Noob here, so don't judge too hard.
However, I am wanting to find out if it's possible to have an output as such that's looking for specific tags and sending those messages to the windows* index but if they don't match they go to a pipeline* index. Is that possible???
}
output {
if "NxLog","Windows Event" in [tags] {
elasticsearch {
hosts => "${ELASTICSEARCH_HOST_AND_PORT:elasticsearch.:9200}"
index => "windowsevent-%{+YYYY.MM.dd}"
}}
else {
elasticsearch {
hosts => "${ELASTICSEARCH_HOST_AND_PORT:elasticsearch.:9200}"
index => "pipeline-%{+YYYY.MM.dd}"
}
}