# Filebeat different logfiles to different backends

**URL:** <https://discuss.elastic.co/t/filebeat-different-logfiles-to-different-backends/114533>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 8, 2018, 1:57pm UTC](https://discuss.elastic.co/t/filebeat-different-logfiles-to-different-backends/114533 "2018-01-08T13:57:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![zozo6015](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zozo6015/32/12117_2.png) [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Post date:** [January 8, 2018, 1:57pm UTC](https://discuss.elastic.co/t/filebeat-different-logfiles-to-different-backends/114533/1 "2018-01-08T13:57:12Z")

</div>

Hello,

I am trying to use filebeat and send differnet log types but they need to end up in different indexes. My idea was to create different rules on logstash by listning on different ports and have them send every log type to a different port and I am not sure if that is possible.

Any idea?

Regards,

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 9, 2018, 12:42pm UTC](https://discuss.elastic.co/t/filebeat-different-logfiles-to-different-backends/114533/2 "2018-01-09T12:42:27Z")

</div>

You do any processing in Logstash? If not, you can configure the index to be based on the event when pushing to Elasticsearch.

Using the `fields` setting in the prospectors, you can add custom fields (e.g. `fields.service: service1`) define the index name based on the custom field.

---

<div class="post-metadata">

**Author:** ![zozo6015](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zozo6015/32/12117_2.png) [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Post date:** [January 9, 2018, 12:57pm UTC](https://discuss.elastic.co/t/filebeat-different-logfiles-to-different-backends/114533/3 "2018-01-09T12:57:06Z")

</div>

Yes, I am using logstash, and the application needs to have it's own indices while the other logs can be put together. That is why I was thinking to send diffferent indices to different logstash backend. If this is not possible via regular filebeat config I might end up cloning the filebeat service and run a different filebeat with different configurations.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 9, 2018, 3:03pm UTC](https://discuss.elastic.co/t/filebeat-different-logfiles-to-different-backends/114533/4 "2018-01-09T15:03:39Z")

</div>

You can use fields or tags in filebeat prospectors:

```auto
filebeat.prospectors:
- ...
  fields_under_root: true
  fields:
    service: a
  tags: [...]
- ...
  fields_under_root: true
  fields:
    service: b
  tags: [...]

```

Using these settings in filebeat, you can access the `service` field in Logstash like any other event field via `[service]`. Using tags you can filter in Logstash with `if "mytag" in [tags] ...`.

E.g. you can construct the index name using service in LS like: `index => "%{[service]}-%{+yyyy.MM.dd}"`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2018, 3:03pm UTC](https://discuss.elastic.co/t/filebeat-different-logfiles-to-different-backends/114533/5 "2018-02-06T15:03:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
