# Does multiple indices in output work?

**URL:** <https://discuss.elastic.co/t/does-multiple-indices-in-output-work/35009>\
**Category:** Logstash\
**Created:** [November 19, 2015, 1:39am UTC](https://discuss.elastic.co/t/does-multiple-indices-in-output-work/35009 "2015-11-19T01:39:38Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![davidweir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidweir/32/9678_2.png) [@davidweir](https://discuss.elastic.co/u/davidweir)\
**Post date:** [November 19, 2015, 1:39am UTC](https://discuss.elastic.co/t/does-multiple-indices-in-output-work/35009/1 "2015-11-19T01:39:39Z")

</div>

Continuing the discussion from [Multiple Elasticsearch Indices in Logstash output](https://discuss.elastic.co/t/multiple-elasticsearch-indices-in-logstash-output/26607/11):

> [@Multiple Elasticsearch Indices in Logstash output](https://discuss.elastic.co/t/multiple-elasticsearch-indices-in-logstash-output/26607/11):
>
> Please show the configuration you're using. Also, please prove that the `IndexType` field is getting the correct value, e.g. by using the stdout output to dump the contents of a message at the end of the pipeline.

Running logstash 1.5.4, elasticsearch 1.4.5 and kibana 4.1.2  
Ive set up this output configuration for logstash but I'm not seeing the different indices being created. Am I missing something?  
output{  
if [source] =~ "_-dev" {  
elasticsearch {  
host =\> "localhost"  
index =\> "dev-%{\_type}-%{+YYYY.MM.dd}"  
}  
} else if [source] =~ "_-staging" {  
elasticsearch {  
host =\> "localhost"  
index =\> "staging-%{\_type}-%{+YYYY.MM.dd}"  
}  
} else if [source] =~ "\*-prod" {  
elasticsearch {  
host =\> "localhost"  
index =\> "prod-%{\_type}-%{+YYYY.MM.dd}"  
}  
} else {  
elasticsearch {  
host =\> "localhost"  
}  
}  
}

All my records have the "source" field. but i only see them in the "logstash-_" index. What's going wrong?  
The reason for doing this is I have one field which I'd like to visualize in kibana but while it's available in the logstash-_ index, kibana's discover tab always says "this field is not indexed thus unavailable for visualization and search". Most of my log entries dont include my desired field, so I thought if I split up the logs in this way, the field I'm interested wouldn't be swamped by non-existent entries.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:22am UTC](https://discuss.elastic.co/t/does-multiple-indices-in-output-work/35009/2 "2017-07-06T05:22:16Z")

</div>


