# Syslogs sent to wrong index

**URL:** <https://discuss.elastic.co/t/syslogs-sent-to-wrong-index/226734>\
**Category:** Logstash\
**Created:** [April 6, 2020, 2:38pm UTC](https://discuss.elastic.co/t/syslogs-sent-to-wrong-index/226734 "2020-04-06T14:38:51Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Roger\_Westgren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roger_westgren/32/65741_2.png) [@Roger\_Westgren](https://discuss.elastic.co/u/Roger_Westgren)\
**Post date:** [April 6, 2020, 2:38pm UTC](https://discuss.elastic.co/t/syslogs-sent-to-wrong-index/226734/1 "2020-04-06T14:38:51Z")

</div>

Hi!

I have a weird problem with my Logstash configuration. There are 2 .conf files in /etc/logstash/conf.d (beats.conf and syslog.conf).

![image](https://us1.discourse-cdn.com/elastic/original/3X/1/8/1876ac1bf34d7a00fb59818bdb0cc05c8a5f7cb5.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/0/d0e8acd927393ee55cb74a54e90e2881105057a2.png)

All the Beats agents get sent to port 5043 (beats.conf), and that's working fine, but I can't find the index pattern to create the syslog-\* index.  
Instead I find this new index (which is the index in the beats.conf file):

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/c/bce26dd2848420c2d0ddca0c7a8f1de3d21fbbda.png)

So I got curious and created the index pattern "%{[@metadata][beat]}-\*"  
and when I check it in the Discover tab all the syslog logs are there.

Port 5140 is listening, both udp and tcp.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/c/bc43cc5174eadd37328d959d8c0bb00761379a0b.png)

I can't figure out why this is happening and can't seem to find any one else with the same problem when I search the web. Can anyone help?

Many thanks!

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [April 6, 2020, 4:08pm UTC](https://discuss.elastic.co/t/syslogs-sent-to-wrong-index/226734/2 "2020-04-06T16:08:43Z")

</div>

Hi,

You should create 3 separates files 01-input.conf where you list all your inputs  
02-filter.conf where you can filter logs and one 03-output.conf.

As for the input file just add

```auto
if [type] == "foo" {
 elasticsearch {

            hosts => "localhost:9200"
            index => "foologs"

        }
}

```

As i see the problem it's just that the outputs you are using aren't processed at the same time.

---

<div class="post-metadata">

**Author:** ![Roger\_Westgren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roger_westgren/32/65741_2.png) [@Roger\_Westgren](https://discuss.elastic.co/u/Roger_Westgren)\
**Post date:** [April 7, 2020, 6:26am UTC](https://discuss.elastic.co/t/syslogs-sent-to-wrong-index/226734/3 "2020-04-07T06:26:36Z")

</div>

Thank's @grumo35, I've created the 3 files you suggested but getting this error:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/4/843a8357c4e23fc1ab2a41c02e9eb8c9386a9833.png)

I haven't been working with ELK for very long so it would really help if you can detail the explanation/answer a little more.

These are the .conf files I made:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/c/7c1991bccd40c08c5835429079f9ded09263068c.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/9/39dca49ff6ca108fb98794f6de3ca9b91ade1db4.png)

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0d748a83fb7e80d360cf02a9b238ddfd0a5462e4.png)

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [April 7, 2020, 7:56am UTC](https://discuss.elastic.co/t/syslogs-sent-to-wrong-index/226734/4 "2020-04-07T07:56:48Z")

</div>

Oh wow sorry i was exhausted yesterday i just put you in trouble, i was meaning to filter in types in the ouptut file not the input one.

Just remove the condition your input.conf should look like this :

```auto
 input{
     tcp { XXXX }
     udp { XXXX }
}

```

And the output file is where you sort events to be indexed :

```auto
output{
if [type] == "foo" {
 elasticsearch {

            hosts => "localhost:9200"
            index => "foologs"

        }
}
}

```

> I haven't been working with ELK for very long so it would really help if you can detail the explanation/answer a little more.

I just used separates files to make it more clear that logstash is processing files depending on their names and this is important to know since you were using multiple files but did not took care of their processing order for logstash.

If you wish to you could just use one big file but it makes it easier to configure with separates files.

Sorry for misleading you yesterday. Let me know if this solution works.

---

<div class="post-metadata">

**Author:** ![Roger\_Westgren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roger_westgren/32/65741_2.png) [@Roger\_Westgren](https://discuss.elastic.co/u/Roger_Westgren)\
**Post date:** [April 7, 2020, 12:18pm UTC](https://discuss.elastic.co/t/syslogs-sent-to-wrong-index/226734/5 "2020-04-07T12:18:10Z")

</div>

It's working now, thanks a whole lot @grumo35!

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [April 7, 2020, 12:27pm UTC](https://discuss.elastic.co/t/syslogs-sent-to-wrong-index/226734/6 "2020-04-07T12:27:06Z")

</div>

Thanks dont hesistate to mark as solved with answer for future members to look at.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2020, 12:27pm UTC](https://discuss.elastic.co/t/syslogs-sent-to-wrong-index/226734/7 "2020-05-05T12:27:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
