# Different index for different logs

**URL:** <https://discuss.elastic.co/t/different-index-for-different-logs/215317>\
**Category:** Logstash\
**Created:** [January 16, 2020, 1:33pm UTC](https://discuss.elastic.co/t/different-index-for-different-logs/215317 "2020-01-16T13:33:51Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![srisum0728](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@srisum0728](https://discuss.elastic.co/u/srisum0728)\
**Post date:** [January 16, 2020, 1:33pm UTC](https://discuss.elastic.co/t/different-index-for-different-logs/215317/1 "2020-01-16T13:33:52Z")

</div>

Need different index for each log file path.  
1\> access log in access.conf file -\> same server  
2\> csv file in task\_engine.csv -\> same server

Need to have task\_engine.csv file in different index so that I can pull it in machine learning .

Issue: I am not getting task\_engine.csv file at all, when I start manually it works but I am seeing acecess logs as well in the same index. I need it to work without manual start, more over need to have task\_engine.csv in different index so I can use it in machine learning.

OS: RHEL 7  
Logstash version: logstash-6.7.1-1.noarch

=====================================================================

# pwd

/etc/logstash/conf.d  
#cat access.conf  
input {  
file {  
path =\> "/var/log/access\_log"  
path =\> "/var/log/access\_log\*\*122019"  
start\_position =\> "beginning"  
}  
}

filter {  
if [path] =~ "access" {  
mutate { replace =\> { "type" =\> "apache\_access" } }  
mutate { remove\_field =\> ["tags", "type", "\_type", "\_score"] }  
grok {  
match =\> ["message", "%{IP:client\_ip} %{USER:ident} %{USER:auth} [%{HTTPDATE:apache\_timestamp}] "%{WORD:method} /%{NOTSPACE:request\_page} HTTP/%{NUMBER:http\_version}" %{NUMBER:server\_response} (?:%{NUMBER:bytes}|-)" ]  
}  
}  
date {  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
}  
geoip {  
source =\> "clientip"  
}  
}

# output { elasticsearch { hosts =\> ["Same\_IP:9200"] index =\> "logstash-prod-accesslog-%{+YYYY.MM.dd}" } stdout { codec =\> rubydebug } }

# pwd

/etc/logstash/conf.d

# cat tasks\_engine.conf

input {  
file {  
path =\> "/var/log/task\_engine.csv"  
start\_position =\> "beginning"  
tags =\> ["task"]  
}  
}

filter {  
csv {  
separator =\> ";"  
columns =\> ["process\_id" , "task\_id" , "status" , "created\_iso" , "created" , "week" , "year" , "updated\_iso" , "user" , "project" , "region" , "process" , "hostname" , "error\_message" , "extended\_task\_name"]  
}  
}

# output { elasticsearch { hosts =\> ["Same\_IP:9200"] index =\> "logstash-task-%{+YYYY.MM.dd}" } stdout { codec =\> rubydebug } }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 13, 2020, 1:33pm UTC](https://discuss.elastic.co/t/different-index-for-different-logs/215317/2 "2020-02-13T13:33:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
