# How many indices we can create at a time using logstash.conf?

**URL:** <https://discuss.elastic.co/t/how-many-indices-we-can-create-at-a-time-using-logstash-conf/272059>\
**Category:** Logstash\
**Created:** [May 4, 2021, 10:51am UTC](https://discuss.elastic.co/t/how-many-indices-we-can-create-at-a-time-using-logstash-conf/272059 "2021-05-04T10:51:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Learn\_Mulesoft\_With](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/learn_mulesoft_with/32/87561_2.png) [@Learn\_Mulesoft\_With](https://discuss.elastic.co/u/Learn_Mulesoft_With)\
**Post date:** [May 4, 2021, 10:51am UTC](https://discuss.elastic.co/t/how-many-indices-we-can-create-at-a-time-using-logstash-conf/272059/1 "2021-05-04T10:51:42Z")

</div>

consider my logstash.conf

input{  
http{  
host =\>"localhost"  
port =\>"5044"  
response\_code =\>201  
type =\> "log\_error"  
}  
http{  
host =\>"localhost"  
port =\>"5045"  
response\_code =\>201  
type =\> "log\_message"  
}  
http{  
host =\>"localhost"  
port =\>"5046"  
response\_code =\>201  
type =\> "rsys\_log"  
}  
}

filter{  
if[type] =="rsys\_log" {  
grok{  
match =\> {  
"message" =\> "%{LOGLEVEL:log-level}\s\*%{TIMESTAMP\_ISO8601:logdate} [%{DATA:runtime}] [%{DATA:processor}; %{WORD:d}:%{DATA:correlationID}]%{DATA:class}:%{GREEDYDATA:message}"  
}  
}  
}  
}

output{  
if[type] =="rsyslog" {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "rsyslog20-%{+YYYY.MM.dd}"  
}  
}  
if[type] =="log\_error" {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "log\_error20-%{+YYYY.MM.dd}"  
}  
}  
if[type] =="log\_message" {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "log\_message20-%{+YYYY.MM.dd}"  
}  
}  
}

but in this only one index is being created

any solution to create mutiple indices at once

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 4, 2021, 12:12pm UTC](https://discuss.elastic.co/t/how-many-indices-we-can-create-at-a-time-using-logstash-conf/272059/2 "2021-05-04T12:12:05Z")

</div>

It's a logstash question so I moved it to #Logstash.

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

This is the icon to use if you are not using markdown format:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6e239431ec2d71cbf1beef741f2e93e7cc762c.jpg)

There's a live preview panel for exactly this reasons.

Lots of people read these forums, and many of them will simply skip over a post that is difficult to read, because it's just too large an investment of their time to try and follow a wall of badly formatted text.  
If your goal is to get an answer to your questions, it's in your interest to make it as easy to read and understand as possible.  
Please update your post.

Side note:

```
if[type] =="rsyslog" {

```

Should be I believe

```
if[type] =="rsys_log" {

```

And now to answer your title question:

> How many indices we can create at a time using logstash.conf?

I don't think there's a known limit.

---

<div class="post-metadata">

**Author:** ![Learn\_Mulesoft\_With](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/learn_mulesoft_with/32/87561_2.png) [@Learn\_Mulesoft\_With](https://discuss.elastic.co/u/Learn_Mulesoft_With)\
**Post date:** [May 4, 2021, 1:46pm UTC](https://discuss.elastic.co/t/how-many-indices-we-can-create-at-a-time-using-logstash-conf/272059/3 "2021-05-04T13:46:42Z")

</div>

Hi dadoonet,

when i am running logstash file and giving input to one of input port then only one indice is created. as you can see in my code above . in the output section i have configured 2 indices but in kibana i could see only 1 index.

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [May 4, 2021, 1:50pm UTC](https://discuss.elastic.co/t/how-many-indices-we-can-create-at-a-time-using-logstash-conf/272059/4 "2021-05-04T13:50:22Z")

</div>

Verified that data is flowing through all 3? Can easily just do an STDOUT for each source one at a time and watch the data if it's flowing or not.

Seems like 2 of them might not push data all the time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2021, 1:50pm UTC](https://discuss.elastic.co/t/how-many-indices-we-can-create-at-a-time-using-logstash-conf/272059/5 "2021-06-01T13:50:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
