# APM indexes throught logstash

**URL:** <https://discuss.elastic.co/t/apm-indexes-throught-logstash/150359>\
**Category:** APM\
**Created:** [September 28, 2018, 2:44pm UTC](https://discuss.elastic.co/t/apm-indexes-throught-logstash/150359 "2018-09-28T14:44:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alexkl](https://avatars.discourse-cdn.com/v4/letter/a/858c86/32.png) [@Alexkl](https://discuss.elastic.co/u/Alexkl)\
**Post date:** [September 28, 2018, 2:44pm UTC](https://discuss.elastic.co/t/apm-indexes-throught-logstash/150359/1 "2018-09-28T14:44:00Z")

</div>

Hello,

I am using ELK 6.4.0

I was using apm with elasticsearch output but i would like to replace it by logstash output.

In my output.elasticsearch i set multiples index depending on processor.event:

> ```
> indices:
> - index: "apm-%{[beat.version]}-sourcemap"
> when.contains:
> processor.event: "sourcemap"
> - index: "apm-%{[beat.version]}-error-%{+yyyy.MM.dd}"
> when.contains:
> processor.event: "error"
> - index: "apm-%{[beat.version]}-transaction-%{+yyyy.MM.dd}"
> when.contains:
> processor.event: "transaction"
> - index: "apm-%{[beat.version]}-span-%{+yyyy.MM.dd}"
> when.contains:
> processor.event: "span"
> - index: "apm-%{[beat.version]}-metric-%{+yyyy.MM.dd}"
> when.contains:
> processor.event: "metric"
> - index: "apm-%{[beat.version]}-onboarding-%{+yyyy.MM.dd}"
> when.contains:
> processor.event: "onboarding"
> 
> ```

So i tried to do the same in my logstash output :

> else if "apm-server" in [@metadata][beat] {  
> elasticsearch {  
> hosts =\> ["logs-es1:9200","logs-es2:9200"]  
> index =\> "apm-%{[processor][event]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
> }  
> }

However when i do that, i have no available logs showing in the discover part. But a lot of shards failed appeared (if i change my output to elasticsearch again, all my problems disappear).

Do you have an idea of what going on ?

Thank you very much

---

<div class="post-metadata">

**Author:** ![gil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gil/32/41911_2.png) [@gil](https://discuss.elastic.co/u/gil)\
**Post date:** [September 28, 2018, 4:44pm UTC](https://discuss.elastic.co/t/apm-indexes-throught-logstash/150359/2 "2018-09-28T16:44:15Z")

</div>

Hello @Alexkl,

You'll need to switch your logstash index directive a bit to match up with the `output.elasticsearch` setting provided - the event and version are reversed:

```auto
index => "apm-%{[@metadata][version]}-%{[processor][event]}-%{+YYYY.MM.dd}"

```

Once that's done, you'll be writing to an index with the correct template to power the APM UI.

---

<div class="post-metadata">

**Author:** ![Alexkl](https://avatars.discourse-cdn.com/v4/letter/a/858c86/32.png) [@Alexkl](https://discuss.elastic.co/u/Alexkl)\
**Post date:** [October 3, 2018, 3:22pm UTC](https://discuss.elastic.co/t/apm-indexes-throught-logstash/150359/3 "2018-10-03T15:22:28Z")

</div>

Thanks... i am ashamed 😃

---

<div class="post-metadata">

**Author:** ![gil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gil/32/41911_2.png) [@gil](https://discuss.elastic.co/u/gil)\
**Post date:** [October 4, 2018, 2:04pm UTC](https://discuss.elastic.co/t/apm-indexes-throught-logstash/150359/4 "2018-10-04T14:04:51Z")

</div>

Glad to hear that resolved it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2018, 10:04am UTC](https://discuss.elastic.co/t/apm-indexes-throught-logstash/150359/5 "2018-10-25T10:04:54Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
