# Separate configs, different indexes yet both logs go to both indexes

**URL:** <https://discuss.elastic.co/t/separate-configs-different-indexes-yet-both-logs-go-to-both-indexes/102411>\
**Category:** Logstash\
**Created:** [October 2, 2017, 8:09am UTC](https://discuss.elastic.co/t/separate-configs-different-indexes-yet-both-logs-go-to-both-indexes/102411 "2017-10-02T08:09:02Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![X\_Calibur](https://avatars.discourse-cdn.com/v4/letter/x/b2d939/32.png) [@X\_Calibur](https://discuss.elastic.co/u/X_Calibur)\
**Post date:** [October 2, 2017, 8:09am UTC](https://discuss.elastic.co/t/separate-configs-different-indexes-yet-both-logs-go-to-both-indexes/102411/1 "2017-10-02T08:09:02Z")

</div>

I have the following 2 config files:

############IMAP Email reader############

input {  
imap {  
host =\> "[imap.gmail.com](http://imap.gmail.com)"  
user =\> "account@gmail.com"  
password =\> "pass"  
secure =\> true  
port =\> 993  
check\_interval =\> 30

}  
}

output{  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "mailbox-%{+YYYY.MM.dd}"  
user =\> user  
password =\> pass  
}  
}

#########SYSLOG to firewall##########

input{

```
    syslog {
            type => "syslog"
            port => 55555
    }

```

}

output{  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "fortigate-%{+YYYY.MM.dd}"  
user =\> user  
password =\> pass  
}  
}

For some reason I'm seeing both logs on both indexes. Meaning the indexes are duplicates of each other. I have no idea how and why that happens...

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 2, 2017, 8:18am UTC](https://discuss.elastic.co/t/separate-configs-different-indexes-yet-both-logs-go-to-both-indexes/102411/2 "2017-10-02T08:18:06Z")

</div>

Have a look at [this thread](https://discuss.elastic.co/t/problem-with-output-elasticsearch-data-duplicate-on-index/101981). Logstash basically concatenates all files in the config directory, which means that all inputs will go to all outputs unless you use conditionals.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 30, 2017, 8:18am UTC](https://discuss.elastic.co/t/separate-configs-different-indexes-yet-both-logs-go-to-both-indexes/102411/3 "2017-10-30T08:18:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
