# How to configure ELK (Elasticsearch, Logstash,Kibana) for different application log files and display each application separately in Kibana?

**URL:** <https://discuss.elastic.co/t/how-to-configure-elk-elasticsearch-logstash-kibana-for-different-application-log-files-and-display-each-application-separately-in-kibana/70411>\
**Category:** Logstash\
**Created:** [January 3, 2017, 9:33am UTC](https://discuss.elastic.co/t/how-to-configure-elk-elasticsearch-logstash-kibana-for-different-application-log-files-and-display-each-application-separately-in-kibana/70411 "2017-01-03T09:33:50Z")\
**Posts on this page:** 1\
**Showing post:** 12

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 4, 2017, 1:11pm UTC](https://discuss.elastic.co/t/how-to-configure-elk-elasticsearch-logstash-kibana-for-different-application-log-files-and-display-each-application-separately-in-kibana/70411/12 "2017-01-04T13:11:22Z")

</div>

> is this my else condition which cause logstash-\* index ?

It sounds like you effectively have this:

```plaintext
output {
  if [type] == "OnsuranceAppLog" {
    elasticsearch { 
      hosts => ["localhost:9200"] 
      index => "onsurance-%{+YYYY.MM.dd}"
    }
  } else {
    elasticsearch {
      hosts => ["localhost:9200"]
    }
    stdout { codec => rubydebug }
  }
  if [type] == "iis" {
    elasticsearch { 
      hosts => ["localhost:9200"] 
      index => "iis-%{+YYYY.MM.dd}"
    }
  } else {
    elasticsearch {
      hosts => ["localhost:9200"]
    }
    stdout { codec => rubydebug }
  }
}

```

In that case yes, the else block is the problem. All messages will reach it.

> another question is, how can i tell ES to keep index of only last 30 days? and delete everything which is older than 30 days. I know you can fire a query to ES but is there any Setting which i can set once and it does the magic?

There's no setting but the Curator program can do this for you.

---

_[View the full topic](https://discuss.elastic.co/t/how-to-configure-elk-elasticsearch-logstash-kibana-for-different-application-log-files-and-display-each-application-separately-in-kibana/70411)._
