# How to create an index for Windows Log Event?

**URL:** <https://discuss.elastic.co/t/how-to-create-an-index-for-windows-log-event/43696>\
**Category:** Logstash\
**Created:** [March 7, 2016, 7:31pm UTC](https://discuss.elastic.co/t/how-to-create-an-index-for-windows-log-event/43696 "2016-03-07T19:31:33Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![eso](https://avatars.discourse-cdn.com/v4/letter/e/d6d6ee/32.png) [@eso](https://discuss.elastic.co/u/eso)\
**Post date:** [March 7, 2016, 7:31pm UTC](https://discuss.elastic.co/t/how-to-create-an-index-for-windows-log-event/43696/1 "2016-03-07T19:31:33Z")

</div>

I have a Winlogbeat set up, and I want to set an explicit index for it as follows:

output {

```
 elasticsearch {

     if [type] == "wineventlog" {

         hosts => ["localhost:9200"]
         index => "winlogbeat"
    }
}

```

}

A parser error occurs. When I removed "if" statement, the parser is happy. Can you tell me what is wrong with it. I want an index for each data source (one for winlogbeat and the other topbeat).

Thanks,  
Edison

---

<div class="post-metadata">

**Author:** ![Muaaz\_Saleem](https://avatars.discourse-cdn.com/v4/letter/m/6de8d8/32.png) [@Muaaz\_Saleem](https://discuss.elastic.co/u/Muaaz_Saleem)\
**Post date:** [March 7, 2016, 8:55pm UTC](https://discuss.elastic.co/t/how-to-create-an-index-for-windows-log-event/43696/2 "2016-03-07T20:55:56Z")

</div>

Hi Edison,  
Conditionals can't be nested into other filters. But I think you could do sth like this for your use case. I've used this with Filebeat.

```
output {
 elasticsearch {
   hosts => ["localhost:9200"]
   index => "%{[@metadata][beat]}"
 }
}
```

---

<div class="post-metadata">

**Author:** ![eso](https://avatars.discourse-cdn.com/v4/letter/e/d6d6ee/32.png) [@eso](https://discuss.elastic.co/u/eso)\
**Post date:** [March 7, 2016, 9:42pm UTC](https://discuss.elastic.co/t/how-to-create-an-index-for-windows-log-event/43696/3 "2016-03-07T21:42:20Z")

</div>

Hello,

Thank you for the reply.

According to the JSON output for winlogevent beat, [beat] has two fields: hostname and name as follows:

beat {  
“hostname” =\> “xxx”  
“name” =\> “xxx”  
}

I don’t know how to get rid of one of them because of identical information. Also, the output does not contain [@metadata]; so it does not really help me at all. What is @metadata? What value does it contain?

Right now, I am using:

Index =\> “%{type}”

where “type” has the value “winlogevent”. At least, the documents for Windows Log Events are being indexed uniquely to a single index value. But, I really want the index value to be “winlogbeat”, and I cannot hard-code it because not all documents are Windows events. If I add TopBeat, this hard-coded index will contain both documents from winlogbeat and topbeat. Too bad that conditionals in Elasticsearch filter is not supported anymore.

Any other suggestion.

Edison

---

<div class="post-metadata">

**Author:** ![Muaaz\_Saleem](https://avatars.discourse-cdn.com/v4/letter/m/6de8d8/32.png) [@Muaaz\_Saleem](https://discuss.elastic.co/u/Muaaz_Saleem)\
**Post date:** [March 8, 2016, 6:07am UTC](https://discuss.elastic.co/t/how-to-create-an-index-for-windows-log-event/43696/4 "2016-03-08T06:07:59Z")

</div>

Hi,

There are a couple ways to go about this. You could put the elasticsearch filter inside the conditional:

```
if [type] == "wineventlog" {
        elasticsearch {
         hosts => ["localhost:9200"]
         index => "winlogbeat"
    }
}

```

Alternatively use @metadata. From what I know, you can think of @metadata as logstash output. It has all the info the previous filters applied. [@metadata][beat] gives us the name of the beat we're using. In your case that's Winlogbeat.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 8, 2016, 6:45am UTC](https://discuss.elastic.co/t/how-to-create-an-index-for-windows-log-event/43696/5 "2016-03-08T06:45:28Z")

</div>

> I don’t know how to get rid of one of them because of identical information.

Use the mutate filter's remove\_field option.

> Also, the output does not contain [@metadata]; so it does not really help me at all. What is @metadata? What value does it contain?

That field contains additional metadata about events that's normally ignored by outputs. See [Metadata use cases in Logstash 1.5 | Elastic Blog](https://www.elastic.co/blog/logstash-metadata) and [Accessing event data and fields | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#metadata).

> Too bad that conditionals in Elasticsearch filter is not supported anymore.

Anymore? Conditionals _inside_ plugin declarations have never been supported.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:08am UTC](https://discuss.elastic.co/t/how-to-create-an-index-for-windows-log-event/43696/6 "2017-07-06T05:08:03Z")

</div>


