# How to configure multiple indexes inside filebeat for one log type?

**URL:** <https://discuss.elastic.co/t/how-to-configure-multiple-indexes-inside-filebeat-for-one-log-type/203943>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 16, 2019, 10:58pm UTC](https://discuss.elastic.co/t/how-to-configure-multiple-indexes-inside-filebeat-for-one-log-type/203943 "2019-10-16T22:58:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hung\_M\_Le](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hung_m_le/32/54995_2.png) [@Hung\_M\_Le](https://discuss.elastic.co/u/Hung_M_Le)\
**Post date:** [October 16, 2019, 10:58pm UTC](https://discuss.elastic.co/t/how-to-configure-multiple-indexes-inside-filebeat-for-one-log-type/203943/1 "2019-10-16T22:58:28Z")

</div>

Hi

I am trying to configure the filebeat to output to Elasticsearch cloud using the following index templates definition inside filebeat.yml. The issue that I encountered is that I do not see the new indexe template (tasdk-warning-\* and tasdk-info-_) inside the "Index Management" section. I can see only one index template (tasdklog-_) and I can create a custom index out of this index template.

I would like to find out what else that I need to configure inside the filebeat.yml to have more than 1 index. I follow the example from the following link:

[https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html](https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html)

extract from filebeat.yml:

#==================== Elasticsearch template setting ==========================  
setup.template.enabled: true  
setup.template.name: "tasdklog"  
#setup.template.fields: "tasdkfields.yml"  
setup.template.pattern: "tasdklog-\*"  
setup.template.overwrite: true  
#setup.ilm.enabled: false  
setup.ilm.enabled: true

setup.ilm.rollover\_alias: "tasdklog"  
setup.ilm.pattern: "{now/d{MM.dd.yyyy|America/New\_York}}-000001"  
setup.ilm.policy\_name: "HungLeLogPolicy"  
#setup.ilm.policy\_file: "/Users/hungl/TEST\_LOG/tasdklog.ilm.policy.json"  
setup.ilm.overwrite: true

setup.template.settings:  
index.number\_of\_shards: 3  
index.number\_of\_replicas: 3

#-------------------------- Elasticsearch output ------------------------------  
output.elasticsearch:

# Array of hosts to connect to.

# hosts: ["localhost:9200"]

hosts: ["[http://eb9cb3db48b04209bd7eb3bc2f843ee0.us-west-1.aws.found.io:9200](http://eb9cb3db48b04209bd7eb3bc2f843ee0.us-west-1.aws.found.io:9200)"]

# index: "tasdklog-%{[agent.version]}-%{+yyyy.MM.dd}"

indices:  
- index: "tasdk-warning-%{[agent.version]}-%{+yyyy.MM.dd}"  
when.contains:  
messages: "WARNING"  
- index: "tasdk-info-%{[agent.version]}-%{+yyyy.MM.dd}"  
when.contains:  
messages: "INFO"  
protocol: "http"  
username: "elastic"  
password: "UrVohVEDJKF94hNarlk4N83L"  
pipeline: "testgrok"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 13, 2019, 10:58pm UTC](https://discuss.elastic.co/t/how-to-configure-multiple-indexes-inside-filebeat-for-one-log-type/203943/2 "2019-11-13T22:58:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
