# Elasticsearch as Logstash output

**URL:** <https://discuss.elastic.co/t/elasticsearch-as-logstash-output/172256>\
**Category:** Logstash\
**Created:** [March 14, 2019, 6:40am UTC](https://discuss.elastic.co/t/elasticsearch-as-logstash-output/172256 "2019-03-14T06:40:59Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dv\_Thiyanesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dv_thiyanesh/32/53965_2.png) [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Post date:** [March 14, 2019, 6:40am UTC](https://discuss.elastic.co/t/elasticsearch-as-logstash-output/172256/1 "2019-03-14T06:40:59Z")

</div>

Instead of having winlogbeat produces daily index, we can create separate index for separate winlogbeat clientlogs? Or any other idea?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 14, 2019, 6:44am UTC](https://discuss.elastic.co/t/elasticsearch-as-logstash-output/172256/2 "2019-03-14T06:44:23Z")

</div>

Creating lots of small indices and shards is inefficient, wastes resources and will cause performance problems down the line. Why do you want to do this?

> **[How many shards should I have in my Elasticsearch cluster?
	  	 | Elastic](https://www.elastic.co/blog/how-many-shards-should-i-have-in-my-elasticsearch-cluster)**
>
> Elasticsearch is a very versatile platform, that supports a variety of use cases, and provides great flexibility around data organisation and replication strategies. This flexibility can however somet...

---

<div class="post-metadata">

**Author:** ![Dv\_Thiyanesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dv_thiyanesh/32/53965_2.png) [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Post date:** [March 14, 2019, 6:58am UTC](https://discuss.elastic.co/t/elasticsearch-as-logstash-output/172256/3 "2019-03-14T06:58:01Z")

</div>

The reason is,  
we have 33 clients and one server we using winlogbeat to ship log from the client and send it to logstash and then to elasticsearch  
so we want to create 33 separate index for 33 client(logs) to store  
Then we need to SEARCH specific client machine logs means easy for the user know that's why we are recommended to do this?  
any idea?

---

<div class="post-metadata">

**Author:** ![Dv\_Thiyanesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dv_thiyanesh/32/53965_2.png) [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Post date:** [March 14, 2019, 6:58am UTC](https://discuss.elastic.co/t/elasticsearch-as-logstash-output/172256/4 "2019-03-14T06:58:41Z")

</div>

We are using java High client Api to fetch data

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 14, 2019, 7:01am UTC](https://discuss.elastic.co/t/elasticsearch-as-logstash-output/172256/5 "2019-03-14T07:01:09Z")

</div>

I would recommend storing the data in a single index together with a tag identifying the user and then add a filter when you query. If you need separate indices, make sure you reduce the number of primary shards to 1 and switch to e.g. monthly or weekly indices instead of daily (depending on your retention period).

---

<div class="post-metadata">

**Author:** ![Dv\_Thiyanesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dv_thiyanesh/32/53965_2.png) [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Post date:** [March 14, 2019, 7:07am UTC](https://discuss.elastic.co/t/elasticsearch-as-logstash-output/172256/6 "2019-03-14T07:07:17Z")

</div>

Now i had a Question with your idea  
You said that 'tag identifying the user' what does it mean? can you expalin?  
How to change creating daily indices to monthly or weekly?

---

<div class="post-metadata">

**Author:** ![Dv\_Thiyanesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dv_thiyanesh/32/53965_2.png) [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Post date:** [March 14, 2019, 7:14am UTC](https://discuss.elastic.co/t/elasticsearch-as-logstash-output/172256/7 "2019-03-14T07:14:12Z")

</div>

We store in a single index the index have all the 33 client logs with the index named with winlogbeat-version-date if it's create daily indices

Then where to tag?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 14, 2019, 7:23am UTC](https://discuss.elastic.co/t/elasticsearch-as-logstash-output/172256/8 "2019-03-14T07:23:24Z")

</div>

Add a field to each document that indicates the client. You should be able to to this in Logstash or through an ingest pipeline.

---

<div class="post-metadata">

**Author:** ![Dv\_Thiyanesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dv_thiyanesh/32/53965_2.png) [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Post date:** [March 14, 2019, 7:27am UTC](https://discuss.elastic.co/t/elasticsearch-as-logstash-output/172256/9 "2019-03-14T07:27:50Z")

</div>

You are saying that to create extra fields in the logfile from the client

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 14, 2019, 7:28am UTC](https://discuss.elastic.co/t/elasticsearch-as-logstash-output/172256/10 "2019-03-14T07:28:28Z")

</div>

Yes.

---

<div class="post-metadata">

**Author:** ![Dv\_Thiyanesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dv_thiyanesh/32/53965_2.png) [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Post date:** [March 14, 2019, 7:28am UTC](https://discuss.elastic.co/t/elasticsearch-as-logstash-output/172256/11 "2019-03-14T07:28:35Z")

</div>

> [@Dv\_Thiyanesh](#):
>
> How to change creating daily indices to monthly or weekly?

How to do?

---

<div class="post-metadata">

**Author:** ![Dv\_Thiyanesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dv_thiyanesh/32/53965_2.png) [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Post date:** [March 14, 2019, 7:36am UTC](https://discuss.elastic.co/t/elasticsearch-as-logstash-output/172256/12 "2019-03-14T07:36:46Z")

</div>

> [@Dv\_Thiyanesh](#):
>
> we can create separate index for separate winlogbeat clientlogs

I need to know this is possible or not? to create separate index for separate machine(to clarify doubt)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 14, 2019, 1:06pm UTC](https://discuss.elastic.co/t/elasticsearch-as-logstash-output/172256/13 "2019-03-14T13:06:35Z")

</div>

By default, an elasticsearch output will use daily indices. The default value for the index option is "logstash-%{+YYYY.MM.dd}". You could change that to monthly using

```
index => "logstash-%{+YYYY.MM}"
```

---

<div class="post-metadata">

**Author:** ![Dv\_Thiyanesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dv_thiyanesh/32/53965_2.png) [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Post date:** [March 14, 2019, 5:26pm UTC](https://discuss.elastic.co/t/elasticsearch-as-logstash-output/172256/14 "2019-03-14T17:26:14Z")

</div>

Okay

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 11, 2019, 5:26pm UTC](https://discuss.elastic.co/t/elasticsearch-as-logstash-output/172256/15 "2019-04-11T17:26:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
