# How do I setup Logstash to segregate logs from multiple servers?

**URL:** <https://discuss.elastic.co/t/how-do-i-setup-logstash-to-segregate-logs-from-multiple-servers/59432>\
**Category:** Logstash\
**Created:** [August 31, 2016, 2:10pm UTC](https://discuss.elastic.co/t/how-do-i-setup-logstash-to-segregate-logs-from-multiple-servers/59432 "2016-08-31T14:10:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ZillaG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zillag/32/10505_2.png) [@ZillaG](https://discuss.elastic.co/u/ZillaG)\
**Post date:** [August 31, 2016, 2:10pm UTC](https://discuss.elastic.co/t/how-do-i-setup-logstash-to-segregate-logs-from-multiple-servers/59432/1 "2016-08-31T14:10:06Z")

</div>

I building a central ELK stack that will be used to aggregate the logs from different customer installations, with each installation having multiple servers. I use rsyslog as the shipper. I wan to be able to "see" the following example structure in my ELK server

```
/path_to_logs/
    - Customer1
    ---- Server1
    ------ app-error.log
    ------ app-system.log
    - Customer2
    ---- Server1
    ------ app-error.log
    ------ app-system.log
    ---- Server2
    ------ app-error.log
    ------ app-system.log

```

I started reading about [rsyslog templates](http://www.rsyslog.com/doc/v8-stable/configuration/templates.html) but am not making the connection yet. For example, how can I embed the "Custoer name" and "Server name" information in the log, and then how can Logstash extract that information?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 31, 2016, 2:42pm UTC](https://discuss.elastic.co/t/how-do-i-setup-logstash-to-segregate-logs-from-multiple-servers/59432/2 "2016-08-31T14:42:07Z")

</div>

If rsyslog knows the customer name it should be easy to include it as (for example) a prefix of each message. Logstash can then extract the customer name along with the hostname, timestamp, and whatever else you've got.

---

<div class="post-metadata">

**Author:** ![ZillaG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zillag/32/10505_2.png) [@ZillaG](https://discuss.elastic.co/u/ZillaG)\
**Post date:** [August 31, 2016, 3:44pm UTC](https://discuss.elastic.co/t/how-do-i-setup-logstash-to-segregate-logs-from-multiple-servers/59432/3 "2016-08-31T15:44:56Z")

</div>

Thanks @magnusbaeck. I guess my question is, how can I make rsyslog (from remote client) "know" the customer name? This is the mechanism I'm missing.

---

<div class="post-metadata">

**Author:** ![ZillaG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zillag/32/10505_2.png) [@ZillaG](https://discuss.elastic.co/u/ZillaG)\
**Post date:** [August 31, 2016, 6:14pm UTC](https://discuss.elastic.co/t/how-do-i-setup-logstash-to-segregate-logs-from-multiple-servers/59432/4 "2016-08-31T18:14:28Z")

</div>

I figured I'll eventually figure this out.

The trick is in the use of rsyslog tempate, where one can store key/value pairs.

So I created an rsyslog list template, and have the following key/pairs, among othes

```
template(name="textLogTemplate" type="list") {
...
  constant(value="\"customer\":\"customer1\", ")
  constant(value="\"role\":\"app-server1\", ")
...
}

```

Then in my Logstash configuration files, I have the following

```
output {
  path => "/var/log/trm/%{customer}/%{role}/trm-system.log"
  codec => line { format => "%message" }
}

```

Which creates a /var/log/trm/customer1/app-server1/trm-system.log file and puts the value of %{message} in it.

Hope someone benefits from this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:40am UTC](https://discuss.elastic.co/t/how-do-i-setup-logstash-to-segregate-logs-from-multiple-servers/59432/5 "2017-07-06T04:40:35Z")

</div>


