# Single input with different filter and output

**URL:** <https://discuss.elastic.co/t/single-input-with-different-filter-and-output/129378>\
**Category:** Logstash\
**Created:** [April 24, 2018, 10:10pm UTC](https://discuss.elastic.co/t/single-input-with-different-filter-and-output/129378 "2018-04-24T22:10:24Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mayurshah](https://avatars.discourse-cdn.com/v4/letter/m/85e7bf/32.png) [@mayurshah](https://discuss.elastic.co/u/mayurshah)\
**Post date:** [April 24, 2018, 10:10pm UTC](https://discuss.elastic.co/t/single-input-with-different-filter-and-output/129378/1 "2018-04-24T22:10:24Z")

</div>

Hi,

I am using logstash 5.6.3 and am trying to figureout how to configure multiple filter and output for a single input. My setup is filebeat forwarding to logstash and from logstash I want out put to elasticsearch as well as csvfile. in both output required fields are little different and formatting is also bit different.

Could someone please give me some direction?  
Appreciate your help.

- Mayur

---

<div class="post-metadata">

**Author:** ![PandKing](https://avatars.discourse-cdn.com/v4/letter/p/258eb7/32.png) [@PandKing](https://discuss.elastic.co/u/PandKing)\
**Post date:** [April 25, 2018, 12:49am UTC](https://discuss.elastic.co/t/single-input-with-different-filter-and-output/129378/2 "2018-04-25T00:49:07Z")

</div>

input {  
beats {  
port =\> 5044  
}  
}

output{  
elasticsearch {  
hosts =\> "elastic:9200"  
sniffing =\> false  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
} # End elasticsearch

```
file {
path => "/opt/logstash/%{host}-%{+YYYY-MM-dd}.json"
codec => "json_lines"
}

```

}

---

<div class="post-metadata">

**Author:** ![mayurshah](https://avatars.discourse-cdn.com/v4/letter/m/85e7bf/32.png) [@mayurshah](https://discuss.elastic.co/u/mayurshah)\
**Post date:** [April 25, 2018, 1:36am UTC](https://discuss.elastic.co/t/single-input-with-different-filter-and-output/129378/3 "2018-04-25T01:36:58Z")

</div>

Thanks PandKing for quick answer. I guess my original question was not clear enough.

I could reach to somewhat similar point. I'm actually stuck at filter and list of fields that I want in both the outputs.

Below is sample http log.

50._ **.**._\* - - [25/Apr/2018:01:11:52 -0000] "GET [https://myserver/my/path](https://myserver/my/path) http/2" 200 1636728 200 1636728 0 0 335 579 468 571 0.524 0.450 DIRECT FIN FIN TCP\_MISS "AppleCoreMedia/1.0.0.14W585a (Apple TV; U; CPU OS 10\_2\_1 like Mac OS X; en\_us)" 14BF2CA8-9291-42E0-8A32-3FF6897ACBD9

I want to parse all the fields and send it to elastic as is. I want to do little extra when I send it to file.

1. I want to convert httpdate to epoch and change IP to geo location details.

Now what is happening is, any mutation I do in filter and all new fields are ending up in elastic index.

Can I be selective about which fields goes to elastic and which fields goes to file?

Thanks,  
Mayur

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 25, 2018, 6:02am UTC](https://discuss.elastic.co/t/single-input-with-different-filter-and-output/129378/4 "2018-04-25T06:02:32Z")

</div>

> Can I be selective about which fields goes to elastic and which fields goes to file?

No, but you can use a clone filter to split each event in two. Configure Logstash to send the original to ES and modify the cloned event as you please and send it to the file.

---

<div class="post-metadata">

**Author:** ![mayurshah](https://avatars.discourse-cdn.com/v4/letter/m/85e7bf/32.png) [@mayurshah](https://discuss.elastic.co/u/mayurshah)\
**Post date:** [May 7, 2018, 10:22pm UTC](https://discuss.elastic.co/t/single-input-with-different-filter-and-output/129378/5 "2018-05-07T22:22:01Z")

</div>

Thanks mangnusbaeck. This solves my problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2018, 10:22pm UTC](https://discuss.elastic.co/t/single-input-with-different-filter-and-output/129378/6 "2018-06-04T22:22:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
