# Different types of json logs to different ES indices without using Logstash

**URL:** <https://discuss.elastic.co/t/different-types-of-json-logs-to-different-es-indices-without-using-logstash/149332>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 20, 2018, 5:22pm UTC](https://discuss.elastic.co/t/different-types-of-json-logs-to-different-es-indices-without-using-logstash/149332 "2018-09-20T17:22:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![soumen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/soumen/32/35729_2.png) [@soumen](https://discuss.elastic.co/u/soumen)\
**Post date:** [September 20, 2018, 5:22pm UTC](https://discuss.elastic.co/t/different-types-of-json-logs-to-different-es-indices-without-using-logstash/149332/1 "2018-09-20T17:22:54Z")

</div>

Hi,

I have two different types of json logs (with different fields) which I need to send to two different ES indices. I want to avoid having to setup Logstash just to do this via conditional processing or having to install separate instances of Filebeat. Is this possible with version 6.x?

I have looked at these previous questions: [Multiple elasticsearch output configuration](https://discuss.elastic.co/t/multiple-elasticsearch-output-configuration/55698) and [Output different prospectors' logs to different Elasticsearch indices?](https://discuss.elastic.co/t/output-different-prospectors-logs-to-different-elasticsearch-indices/47444) - just checking if things have improved since then.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [September 25, 2018, 5:55am UTC](https://discuss.elastic.co/t/different-types-of-json-logs-to-different-es-indices-without-using-logstash/149332/2 "2018-09-25T05:55:37Z")

</div>

I wonder if `indices` config option is the feature you are looking for? [https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html#\_literal\_indices\_literal](https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html#_literal_indices_literal)

---

<div class="post-metadata">

**Author:** ![soumen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/soumen/32/35729_2.png) [@soumen](https://discuss.elastic.co/u/soumen)\
**Post date:** [September 25, 2018, 8:45am UTC](https://discuss.elastic.co/t/different-types-of-json-logs-to-different-es-indices-without-using-logstash/149332/3 "2018-09-25T08:45:47Z")

</div>

I did check that link before and I thought it was exactly what I was after. However, the key point here is that the fields of the two logs is entirely different and this link gives me the impression that the input structure is same; it just creates separate indices based on separate criteria - sort of like creating separate tables based on separate "where" clauses but the fields are same.

Please correct me if my impression is wrong.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 23, 2018, 8:45am UTC](https://discuss.elastic.co/t/different-types-of-json-logs-to-different-es-indices-without-using-logstash/149332/4 "2018-10-23T08:45:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
