# Why does Logstash write into two indices? (default and custom ones)

**URL:** <https://discuss.elastic.co/t/why-does-logstash-write-into-two-indices-default-and-custom-ones/75233>\
**Category:** Logstash\
**Created:** [February 15, 2017, 5:37pm UTC](https://discuss.elastic.co/t/why-does-logstash-write-into-two-indices-default-and-custom-ones/75233 "2017-02-15T17:37:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mr.King](https://avatars.discourse-cdn.com/v4/letter/m/bbe5ce/32.png) [@Mr.King](https://discuss.elastic.co/u/Mr.King)\
**Post date:** [February 15, 2017, 5:37pm UTC](https://discuss.elastic.co/t/why-does-logstash-write-into-two-indices-default-and-custom-ones/75233/1 "2017-02-15T17:37:18Z")

</div>

Hello,

I am using Elasticsearch 5.2 and Logstash 5.2 .

My problem is that Logstash is writing into the default index (format logstash-2017.02.15) and into my custom one. I just want it to write only into my "logstash-secure" index. How can I do?

Here is my simple Logstash configuration:

```
output {
    elasticsearch {
        hosts => ["elasticsearch:9200"]
        index => "logstash-secure"
    }
    stdout { codec => rubydebug }
}

```

PS: if you tell me that I have to use a custom template, could you please explain me why? 🙂

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 15, 2017, 6:25pm UTC](https://discuss.elastic.co/t/why-does-logstash-write-into-two-indices-default-and-custom-ones/75233/2 "2017-02-15T18:25:47Z")

</div>

Logstash sends events to logstash-2017.02.15 because you've told it to. I suspect you have more than one configuration file in /etc/logstash/conf.d. Remember that Logstash reads _all_ files in that directory.

---

<div class="post-metadata">

**Author:** ![Mr.King](https://avatars.discourse-cdn.com/v4/letter/m/bbe5ce/32.png) [@Mr.King](https://discuss.elastic.co/u/Mr.King)\
**Post date:** [February 15, 2017, 8:27pm UTC](https://discuss.elastic.co/t/why-does-logstash-write-into-two-indices-default-and-custom-ones/75233/3 "2017-02-15T20:27:12Z")

</div>

Thank you Magnus for your answer.  
You are right, I have an other configuration. I did not paste it because I thought there was no incidence.

Here is my first conf file:

```
input {
    beats {
        port => "5044"
    }
}

filter {
[some conf]
}

output {
    elasticsearch {
        hosts => ["elasticsearch:9200"]
    }
}

```

And my second conf file:

```
input {
  file {
    path => "/var/log/secure"
    start_position => "beginning"
  }
}
filter {
[some conf]
}
output {
    elasticsearch {
        hosts => ["elasticsearch:9200"]
        index => "logstash-secure"
    }
    stdout { codec => rubydebug }
}

```

If I understand your answer, no matter in which file the configuration is written the ouputs sections are "merged"?  
If it is the case, my question would become "_how could I route two inputs into two different indices_"?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 15, 2017, 8:49pm UTC](https://discuss.elastic.co/t/why-does-logstash-write-into-two-indices-default-and-custom-ones/75233/4 "2017-02-15T20:49:36Z")

</div>

> If I understand your answer, no matter in which file the configuration is written the ouputs sections are "merged"?

Yes.

> If it is the case, my question would become "how could I route two inputs into two different indices"?

Use conditionals, e.g. based on the message type or some other field.

> **[Accessing event data and fields | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html)**

---

<div class="post-metadata">

**Author:** ![Mr.King](https://avatars.discourse-cdn.com/v4/letter/m/bbe5ce/32.png) [@Mr.King](https://discuss.elastic.co/u/Mr.King)\
**Post date:** [February 15, 2017, 10:10pm UTC](https://discuss.elastic.co/t/why-does-logstash-write-into-two-indices-default-and-custom-ones/75233/5 "2017-02-15T22:10:11Z")

</div>

Thank you very much for your help Magnus.  
I solved my issue with the conditional statements.  
I post it for people who can wonder the same question 🙂

Here is my new first conf file:

```
input {
    beats {
        port => "5044"
        add_field => { "log_type" => "apache" }
    }
}
filter {
[some conf]
}
output {
    if [log_type] == "apache" {
        elasticsearch {
            hosts => ["elasticsearch:9200"]
        }
    }
}

```

And my second conf file:

```
input {
  file {
    path => "/var/log/secure"
    start_position => "beginning"
    add_field => { "log_type" => "secure.log" }
  }
}
filter {
[some conf]
}
output {
        if [log_type] == "secure.log" {
           elasticsearch {
               hosts => ["elasticsearch:9200"]
               index => "logstash-secure"
           }
       }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 15, 2017, 10:10pm UTC](https://discuss.elastic.co/t/why-does-logstash-write-into-two-indices-default-and-custom-ones/75233/6 "2017-03-15T22:10:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
