# Separate ELK pattern for log files

**URL:** <https://discuss.elastic.co/t/separate-elk-pattern-for-log-files/339817>\
**Category:** Elasticsearch\
**Created:** [August 1, 2023, 2:56pm UTC](https://discuss.elastic.co/t/separate-elk-pattern-for-log-files/339817 "2023-08-01T14:56:36Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sanjeev1895](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Post date:** [August 1, 2023, 2:56pm UTC](https://discuss.elastic.co/t/separate-elk-pattern-for-log-files/339817/1 "2023-08-01T14:56:36Z")

</div>

Hi team,  
Can any one help me to find the solution for my below requirement.

I have two apache server and I want to send the apache access and error logs to elk server via filebeat apache module to logstash. I configured apache.yml and apache.conf file in logstash.  
example:  
in logstash,  
apache1.conf - srever1  
apache2.conf - server2. with different index name.  
These configuration was working fine, but the issue is it sending the logs to both index name.  
see my apache.conf file below,( apache2.conf file also same , only the difference is file path and index name)

```auto
input {
  beats {
     port => 5044
 }
}

filter {
    if [log][file][path] in ["/var/log/apache2/sfsite-access_log","/var/log/apache2/sfapi-access_log"] {
      grok {
        match => { "message" => "\[%{HTTPDATE:time_stamp}\] %{HOSTNAME:domain_name} \"%{WORD:method} /%{NOTSPACE:request_page} HTTP/%{NUMBER:http_version}\" %{NUMBER:response_code} (?:%{NUMBER:response_bytes}|-) %{QS:agent} %{NOTSPACE:page_url} %{QS:agent_type}" }

 }
      grok {
        match => { "message" => "%{IP:client_ip}" }
 }
      geoip {
        source => "[client_ip]"
        ecs_compatibility => disabled
      }
}

else if [log][file][path] in ["/var/log/apache2/sfsite-error_log","/var/log/apache2/sfapi-error_log"] {
      grok {
        match => { "message" => "\[%{HTTPDERROR_DATE:timestamp-error}\] \[%{DATA:loglevel}%{SPACE}\] \[%{DATA:process-id}%{SPACE}\]%{SPACE}\[%{DATA:client-ip}\] %{GREEDYDATA:message} (\[%{NOTSPACE:Index}\]\[%{NUMBER:shards}\])?%{GREEDYDATA} %{GREEDYDATA:referred_url}" }
   }
 }
}

output {
  elasticsearch {
    hosts => ["https://a.a.a.a:9200"]
    index => "index-testing-%{+YYYY.MM.dd}"
    user => "elastic"
    password => "pppppp"
    ssl => true
    cacert => "/etc/logstash/http_ca.crt"
  }
}

```

can any one help me out this.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 1, 2023, 2:59pm UTC](https://discuss.elastic.co/t/separate-elk-pattern-for-log-files/339817/2 "2023-08-01T14:59:22Z")

</div>

> [@sanjeev1895](#):
>
> These configuration was working fine, but the issue is it sending the logs to both index name.

You need to have conditionals in the output as well, the same ones that you are using in the filter section.

---

<div class="post-metadata">

**Author:** ![sanjeev1895](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Post date:** [August 1, 2023, 5:45pm UTC](https://discuss.elastic.co/t/separate-elk-pattern-for-log-files/339817/3 "2023-08-01T17:45:37Z")

</div>

Hi @Leandrojmp

Can you give any examples for configure the conditional statements in output sections as well. It will more helpful.

Also is there any documentation..!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 1, 2023, 5:52pm UTC](https://discuss.elastic.co/t/separate-elk-pattern-for-log-files/339817/4 "2023-08-01T17:52:43Z")

</div>

> [@sanjeev1895](#):
>
> Can you give any examples for configure the conditional statements in output sections as well.

It is exactly the same ones you are using in your filter.

It would be something like this:

```auto
output {
  if [log][file][path] in ["/var/log/apache2/sfsite-access_log","/var/log/apache2/sfapi-access_log"] {
    elasticsearch { your output for this indice}
  } else if [log][file][path] in ["/var/log/apache2/sfsite-error_log","/var/log/apache2/sfapi-error_log"] {
    elasticsearch { your output for this indice}
  }
}

```

> [@sanjeev1895](#):
>
> Also is there any documentation..!

The documentation about conditionals is [this one](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#event-dependent-configuration).

---

<div class="post-metadata">

**Author:** ![sanjeev1895](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Post date:** [August 1, 2023, 6:14pm UTC](https://discuss.elastic.co/t/separate-elk-pattern-for-log-files/339817/5 "2023-08-01T18:14:09Z")

</div>

@leandrojmp

Thank you so much for your guidance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 29, 2023, 6:14pm UTC](https://discuss.elastic.co/t/separate-elk-pattern-for-log-files/339817/6 "2023-08-29T18:14:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
