# Change index per pipeline

**URL:** <https://discuss.elastic.co/t/change-index-per-pipeline/144901>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 17, 2018, 12:46pm UTC](https://discuss.elastic.co/t/change-index-per-pipeline/144901 "2018-08-17T12:46:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Josiah\_Raiche](https://avatars.discourse-cdn.com/v4/letter/j/51bf81/32.png) [@Josiah\_Raiche](https://discuss.elastic.co/u/Josiah_Raiche)\
**Post date:** [August 17, 2018, 12:46pm UTC](https://discuss.elastic.co/t/change-index-per-pipeline/144901/1 "2018-08-17T12:46:36Z")

</div>

I'm very new to elasticsearch, so I may be approaching this problem incorrectly.

I've got a couple logs with different log formats. It's pretty easy to create a pipeline with a grok pattern for each, but I'd like to send each log type to a different index.

I assume this is a common pattern. How do other folks handle this?

Ideally I'd like to do this with just filebeat and elasticsearch.

---

<div class="post-metadata">

**Author:** ![Josiah\_Raiche](https://avatars.discourse-cdn.com/v4/letter/j/51bf81/32.png) [@Josiah\_Raiche](https://discuss.elastic.co/u/Josiah_Raiche)\
**Post date:** [August 17, 2018, 2:02pm UTC](https://discuss.elastic.co/t/change-index-per-pipeline/144901/2 "2018-08-17T14:02:00Z")

</div>

Nevermind, I found the answer. I had to use `inputs` instead of the `module` in my filebeat.yml file. Final relevant extracts:

```auto
filebeat.inputs:
- type: log
  paths: 
  - "C:/tester.log"
  fields:
    type: "applog" 
  # VERY IMPORTANT: don't set fields_under_root. Obvious now, not at the time...

setup.template:
  name: "%{[fields.type]:filebeat}-%{[beat.version]}"
  pattern: "%{[fields.type]:filebeat}-%{[beat.version]}-*"

[...]

output.elasticsearch:
  # Array of hosts to connect to.
  hosts: ["http://server:9200"]
  index: "filebeat-%{[beat.version]}-%{+yyyy.MM.dd}"
  indices: 
    - index: "applog-%{[beat.version]}-%{+yyyy.MM.dd}"
      when.equals:
        fields.type: "applog"
        
  pipelines:
    - pipeline: "filebeat-6.3.2-applog-log-default"
      when.equals:
        fields.type: "applog"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2018, 2:02pm UTC](https://discuss.elastic.co/t/change-index-per-pipeline/144901/3 "2018-09-14T14:02:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
