# Winlogbeat being ingested in both winlog-\* and syslog-\*

**URL:** <https://discuss.elastic.co/t/winlogbeat-being-ingested-in-both-winlog-and-syslog/138218>\
**Category:** Logstash\
**Created:** [July 2, 2018, 1:37pm UTC](https://discuss.elastic.co/t/winlogbeat-being-ingested-in-both-winlog-and-syslog/138218 "2018-07-02T13:37:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![erikjsmith](https://avatars.discourse-cdn.com/v4/letter/e/48db29/32.png) [@erikjsmith](https://discuss.elastic.co/u/erikjsmith)\
**Post date:** [July 2, 2018, 1:37pm UTC](https://discuss.elastic.co/t/winlogbeat-being-ingested-in-both-winlog-and-syslog/138218/1 "2018-07-02T13:37:14Z")

</div>

My Windows Event Collector has Winlogbeat 6.3 on it with it configured to ship to logstash on 5044. I have my logstash listening on both 5044(for winlogbeat) and 5514 (for syslog). My WEC doesn't have filebeat or any other syslog shipper installed on it however all that data winlogbeat data is also ending up in my syslog index. Any ideas what might be causing this and how to stop it?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 2, 2018, 1:39pm UTC](https://discuss.elastic.co/t/winlogbeat-being-ingested-in-both-winlog-and-syslog/138218/2 "2018-07-02T13:39:25Z")

</div>

If you have multiple config files for Logstash, they will get concatenated, so unless you use conditionals, data from all inputs will go to all outputs.

---

<div class="post-metadata">

**Author:** ![erikjsmith](https://avatars.discourse-cdn.com/v4/letter/e/48db29/32.png) [@erikjsmith](https://discuss.elastic.co/u/erikjsmith)\
**Post date:** [July 2, 2018, 1:56pm UTC](https://discuss.elastic.co/t/winlogbeat-being-ingested-in-both-winlog-and-syslog/138218/3 "2018-07-02T13:56:33Z")

</div>

> [@Christian\_Dahlqvist](#):
>
> have multipl

Ok, I have tried to use a conditional in my configs and now my logstash isn't listening on any ports:  
output {  
if [type] == "wineventlog" {  
elasticsearch {  
hosts =\> ["[http://elk.xxxx.com:9200](http://elk.xxxx.com:9200)"]  
index =\> "winlogbeat-%{+YYYY.MM.dd}"  
}  
}  
if [type] == "syslog" {  
elasticsearch {  
hosts =\> [[http://elk.xxxx.com:9200](http://elk.xxxx.com:9200)"  
index ==\> "syslog-%{+YYYY.MM.dd}"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 30, 2018, 1:56pm UTC](https://discuss.elastic.co/t/winlogbeat-being-ingested-in-both-winlog-and-syslog/138218/4 "2018-07-30T13:56:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
