# Filebeat: Select index based on prospector

**URL:** <https://discuss.elastic.co/t/filebeat-select-index-based-on-prospector/93691>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 19, 2017, 5:11am UTC](https://discuss.elastic.co/t/filebeat-select-index-based-on-prospector/93691 "2017-07-19T05:11:09Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 19, 2017, 1:59pm UTC](https://discuss.elastic.co/t/filebeat-select-index-based-on-prospector/93691/2 "2017-07-19T13:59:48Z")

</div>

For simplicity I'd use format strings:

```auto
filebeat.prospectors:
- ...
  fields.class: "nginx"
- ...
  fields.class: "apache"

output.elasticsearch:
  index: '%{[fields.class]-%{+yyyy.MM.dd}'

```

You can use `indices` with when clause. If no when clause matches, the `index` setting will be applied.

Documentation on `when`-clause is available in the 'Conditions' documentation: [https://www.elastic.co/guide/en/beats/filebeat/current/configuration-processors.html#conditions](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-processors.html#conditions)

It's always `when.<condition>:`.

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-select-index-based-on-prospector/93691)._
