# Elasticsearch: Project hierarchy

**URL:** <https://discuss.elastic.co/t/elasticsearch-project-hierarchy/307506>\
**Category:** Kibana\
**Created:** [June 17, 2022, 11:46am UTC](https://discuss.elastic.co/t/elasticsearch-project-hierarchy/307506 "2022-06-17T11:46:50Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![zain.jutt](https://avatars.discourse-cdn.com/v4/letter/z/49beb7/32.png) [@zain.jutt](https://discuss.elastic.co/u/zain.jutt)\
**Post date:** [June 17, 2022, 11:46am UTC](https://discuss.elastic.co/t/elasticsearch-project-hierarchy/307506/1 "2022-06-17T11:46:50Z")

</div>

Hi, I am new to ElK stack. i am using it to centralize logs for the test runs.  
I have a suite of 50 test cases which runs on the nightly basis and generate some tests and system-side data. I want to store this data into Elasticsearch for that I am already using filebeat and logstash. My question is What would be the approach here do i need to create a separate index for each test and push data into it or how will this work?

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [June 17, 2022, 2:03pm UTC](https://discuss.elastic.co/t/elasticsearch-project-hierarchy/307506/2 "2022-06-17T14:03:09Z")

</div>

You don't need a separate index for this, a simple approach would be to index the filename, then you can simply filter on it on the dashboard

---

<div class="post-metadata">

**Author:** ![zain.jutt](https://avatars.discourse-cdn.com/v4/letter/z/49beb7/32.png) [@zain.jutt](https://discuss.elastic.co/u/zain.jutt)\
**Post date:** [June 17, 2022, 2:22pm UTC](https://discuss.elastic.co/t/elasticsearch-project-hierarchy/307506/3 "2022-06-17T14:22:12Z")

</div>

Thanks, @flash1293 for the reply.  
Actually, for one test I have 3 different log files which include mobile logs, system logs and some debug logs. so as you mentioned if I create one index for all 50 tests and push data into it then I am wondering index will contain thousands of documtes (How many documents an index can contain) and will it be easy to query that big index?  
Sorry for the very basic questions.

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [June 17, 2022, 3:59pm UTC](https://discuss.elastic.co/t/elasticsearch-project-hierarchy/307506/4 "2022-06-17T15:59:35Z")

</div>

Thousands of documents is not an issue at all, Elasticsearch can handle many millions of documents in a single index.

A common approach is it to split indices by time (e.g. one per month) and delete the old ones after a while (this can also be automated).

In Kibana you can define a single data view sourcing documents from multiple indices using a wildcard index name pattern.

---

<div class="post-metadata">

**Author:** ![zain.jutt](https://avatars.discourse-cdn.com/v4/letter/z/49beb7/32.png) [@zain.jutt](https://discuss.elastic.co/u/zain.jutt)\
**Post date:** [June 21, 2022, 1:20pm UTC](https://discuss.elastic.co/t/elasticsearch-project-hierarchy/307506/5 "2022-06-21T13:20:32Z")

</div>

Thank you for the support 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 19, 2022, 1:20pm UTC](https://discuss.elastic.co/t/elasticsearch-project-hierarchy/307506/6 "2022-07-19T13:20:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
