# Handling different flows in data streams

**URL:** <https://discuss.elastic.co/t/handling-different-flows-in-data-streams/365342>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management, datastreams\
**Created:** [August 22, 2024, 7:30am UTC](https://discuss.elastic.co/t/handling-different-flows-in-data-streams/365342 "2024-08-22T07:30:39Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zain\_Ul\_Abideen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zain_ul_abideen/32/131962_2.png) [@Zain\_Ul\_Abideen](https://discuss.elastic.co/u/Zain_Ul_Abideen)\
**Post date:** [August 22, 2024, 7:30am UTC](https://discuss.elastic.co/t/handling-different-flows-in-data-streams/365342/1 "2024-08-22T07:30:39Z")

</div>

Hello,

I have been using data streams for my business flow logs, each flow has the different log structure. I have couple of solutions in mind:

1. Having same structure for each flow and keep stringified version of log object in particular key. For example:

```auto
{
                tag: '--ELK--',
                function: '<function name>',
                options: <stringified object>
}

```

this will inefficient in searching

1. Having same structure for each flow and keep nested object of log object in particular key. For example:

```auto
{
                tag: '--ELK--',
                function: '<function name>',
                options: <JSON object>
}

```

this will add complexity in writing in the indices as lucene index does not have nested object support.

1. Is there a way to control the index creation in the data stream in such a way that index could be created as per flow for example: if I have login, signup, and logout flows, in my `logs-datastream` if I could create different index in the data stream for each flow so that each index would have it's own structure.

Kindly suggest. TIA

---

<div class="post-metadata">

**Author:** ![arm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arm/32/136968_2.png) [@arm](https://discuss.elastic.co/u/arm)\
**Post date:** [August 22, 2024, 7:36am UTC](https://discuss.elastic.co/t/handling-different-flows-in-data-streams/365342/2 "2024-08-22T07:36:13Z")

</div>

Another thing I can add over here is parsing the data as fields and values,

```auto
{
   "key": "property_name",
   "value": "property_value"
}

```
