# Auditbeat and filebeat in same Index

**URL:** <https://discuss.elastic.co/t/auditbeat-and-filebeat-in-same-index/141736>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [July 26, 2018, 10:50am UTC](https://discuss.elastic.co/t/auditbeat-and-filebeat-in-same-index/141736 "2018-07-26T10:50:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Samau4ka](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samau4ka/32/25281_2.png) [@Samau4ka](https://discuss.elastic.co/u/Samau4ka)\
**Post date:** [July 26, 2018, 10:50am UTC](https://discuss.elastic.co/t/auditbeat-and-filebeat-in-same-index/141736/1 "2018-07-26T10:50:26Z")

</div>

I want to send Auditbeat and filebeats logs in same index over Logstash. Filebeat is already successfully sending the data. But i dont know how i get Auditbeat logs in the same index because there is no output\_type tag. I need the output\_type for Logstash.

pls help

thx

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [July 26, 2018, 1:20pm UTC](https://discuss.elastic.co/t/auditbeat-and-filebeat-in-same-index/141736/2 "2018-07-26T13:20:41Z")

</div>

Hello @Samau4ka, Why do you want to send data of metricbeat and filebeat to the same index?

---

<div class="post-metadata">

**Author:** ![Samau4ka](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samau4ka/32/25281_2.png) [@Samau4ka](https://discuss.elastic.co/u/Samau4ka)\
**Post date:** [July 26, 2018, 1:37pm UTC](https://discuss.elastic.co/t/auditbeat-and-filebeat-in-same-index/141736/3 "2018-07-26T13:37:36Z")

</div>

Hi @pierhugues on my setup every server is a index. so i can separate them.

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [July 26, 2018, 2:28pm UTC](https://discuss.elastic.co/t/auditbeat-and-filebeat-in-same-index/141736/4 "2018-07-26T14:28:23Z")

</div>

@Samau4ka I would not recommend having a different index per server, depending on the number of servers and the naming you are using it could generate a lot of shards on Elasticsearch.

If I were you I would keep a time-based index per beats and you can achieve the same thing by filtering on the `beat.host` or 'beat.hostname' field in kibana to get the information for a specific host. You can also add custom fields if you want more granularity. You can check our [doc](https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-beat.html) to see the default fields.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 5:30am UTC](https://discuss.elastic.co/t/auditbeat-and-filebeat-in-same-index/141736/5 "2022-11-04T05:30:24Z")

</div>


