# Work with multiples inputs/outputs in microsoft-logstash-output-azure-loganalytics plugin

**URL:** <https://discuss.elastic.co/t/work-with-multiples-inputs-outputs-in-microsoft-logstash-output-azure-loganalytics-plugin/324068>\
**Category:** Logstash\
**Created:** [January 26, 2023, 7:17pm UTC](https://discuss.elastic.co/t/work-with-multiples-inputs-outputs-in-microsoft-logstash-output-azure-loganalytics-plugin/324068 "2023-01-26T19:17:48Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rafael\_Oliveira](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rafael_oliveira/32/116447_2.png) [@Rafael\_Oliveira](https://discuss.elastic.co/u/Rafael_Oliveira)\
**Post date:** [January 26, 2023, 7:17pm UTC](https://discuss.elastic.co/t/work-with-multiples-inputs-outputs-in-microsoft-logstash-output-azure-loganalytics-plugin/324068/1 "2023-01-26T19:17:48Z")

</div>

I'm working with microsoft-logstash-output-azure-loganalytics plugin and have to receive different inputs and send to different output based on tags or port. Is is possible? Let's my config file:

```auto
input {
      tcp {
          port => "5014"
          type => syslog #optional, will effect log type in table
          tags => ["legacy1"]
      }
      tcp {
          port => "5015"
          type => syslog #optional, will effect log type in table
          tags => ["legacy2"]
      }

  }
  filter {
  }
  output {
        if "legacy1" in [tags] {

      microsoft-logstash-output-azure-loganalytics {
        workspace_id => "" # <your workspace id>
        workspace_key => "" # <your workspace key>
        custom_log_table_name => "tablelegacy1"
      }

}

        if "legacy2" in [tags] {

      microsoft-logstash-output-azure-loganalytics {
        workspace_id => "" # <your workspace id>
        workspace_key => "" # <your workspace key>
        custom_log_table_name => "tablelegacy2"
      }
    }

  }

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 26, 2023, 10:40pm UTC](https://discuss.elastic.co/t/work-with-multiples-inputs-outputs-in-microsoft-logstash-output-azure-loganalytics-plugin/324068/2 "2023-01-26T22:40:58Z")

</div>

Welcome to our community.

Yes, it's possible for both cases, tag or port. Here is a similar [sample](https://gist.github.com/jalogisch/fe9da2ce9d958ae9ea10d82b500e00dd).

---

<div class="post-metadata">

**Author:** ![Rafael\_Oliveira](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rafael_oliveira/32/116447_2.png) [@Rafael\_Oliveira](https://discuss.elastic.co/u/Rafael_Oliveira)\
**Post date:** [January 27, 2023, 3:42pm UTC](https://discuss.elastic.co/t/work-with-multiples-inputs-outputs-in-microsoft-logstash-output-azure-loganalytics-plugin/324068/3 "2023-01-27T15:42:16Z")

</div>

I did that simple test but only the first file was created.

Let's the code:

```auto
input {
      tcp {
          port => "30001"
          codec => "json"
          tags => "Teste1"
      }
      tcp {
          port => "30002"
          codec => "json"
          tags => "Teste2"
      }

  }
  filter {
  }

output {
     if "Teste1" in [tags] {
     file {
     path => "/tmp/Log_Teste1.log"
     }

     if "Teste2" in [tags] {
     file {
     path => "/tmp/Log_Teste2.log"
     }
   }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 27, 2023, 4:08pm UTC](https://discuss.elastic.co/t/work-with-multiples-inputs-outputs-in-microsoft-logstash-output-azure-loganalytics-plugin/324068/4 "2023-01-27T16:08:19Z")

</div>

Add to see your data. Use the command line to run LS, not service.

output {  
stdout { codec =\> rubydebug{} }  
...  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2023, 4:09pm UTC](https://discuss.elastic.co/t/work-with-multiples-inputs-outputs-in-microsoft-logstash-output-azure-loganalytics-plugin/324068/5 "2023-02-24T16:09:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
