# Elactic & Logstash infrastructure for diferent retention requeriment

**URL:** <https://discuss.elastic.co/t/elactic-logstash-infrastructure-for-diferent-retention-requeriment/151966>\
**Category:** Elasticsearch\
**Created:** [October 11, 2018, 5:01am UTC](https://discuss.elastic.co/t/elactic-logstash-infrastructure-for-diferent-retention-requeriment/151966 "2018-10-11T05:01:12Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![cdra](https://avatars.discourse-cdn.com/v4/letter/c/ea666f/32.png) [@cdra](https://discuss.elastic.co/u/cdra)\
**Post date:** [October 11, 2018, 5:01am UTC](https://discuss.elastic.co/t/elactic-logstash-infrastructure-for-diferent-retention-requeriment/151966/1 "2018-10-11T05:01:12Z")

</div>

We have a computer (C1) with elacticsearch and Kibana. Other computer (C2) with logstash installed.  
Network computers send syslog messages to logstash. Logstash send messages to C1.These logs have some información: User access, equipment failures. etc....We keep this information for 6 months.

We need keep some syslog messages (those with facility 4 or 10) during 5 years, so I was thinking deploy extra computer (C3) with elacticsearch and kibana. C2 would send syslog messages (those with facility 4 or 10 facility 4 or 10) to C3 also.

is it a good design? other alternative?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 11, 2018, 5:09am UTC](https://discuss.elastic.co/t/elactic-logstash-infrastructure-for-diferent-retention-requeriment/151966/2 "2018-10-11T05:09:26Z")

</div>

When you use time-based indices, retention is managed by index. You could therefore simply create two separate indices (one per retention period) and have Logstash write events with facility 4 or 10 to the one with longer retention period. When doing this you probably want to adjust the time period each index type covers and e.g. use monthly indices for the index with longer retention period and a daily or weekly index for the other. You can easily do this within a single cluster.

---

<div class="post-metadata">

**Author:** ![cdra](https://avatars.discourse-cdn.com/v4/letter/c/ea666f/32.png) [@cdra](https://discuss.elastic.co/u/cdra)\
**Post date:** [October 11, 2018, 5:42am UTC](https://discuss.elastic.co/t/elactic-logstash-infrastructure-for-diferent-retention-requeriment/151966/3 "2018-10-11T05:42:33Z")

</div>

My logstash config file is like:

if [type] == "syslog"  
{  
elasticsearch  
{  
hosts =\> ["xxxxxxxx:9200"]  
}  
}

So, it uses default index template....(example....logstash-2018.06.11)

How could create others logstash indexes for syslog with facility 4 or 10 using default logstash template ??

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 11, 2018, 5:55am UTC](https://discuss.elastic.co/t/elactic-logstash-infrastructure-for-diferent-retention-requeriment/151966/4 "2018-10-11T05:55:56Z")

</div>

Once you have parsed out the facility from the log message, create two separate Elasticsearch outputs and use [conditionals](https://www.elastic.co/guide/en/logstash/6.4/event-dependent-configuration.html#conditionals) to send events to the correct plugin based on the facility value.

---

<div class="post-metadata">

**Author:** ![cdra](https://avatars.discourse-cdn.com/v4/letter/c/ea666f/32.png) [@cdra](https://discuss.elastic.co/u/cdra)\
**Post date:** [October 11, 2018, 6:05am UTC](https://discuss.elastic.co/t/elactic-logstash-infrastructure-for-diferent-retention-requeriment/151966/5 "2018-10-11T06:05:31Z")

</div>

I know create different outputs using conditionals...but i suppose that I must configure "index =\> " parameter...not ??? how should I configure it for créate index by week ??

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 11, 2018, 6:11am UTC](https://discuss.elastic.co/t/elactic-logstash-infrastructure-for-diferent-retention-requeriment/151966/6 "2018-10-11T06:11:04Z")

</div>

Yes, you need to specify two different index names for short and longer retention, e.g. `logstash-short-%{+YYYY.MM.dd}` and `logstash-long-%{+YYYY.MM}`.

---

<div class="post-metadata">

**Author:** ![cdra](https://avatars.discourse-cdn.com/v4/letter/c/ea666f/32.png) [@cdra](https://discuss.elastic.co/u/cdra)\
**Post date:** [October 11, 2018, 6:21am UTC](https://discuss.elastic.co/t/elactic-logstash-infrastructure-for-diferent-retention-requeriment/151966/7 "2018-10-11T06:21:03Z")

</div>

My logstash template is like:

"logstash":  
{  
"order": 0,  
"index\_patterns": ["logstash-\*"],  
"settings": {"index": {  
"number\_of\_shards": "1"  
}

I suppose that is créate a new index like "logstash-long-%{+YYYY.MM}" it will use that template because index is like "logstash-\*", not ???

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 8, 2018, 6:35am UTC](https://discuss.elastic.co/t/elactic-logstash-infrastructure-for-diferent-retention-requeriment/151966/8 "2018-11-08T06:35:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
