# Single input and multiple output

**URL:** <https://discuss.elastic.co/t/single-input-and-multiple-output/122632>\
**Category:** Logstash\
**Created:** [March 6, 2018, 3:34am UTC](https://discuss.elastic.co/t/single-input-and-multiple-output/122632 "2018-03-06T03:34:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kalla](https://avatars.discourse-cdn.com/v4/letter/k/e47c2d/32.png) [@kalla](https://discuss.elastic.co/u/kalla)\
**Post date:** [March 6, 2018, 3:34am UTC](https://discuss.elastic.co/t/single-input-and-multiple-output/122632/1 "2018-03-06T03:34:45Z")

</div>

Hi,

It is possible to create multiple index with different column values (In elastic search) with 1 input (beats) ?

My logstash.conf is:

```
input {
  beats {
    port => 5044
  }
}

filter {
  csv {
    separator => ","
    columns => ["A", "B", "C", "D"]
  }

  mutate {
    remove_field => ["message", "prospector", "tags", "beat", "offset", "@version", "host"]
  }
}

output {
    elasticsearch {
      hosts => "http://localhost:9200"
      index => "index-%{[A]}"
      manage_template => false
    }

    elasticsearch {
      hosts => "http://localhost:9200"
      index => "index-%{[B]}"
      manage_template => false
    }
}

```

ex.  
index-%{[A]} will have all the csv columns  
and index-%{[B]} will have only column B

How to configure logstash output part?

---

<div class="post-metadata">

**Author:** ![Shaoranlaos](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Shaoranlaos](https://discuss.elastic.co/u/Shaoranlaos)\
**Post date:** [March 6, 2018, 6:51am UTC](https://discuss.elastic.co/t/single-input-and-multiple-output/122632/2 "2018-03-06T06:51:39Z")

</div>

i don't now if it is possible on logstash side but you could use the mapping configuration on elasticsearch side to disable the fields(columns) that should not be in an index

[https://www.elastic.co/guide/en/elasticsearch/reference/current/enabled.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/enabled.html)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 6, 2018, 6:54am UTC](https://discuss.elastic.co/t/single-input-and-multiple-output/122632/3 "2018-03-06T06:54:14Z")

</div>

You can use a clone filter to splice each event in two. You can then e.g. use a prune filter to delete all fields in the cloned event except the one field you want to keep (and make sure you keep the `@timestamp` field; see [https://github.com/logstash-plugins/logstash-filter-prune/issues/22](https://github.com/logstash-plugins/logstash-filter-prune/issues/22)). The cloned event will be identical to the original event except for a tag that you can use to distinguish it and apply extra filters and pick the other output.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2018, 6:54am UTC](https://discuss.elastic.co/t/single-input-and-multiple-output/122632/4 "2018-04-03T06:54:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
