input { udp { host => "172.29.12.11" port => 514 codec => "json" type => "rsyslog" } } output { if [type] == "rsyslog" { elasticsearch { hosts => [ "172.29.12.11:9200" ] index => "logstash-%{+YYYY.MM.dd}" } } }