# How to apply predefined template if log collection is done in a different way

**URL:** <https://discuss.elastic.co/t/how-to-apply-predefined-template-if-log-collection-is-done-in-a-different-way/215434>\
**Category:** Kibana\
**Created:** [January 17, 2020, 9:29am UTC](https://discuss.elastic.co/t/how-to-apply-predefined-template-if-log-collection-is-done-in-a-different-way/215434 "2020-01-17T09:29:42Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![karthiknpy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karthiknpy/32/53587_2.png) [@karthiknpy](https://discuss.elastic.co/u/karthiknpy)\
**Post date:** [January 17, 2020, 9:29am UTC](https://discuss.elastic.co/t/how-to-apply-predefined-template-if-log-collection-is-done-in-a-different-way/215434/1 "2020-01-17T09:29:42Z")

</div>

Hey Fellas,

I need to collect suricata logs from a machine. By default suricata has a template in kibana if logs collected with filebeat and suricata filebeat module is installed, dashboards are created automatically. Stuffs are taken care...!

But

I dont have a provision to collect logs via Filebeat due to a special case.  
All I can afford is sending logs to a logstash syslog input plugin.  
How to apply the suricata default dashboard to interpret the logs collected by suricata automatically to a custom index name.

Regards  
Karthik. K

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [January 17, 2020, 12:31pm UTC](https://discuss.elastic.co/t/how-to-apply-predefined-template-if-log-collection-is-done-in-a-different-way/215434/2 "2020-01-17T12:31:35Z")

</div>

Hi

You have to take care, that logstash transforms the data in the same schema filebeat would, and save it also in the same index. then the dashboard should work

Best,  
Matthias

---

<div class="post-metadata">

**Author:** ![karthiknpy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karthiknpy/32/53587_2.png) [@karthiknpy](https://discuss.elastic.co/u/karthiknpy)\
**Post date:** [January 17, 2020, 3:02pm UTC](https://discuss.elastic.co/t/how-to-apply-predefined-template-if-log-collection-is-done-in-a-different-way/215434/3 "2020-01-17T15:02:53Z")

</div>

Hi matw,

Thanks for the quick response. I have given a thought about it but the situation demands a custom name for the index as I have already specified.

Can you give a thought or a tweak which will make this possible ?

Any guidance is very much appreciated.

Regards  
Karthik.K

---

<div class="post-metadata">

**Author:** ![aravindputrevu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aravindputrevu/32/24816_2.png) [@aravindputrevu](https://discuss.elastic.co/u/aravindputrevu)\
**Post date:** [January 19, 2020, 7:26am UTC](https://discuss.elastic.co/t/how-to-apply-predefined-template-if-log-collection-is-done-in-a-different-way/215434/4 "2020-01-19T07:26:15Z")

</div>

You can write to a different index or create a specific index name. Please refer the Logstash Elasticsearch Output plugin documentation [here](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#_writing_to_different_indices_best_practices)

---

<div class="post-metadata">

**Author:** ![karthiknpy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karthiknpy/32/53587_2.png) [@karthiknpy](https://discuss.elastic.co/u/karthiknpy)\
**Post date:** [January 19, 2020, 4:29pm UTC](https://discuss.elastic.co/t/how-to-apply-predefined-template-if-log-collection-is-done-in-a-different-way/215434/5 "2020-01-19T16:29:35Z")

</div>

Aravind,

I do understand that we can write to different indexes with different names using logstash no doubt in that. My question is if I'm writing to a index with a different name also. How can I used the default suricata dashboard provided by ELK SIEM to read and populate data from that custom named index. I wonder If we can do some tweakings to achieve this.

Thanks  
Karthik. K

---

<div class="post-metadata">

**Author:** ![aravindputrevu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aravindputrevu/32/24816_2.png) [@aravindputrevu](https://discuss.elastic.co/u/aravindputrevu)\
**Post date:** [January 20, 2020, 9:37am UTC](https://discuss.elastic.co/t/how-to-apply-predefined-template-if-log-collection-is-done-in-a-different-way/215434/6 "2020-01-20T09:37:45Z")

</div>

Well, you can create a index pattern to make the dashboard use the data from multiple indexes.  
For ex: if you indexes named "surcata-es" and "surcata-mine", you can create an index pattern with "surcata-\*" in kibana.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 17, 2020, 9:37am UTC](https://discuss.elastic.co/t/how-to-apply-predefined-template-if-log-collection-is-done-in-a-different-way/215434/7 "2020-02-17T09:37:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
