic.co/u/timothybward)\
**Post date:** [February 28, 2016, 2:06pm UTC](https://discuss.elastic.co/t/ready-to-throw-logstash-config-file-out-the-window-help-please/42951/5 "2016-02-28T14:06:04Z")

</div>

Pretty sure I just got it.  
Had the conditionals in the wrong place If this fixed it thanks for the pointers!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 28, 2016, 2:52pm UTC](https://discuss.elastic.co/t/ready-to-throw-logstash-config-file-out-the-window-help-please/42951/6 "2016-02-28T14:52:46Z")

</div>

Excellent. It should look something like this:

```
output {
  if [type] == "syslog-relay" {
    elasticsearch {
      hosts => "localhost:9200"
      index => "logstash-%{+YYYY.MM.dd}"
    }
  } else if [type] == "netflow" {
    elasticsearch {
      hosts => "localhost:9200"
      index => "flowstash-%{+YYYY.MM.dd}"
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![timothybward](https://avatars.discourse-cdn.com/v4/letter/t/96bed5/32.png) [@timothybward](https://discuss.elastic.co/u/timothybward)\
**Post date:** [February 28, 2016, 3:08pm UTC](https://discuss.elastic.co/t/ready-to-throw-logstash-config-file-out-the-window-help-please/42951/7 "2016-02-28T15:08:36Z")

</div>

The below is what I had to do to get it to work -- the way you just suggested was the first thing I tried and it was no love -- this finally worked but I think yours makes more sense. Maybe I had a typo and got frustrated too quickly.

```
output {
        if [type] == "syslog-relay" {
                        elasticsearch {
                                hosts => "localhost:9200"
                                index => "logstash-%{+YYYY.MM.dd}"
                        }
                }
        }
output {
                if [type] == "netflow" {
                                elasticsearch {
                                        hosts => "localhost:9200"
                                        index => "flowstash-%{+YYYY.MM.dd}"
                                }
                        }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:09am UTC](https://discuss.elastic.co/t/ready-to-throw-logstash-config-file-out-the-window-help-please/42951/8 "2017-07-06T05:09:29Z")

</div>


