# Same information in differents Indexes

**URL:** <https://discuss.elastic.co/t/same-information-in-differents-indexes/61315>\
**Category:** Elasticsearch\
**Created:** [September 22, 2016, 10:00pm UTC](https://discuss.elastic.co/t/same-information-in-differents-indexes/61315 "2016-09-22T22:00:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mrognone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrognone/32/16034_2.png) [@mrognone](https://discuss.elastic.co/u/mrognone)\
**Post date:** [September 22, 2016, 10:00pm UTC](https://discuss.elastic.co/t/same-information-in-differents-indexes/61315/1 "2016-09-22T22:00:39Z")

</div>

Hi all,

I'm super noob with ELK, after 1 month I finally created beautifuls dashboard with useful information to my company. But I have an issue, I tried to find something about this , but didn't find anything.

Situation:  
Logstash-server Conf Files:

- Cisco Asa A
- Cisco Asa B
- Cisco Asa C

These 3 config files have differents Output Indexes and Differents Input UDP ports, but the information sent to " Cisco Asa A " is replicated in the indexes of Cisco ASa B & C .  
Also the physical device " B " & " C" doesn't have syslogs/netflows configured yet.

Doing a Curl to elasticsearch Im saw the index of " B " " C" growing like " Cisco Asa A " , also when I added the " Asa B " & " Asa C" indexes into Kibana I saw the same info than " Cisco Asa A"

I really don't know what is going on here. Im pretty sure that i'm misunderstood something.

can anyone guide me with this situation ?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Joshua\_Rich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshua_rich/32/44953_2.png) [@Joshua\_Rich](https://discuss.elastic.co/u/Joshua_Rich)\
**Post date:** [September 23, 2016, 1:58am UTC](https://discuss.elastic.co/t/same-information-in-differents-indexes/61315/2 "2016-09-23T01:58:12Z")

</div>

Welcome to the Elastic community @mrognone! As a start, can you post your Logstash server config here? That'll help us work out what could be going wrong.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 23, 2016, 6:34am UTC](https://discuss.elastic.co/t/same-information-in-differents-indexes/61315/3 "2016-09-23T06:34:12Z")

</div>

If you place multiple configuration files in a directory and point Logstash to it, it will read all of them and concatenate them. You may therefore need to use [conditionals](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html) to ensure that data is not sent to all configured outputs.

---

<div class="post-metadata">

**Author:** ![mrognone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrognone/32/16034_2.png) [@mrognone](https://discuss.elastic.co/u/mrognone)\
**Post date:** [September 23, 2016, 2:31pm UTC](https://discuss.elastic.co/t/same-information-in-differents-indexes/61315/4 "2016-09-23T14:31:28Z")

</div>

Hi @Joshua_Rich & @Christian_Dahlqvist, Thanks for help me 🙂

@Joshua_Rich, Do you need all config files in /etc/logstash/conf.d ? or i misunderstood you.

@Christian_Dahlqvist I will read about this, maybe there i can find the way to filter the info.

Here is the config file from " Cisco ASa A " the others have the same info , but udp input port ,output index and Host are differents.

input {  
udp {  
port =\> 9933  
codec =\> netflow {  
versions =\> [9]  
}  
}  
}

filter {  
grok {  
match =\> { "host" =\> "10.9.254.1" }  
}

geoip {  
add\_tag =\> ["GeoIP"]  
database =\> "/etc/logstash/GeoLiteCity.dat" ### Change me to location of GeoLiteCity.dat file  
source =\> "netflow.ipv4\_dst\_addr"  
}

if [geoip][city\_name] == "" { mutate { remove\_field =\> "[geoip][city\_name]" } }  
if [geoip][continent\_code] == "" { mutate { remove\_field =\> "[geoip][continent\_code]" } }  
if [geoip][country\_code2] == "" { mutate { remove\_field =\> "[geoip][country\_code2]" } }  
if [geoip][country\_code3] == "" { mutate { remove\_field =\> "[geoip][country\_code3]" } }  
if [geoip][country\_name] == "" { mutate { remove\_field =\> "[geoip][country\_name]" } }  
if [geoip][latitude] == "" { mutate { remove\_field =\> "[geoip][latitude]" } }  
if [geoip][longitude] == "" { mutate { remove\_field =\> "[geoip][longitude]" } }  
if [geoip][postal\_code] == "" { mutate { remove\_field =\> "[geoip][postal\_code]" } }  
if [geoip][region\_name] == "" { mutate { remove\_field =\> "[geoip][region\_name]" } }  
if [geoip][time\_zone] == "" { mutate { remove\_field =\> "[geoip][time\_zone]" } }

}

output {  
stdout { codec =\> rubydebug }  
elasticsearch {  
index =\> "logstash-asa\_netflow\_ba%{+YYYY.MM.dd}"  
hosts =\> "visualizeitlogmonitvm.viridian.local:9200"

}  
}

Thanks In advance.

---

<div class="post-metadata">

**Author:** ![mrognone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrognone/32/16034_2.png) [@mrognone](https://discuss.elastic.co/u/mrognone)\
**Post date:** [September 26, 2016, 2:47pm UTC](https://discuss.elastic.co/t/same-information-in-differents-indexes/61315/5 "2016-09-26T14:47:48Z")

</div>

Hi @Christian_Dahlqvist, how are you ?

I used conditionals as you told me , and now it's working ok.

Thanks a lot !! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:17pm UTC](https://discuss.elastic.co/t/same-information-in-differents-indexes/61315/6 "2017-07-05T22:17:15Z")

</div>


