# Extract specific log set from others indexed togheter

**URL:** <https://discuss.elastic.co/t/extract-specific-log-set-from-others-indexed-togheter/341262>\
**Category:** Elasticsearch\
**Created:** [August 21, 2023, 2:12pm UTC](https://discuss.elastic.co/t/extract-specific-log-set-from-others-indexed-togheter/341262 "2023-08-21T14:12:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![necromancer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/necromancer/32/125541_2.png) [@necromancer](https://discuss.elastic.co/u/necromancer)\
**Post date:** [August 21, 2023, 2:12pm UTC](https://discuss.elastic.co/t/extract-specific-log-set-from-others-indexed-togheter/341262/1 "2023-08-21T14:12:27Z")

</div>

I want to know ihow can I extract/separate my nginx logs from an index where they are saved along with systemd logs and others (cron, fail2ban, etc)?  
I have it indexed with the ident "nginx".  
My point with it is be able to backup only the nginx logs, not all other logs.  
I tryed with \_reindex, but I don't understand well how to do it or even if it is posible. I also read about elasticsearch and kibana been squema on write, what means that if I want to change it I need rebuild all my environment.

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [September 5, 2023, 4:33pm UTC](https://discuss.elastic.co/t/extract-specific-log-set-from-others-indexed-togheter/341262/2 "2023-09-05T16:33:44Z")

</div>

Hi @necromancer (nice username), welcome to our community 👋

For new documents you may want to look at the `reroute` processor that you can put in an ingest pipeline. Funny fact, the examples in the docs are exactly your use case 😄

> **[Reroute processor | Elasticsearch Guide \[8.9\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/reroute-processor.html)**

For existing documents you can "copy" your documents to a new index using `_reindex` and a query, check this example from the docs

> **[Reindex API | Elasticsearch Guide \[8.9\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html#docs-reindex-select-query)**

Be sure to first create your new index with the appropriate mappings and settings.

(moving this thread to the Elasticsearch forum since there's nothing specific about Kibana here)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 3, 2023, 4:34pm UTC](https://discuss.elastic.co/t/extract-specific-log-set-from-others-indexed-togheter/341262/3 "2023-10-03T16:34:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
