# Single syslog input to multiple indices output

**URL:** <https://discuss.elastic.co/t/single-syslog-input-to-multiple-indices-output/57433>\
**Category:** Logstash\
**Created:** [August 7, 2016, 10:00pm UTC](https://discuss.elastic.co/t/single-syslog-input-to-multiple-indices-output/57433 "2016-08-07T22:00:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bastianhoss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bastianhoss/32/11437_2.png) [@bastianhoss](https://discuss.elastic.co/u/bastianhoss)\
**Post date:** [August 7, 2016, 10:00pm UTC](https://discuss.elastic.co/t/single-syslog-input-to-multiple-indices-output/57433/1 "2016-08-07T22:00:45Z")

</div>

Hi Community,

searching a way for multiple indice output. In this case with a lot of different programs. Cisco ASA...

My inputs is syslog, forwarding rsyslog massages in type "syslog"

input {  
syslog {  
type =\> syslog  
port =\> 10514  
}  
}

filter options are possible when using program:

```
 else if [program] == "%ASA*" {
     grok{
        match => [
           "message" , "%{GREEDYDATA:data} "
        ]
     }
  }

```

and output dosen't work with:

...  
else if [program] == "%ASA\*" {  
elasticsearch {  
hosts =\> ["ip:9200"]  
index =\> "firewall-"  
}  
}

Any ideas ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 10, 2016, 5:57am UTC](https://discuss.elastic.co/t/single-syslog-input-to-multiple-indices-output/57433/2 "2016-08-10T05:57:19Z")

</div>

Conditionals work fine within an `output` block so it's not clear what the problem is. I found two weird things though:

> else if [program] == "%ASA\*" {

Is the `program` field literally "%ASA\*"? Or are you trying to use \* as a wildcard character?

> index =\> "firewall-"

Do you really want to store the events in an index named, literally, "firewall-"?

---

<div class="post-metadata">

**Author:** ![bastianhoss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bastianhoss/32/11437_2.png) [@bastianhoss](https://discuss.elastic.co/u/bastianhoss)\
**Post date:** [August 17, 2016, 7:27am UTC](https://discuss.elastic.co/t/single-syslog-input-to-multiple-indices-output/57433/3 "2016-08-17T07:27:53Z")

</div>

Hi,

- is a wildcard...

else if "ASA" in [program] {  
elasticsearch {  
index =\> "firewall-"  
}  
}

brings the correct seperation....

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:43am UTC](https://discuss.elastic.co/t/single-syslog-input-to-multiple-indices-output/57433/4 "2017-07-06T04:43:08Z")

</div>


