# Apache logs by virtualhost in ELK 6.7

**URL:** <https://discuss.elastic.co/t/apache-logs-by-virtualhost-in-elk-6-7/179822>\
**Category:** Logstash\
**Created:** [May 6, 2019, 5:16pm UTC](https://discuss.elastic.co/t/apache-logs-by-virtualhost-in-elk-6-7/179822 "2019-05-06T17:16:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Victor\_Guerrero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/victor_guerrero/32/45649_2.png) [@Victor\_Guerrero](https://discuss.elastic.co/u/Victor_Guerrero)\
**Post date:** [May 6, 2019, 5:16pm UTC](https://discuss.elastic.co/t/apache-logs-by-virtualhost-in-elk-6-7/179822/1 "2019-05-06T17:16:50Z")

</div>

Hi community,

I spent a couple of days looking for a solution without luck.

I have a server with different domains hosted, also known as virtual host, running Apache2 as front server. Each domain has their own logs with a file directory structure like that:

- /var/www/domain1.com/logs/access\_ssl\_log,
- /var/www/domain2.com/logs/access\_ssl\_log
- /var/www/domain3.com/logs/access\_ssl\_log
- ....

There is a way of have domain logs separated by indexes in Elasticsearch?

I'm using ELK 6.7.2 + Filesbeat 6.7.2

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 6, 2019, 6:34pm UTC](https://discuss.elastic.co/t/apache-logs-by-virtualhost-in-elk-6-7/179822/2 "2019-05-06T18:34:08Z")

</div>

If you are ingesting the files with filebeat they will have the file name on every event. You can parse the domain name out of the path and use a [sprintf](https://www.elastic.co/guide/en/logstash/5.2/event-dependent-configuration.html#sprintf) reference for the index name.

That said, if this results in a large number of small indexes you may have performance problems.

---

<div class="post-metadata">

**Author:** ![Victor\_Guerrero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/victor_guerrero/32/45649_2.png) [@Victor\_Guerrero](https://discuss.elastic.co/u/Victor_Guerrero)\
**Post date:** [May 6, 2019, 6:50pm UTC](https://discuss.elastic.co/t/apache-logs-by-virtualhost-in-elk-6-7/179822/3 "2019-05-06T18:50:38Z")

</div>

Hi Badger,

Please, could you explain how I can implement the option that you have suggested?

Thanks !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 3, 2019, 6:50pm UTC](https://discuss.elastic.co/t/apache-logs-by-virtualhost-in-elk-6-7/179822/4 "2019-06-03T18:50:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
