# Unable to create multiple index in elasticsearch from logstash with multiple input

**URL:** <https://discuss.elastic.co/t/unable-to-create-multiple-index-in-elasticsearch-from-logstash-with-multiple-input/201706>\
**Category:** Logstash\
**Created:** [October 1, 2019, 12:58am UTC](https://discuss.elastic.co/t/unable-to-create-multiple-index-in-elasticsearch-from-logstash-with-multiple-input/201706 "2019-10-01T00:58:12Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Asmaa\_Sarih](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asmaa_sarih/32/55145_2.png) [@Asmaa\_Sarih](https://discuss.elastic.co/u/Asmaa_Sarih)\
**Post date:** [October 1, 2019, 12:58am UTC](https://discuss.elastic.co/t/unable-to-create-multiple-index-in-elasticsearch-from-logstash-with-multiple-input/201706/1 "2019-10-01T00:58:13Z")

</div>

Hi Team,

Can anyone help me in confugiring multiple indexes from multiple input with logstash,  
I am unable to create multiple index in elastic (with multiple if conditions) . One index is getting created but not both,  
and it works well if I do just one condition with : if , else .  
But if I want to create more than two indexes with multipe input ?,

My logstash.conf file  
input {  
udp {  
host =\> "127.0.0.1"  
port =\> 10514  
codec =\> "json"  
type =\> "rsyslog"  
}  
file {  
type =\> "fortigate"  
path =\> "/home/user/Téléchargements/fortiWebFilter.log"  
sincedb\_path =\> "/dev/null"  
start\_position =\> "beginning"  
}  
}

filter {  
if [type] == "fortigate" {

```
grok {
	match => ["message", "%{SYSLOG5424PRI:syslog_index}%{GREEDYDATA:message}"]
	#overwrite => ["message"]
	tag_on_failure => ["failure_grok_fortigate"]
}

kv {

```

value\_split =\> "="

}

mutate {

#I want to use the timestamp inside the logs instead of Logstash's timestamp so we'll first create a new field containing the date and time fields from the syslog before we convert that to the @timestamp field  
add\_field =\> { "temp\_time" =\> "%{date} %{time}" }  
#add\_field =\> { "Desti\_Country" =\> "%{dstip}" }  
#The syslog contains a type field which messes with the Logstash type field so we have to rename it.  
rename =\> { "type" =\> "ftg\_type" }  
#rename =\> { "ip" =\> "Desti\_IP" }  
rename =\> { "subtype" =\> "ftg\_subtype" }  
#add\_field =\> { "type" =\> "forti\_log" }  
convert =\> { "rcvdbyte" =\> "integer" }  
convert =\> { "sentbyte" =\> "integer" }  
}

date {  
match =\> ["temp\_time", "yyyy-MM-dd HH:mm:ss"]  
timezone =\> "UTC"  
target =\> "@timestamp"  
}

geoip {  
source =\> "dstip"  
add\_field =\> ["[geoip][desti\_ip]", "%{[geoip][ip]}" ]  
}

mutate {

#add/remove fields as you see fit.  
remove\_field =\> ["syslog\_index","sessionid","dstcountry","dstip","transip","country\_code3","region\_code","country\_code2","syslog5424\_pri","transport","appcat","srccountry","dstintf","devid","@version","itime","path","logver","logid","vd","host","srcintf","trandisp","location","date","time","service","temp\_time","tags","sentpkt","rcvdpkt","log\_id","message","poluuid"]

remove\_field =\> "[geoip][longitude]"  
remove\_field =\> "[geoip][region\_code]"  
remove\_field =\> "[geoip][country\_code3]"  
remove\_field =\> "[geoip][continent\_code]"  
remove\_field =\> "[geoip][country\_code2]"  
remove\_field =\> "[geoip][latitude]"  
remove\_field =\> "[geoip][location]"  
remove\_field =\> "[geoip][region\_name]"  
remove\_field =\> "[geoip][ip]"  
}

}  
}

output {  
#stdout { codec =\> rubydebug }  
if [type] == "rsyslog" {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "rsyslog-index"  
}  
}  
if [type] == "fortigate"{  
elasticsearch {  
hosts =\> "localhost:9200"  
#http\_compression =\> "true"  
index =\> "forti-index"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 29, 2019, 12:58am UTC](https://discuss.elastic.co/t/unable-to-create-multiple-index-in-elasticsearch-from-logstash-with-multiple-input/201706/2 "2019-10-29T00:58:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
