# Configure logstash for dev and prod with different index pattern

**URL:** <https://discuss.elastic.co/t/configure-logstash-for-dev-and-prod-with-different-index-pattern/165853>\
**Category:** Logstash\
**Created:** [January 26, 2019, 4:08pm UTC](https://discuss.elastic.co/t/configure-logstash-for-dev-and-prod-with-different-index-pattern/165853 "2019-01-26T16:08:03Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sundarm](https://avatars.discourse-cdn.com/v4/letter/s/9de0a6/32.png) [@sundarm](https://discuss.elastic.co/u/sundarm)\
**Post date:** [January 26, 2019, 4:08pm UTC](https://discuss.elastic.co/t/configure-logstash-for-dev-and-prod-with-different-index-pattern/165853/1 "2019-01-26T16:08:03Z")

</div>

Hi ,

I am having single logstash server and installed filebeats on dev and prod instances and in my logstash config i am using the following index pattern index =\> "applogs-%{+YYYY.MM.dd}" so now all my dev and prod logs in kibana are listing under the same index pattern applogs. I would like to separate dev and prod index pattern . Can some one help to separate the environment logs .

Thanks,  
sundar

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [January 26, 2019, 4:38pm UTC](https://discuss.elastic.co/t/configure-logstash-for-dev-and-prod-with-different-index-pattern/165853/2 "2019-01-26T16:38:50Z")

</div>

It's a little hard to give exact advice without knowing the shape of yur events and what differentiates your dev events from prod events, but perhaps this will help:

The Elasticsearch Output's `index` directive uses the [Logstash sprintf syntax](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#sprintf), which allows access to individual fields on the event; assuming you had a field called `env` that contained either `"dev"` xor `"prod"`, you could supply the field as follows:

```auto
output {
  elasticsearch {
    # ...
    index => "applogs-%{[env]}-%{+YYYY.MM.dd}"
  }
}

```

---

<div class="post-metadata">

**Author:** ![sundarm](https://avatars.discourse-cdn.com/v4/letter/s/9de0a6/32.png) [@sundarm](https://discuss.elastic.co/u/sundarm)\
**Post date:** [January 26, 2019, 5:16pm UTC](https://discuss.elastic.co/t/configure-logstash-for-dev-and-prod-with-different-index-pattern/165853/3 "2019-01-26T17:16:53Z")

</div>

HI yaauie,

Thanks for your immediate reply. Its really very helpful but could you please tell me where should i mention this env . In my filebeat config and logstash config both ?  
Below is my simple filebeat config

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /var/www/html/var/log/*.log
fields:
      # used in the output section to send each log to its
      # proper index instead of the default 'filebeat-*'
      index_name: applogs
setup.template.enabled: false
output.logstash:
  hosts: ["10.91.96.201:5044"]
  index: "%{[fields.index_name]:logs}-%{+YYYY.MM.dd}"

logging.to_syslog: true
logging.to_files: false

```

In my logstash config output i have configured as below

```auto
index => "applogs-%{+YYYY.MM.dd}"

```

Thanks

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [January 26, 2019, 5:58pm UTC](https://discuss.elastic.co/t/configure-logstash-for-dev-and-prod-with-different-index-pattern/165853/4 "2019-01-26T17:58:21Z")

</div>

In Filebeat, the `fields` directive allows you to add fields; if you find it acceptable to have a different config in dev vs prod, then adding the relevant field in Filebeat may be appropriate.

Otherwise, if you can differentiate dev and prod via the _contents_ of the event messages, then the field can be added in Logstash.

I cannot be any more clear without knowing what differentiates your logs from each other.

---

<div class="post-metadata">

**Author:** ![sundarm](https://avatars.discourse-cdn.com/v4/letter/s/9de0a6/32.png) [@sundarm](https://discuss.elastic.co/u/sundarm)\
**Post date:** [January 29, 2019, 4:14pm UTC](https://discuss.elastic.co/t/configure-logstash-for-dev-and-prod-with-different-index-pattern/165853/5 "2019-01-29T16:14:48Z")

</div>

HI Yaauie,

Now i am not using filebeat. I directly installed logstash on my webserver and trying to send drupal logs to my kibana. Could you please help me to configure logstash filter for drupal logs .

Thanks

---

<div class="post-metadata">

**Author:** ![sundarm](https://avatars.discourse-cdn.com/v4/letter/s/9de0a6/32.png) [@sundarm](https://discuss.elastic.co/u/sundarm)\
**Post date:** [January 30, 2019, 11:31am UTC](https://discuss.elastic.co/t/configure-logstash-for-dev-and-prod-with-different-index-pattern/165853/6 "2019-01-30T11:31:08Z")

</div>

HI,

Now i am not using filebeat. I directly installed logstash on my webserver and trying to send drupal logs to my kibana. Could you please help me to configure logstash filter for drupal logs .

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 27, 2019, 11:40am UTC](https://discuss.elastic.co/t/configure-logstash-for-dev-and-prod-with-different-index-pattern/165853/7 "2019-02-27T11:40:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
