# Create different Indices for different filebeat folder location

**URL:** <https://discuss.elastic.co/t/create-different-indices-for-different-filebeat-folder-location/132478>\
**Category:** Logstash\
**Created:** [May 18, 2018, 11:31am UTC](https://discuss.elastic.co/t/create-different-indices-for-different-filebeat-folder-location/132478 "2018-05-18T11:31:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![SumitV](https://avatars.discourse-cdn.com/v4/letter/s/67e7ee/32.png) [@SumitV](https://discuss.elastic.co/u/SumitV)\
**Post date:** [May 18, 2018, 11:31am UTC](https://discuss.elastic.co/t/create-different-indices-for-different-filebeat-folder-location/132478/1 "2018-05-18T11:31:46Z")

</div>

Hi There,  
I have different application logs sitting in different folders, for instance  
../ABC/_.logs  
../XYZ/_.logs

In this case filebeat should take generate events for multiple location and according to these location my indexes should be created in elasticsearch.

So for above scenario elasticsearch should have two indexes with name "abc" and "xyz".

What configuration shall we have and where?

My conf file currently has below details.

input {  
beats {  
port =\> "5044"  
}  
}  
filter {  
grok{  
match =\> {"message" =\> "%{TIMESTAMP\_ISO8601:timestamp} [%{NUMBER:number}] %{LOGLEVEL:loglevel} %{DATA:file} - (?(.|\r|\n)_)"}  
}  
date {  
match =\> ["timestamp", "YYYY-MM-dd HH:mm:ss,SSS"]  
}  
}  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
user =\> "elastic"  
password =\> "_&_^_&%"  
index =\> "abc"  
}  
}

Thanks,  
Sumit

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 20, 2018, 9:08am UTC](https://discuss.elastic.co/t/create-different-indices-for-different-filebeat-folder-location/132478/2 "2018-05-20T09:08:31Z")

</div>

You will need to parse the [`source` path](https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-log.html) and then use that in the output section.

---

<div class="post-metadata">

**Author:** ![SumitV](https://avatars.discourse-cdn.com/v4/letter/s/67e7ee/32.png) [@SumitV](https://discuss.elastic.co/u/SumitV)\
**Post date:** [May 21, 2018, 10:55am UTC](https://discuss.elastic.co/t/create-different-indices-for-different-filebeat-folder-location/132478/3 "2018-05-21T10:55:09Z")

</div>

Thanks Mark. Can you provide some example, i am not able to understand how we need to set the two paths.  
I guess, you are asking to change filebeat.yml file. Do you want me to add another path in paths section? If yes, then how logstash will identify for 2nd path which new indexes needs to create?

Thanks,  
Sumit.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 18, 2018, 11:07am UTC](https://discuss.elastic.co/t/create-different-indices-for-different-filebeat-folder-location/132478/4 "2018-06-18T11:07:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
