# Create Multiple Indexes from filebeat

**URL:** <https://discuss.elastic.co/t/create-multiple-indexes-from-filebeat/283163>\
**Category:** Logstash\
**Created:** [September 2, 2021, 12:02pm UTC](https://discuss.elastic.co/t/create-multiple-indexes-from-filebeat/283163 "2021-09-02T12:02:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rahul\_sirugudi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_sirugudi/32/94019_2.png) [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Post date:** [September 2, 2021, 12:02pm UTC](https://discuss.elastic.co/t/create-multiple-indexes-from-filebeat/283163/1 "2021-09-02T12:02:14Z")

</div>

Hi, I am new to ELK stack. I am trying to set up logs for applications. In total we have 29 applications (deb). running in both (autoscaling and spot-fleet in aws). My idea is to use one filebeat configuration on all the 29 applications, but segregate per the application log location and create indexes. Here is my set up on filebeat.

```auto
- type: log
# Change to true to enable this input configuration.
  enabled: true

  paths:
    - /var/log/rahul/*/*/*.log
  fields: {log_type: qa}
  -type: log
  paths:
          - /var/log/rahul/application-1/*/*.log
  fields: {log_type: application-1}

```

Now in the logstash

```auto
input {
  beats {
    port => 5044
    ssl => false
  }
}
filter {}

output {
if [log_type] == "application-1"{
    elasticsearch {
    hosts => ["0.0.0.0:9200"]
   user => "un"
   password => "pwd"
   index => "application-%{+YYYY.MM.dd}"
   }
   stdout { codec => rubydebug }
  }
if [log_type] == "qa"{
elasticsearch {
hosts => ["0.0.0.0:9200"]
   user => "un"
   password => "pwd"
   index => "qa-%{+YYYY.MM.dd}"
   document_type => "qa_logs"
}
stdout { codec => rubydebug }
}
}

```

with this setup i don't see indexes are creating in kibana.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 2, 2021, 1:10pm UTC](https://discuss.elastic.co/t/create-multiple-indexes-from-filebeat/283163/2 "2021-09-02T13:10:47Z")

</div>

Your conditional is wrong, your fields are not being added to the root of the document, but into the top-level field named `fields`.

You should refer to your field as `[fields][log_type]`.

If you want to add them in the root of your document, you need to change your config, check this part of the [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-general-options.html#_fields_under_root).

---

<div class="post-metadata">

**Author:** ![rahul\_sirugudi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_sirugudi/32/94019_2.png) [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Post date:** [September 2, 2021, 1:54pm UTC](https://discuss.elastic.co/t/create-multiple-indexes-from-filebeat/283163/3 "2021-09-02T13:54:57Z")

</div>

Thank you.

```auto
[fields][log_type]

```

this condition is working indexes are created as expected.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 30, 2021, 1:55pm UTC](https://discuss.elastic.co/t/create-multiple-indexes-from-filebeat/283163/4 "2021-09-30T13:55:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
