# How to forward index from filebeat to elasticsearch via logstash using http output

**URL:** <https://discuss.elastic.co/t/how-to-forward-index-from-filebeat-to-elasticsearch-via-logstash-using-http-output/328587>\
**Category:** Logstash\
**Created:** [March 27, 2023, 8:39am UTC](https://discuss.elastic.co/t/how-to-forward-index-from-filebeat-to-elasticsearch-via-logstash-using-http-output/328587 "2023-03-27T08:39:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![majan3k](https://avatars.discourse-cdn.com/v4/letter/m/48db29/32.png) [@majan3k](https://discuss.elastic.co/u/majan3k)\
**Post date:** [March 27, 2023, 8:39am UTC](https://discuss.elastic.co/t/how-to-forward-index-from-filebeat-to-elasticsearch-via-logstash-using-http-output/328587/1 "2023-03-27T08:39:45Z")

</div>

Hello,  
Hello, I am starting my journey with elasticsearch and I have a couple of questions. I tried to find answers in documentation but some areas are not clear for me and I am confused.

1. If I understood correct, in order to group logs from some servers and find them in one place, I shoudl used diffrent "indexes" for diffrenst group of servers. For example, I have 5 servers in one location so I can put them into one index, and other servers from another location into second index and so on, am I right?
2. I am using Filebeat to pass logs into Logstash and http output to pass logs from logstach. I tried with below solution,  
[How to forward index from filebeat to elasticsearch via logstash - Elastic Stack / Beats - Discuss the Elastic Stack](https://discuss.elastic.co/t/how-to-forward-index-from-filebeat-to-elasticsearch-via-logstash/38722)

but based on documentation for http output, https doesn't have index parameter so now I don't know how to create indexes and pass them to my log analytics tool.  
[Http output plugin | Logstash Reference [8.6] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-http.html)

In my filebeat yml file

```auto
output.logstash:
  # The Logstash hosts
  hosts: ["servername.domain:5044"]
  index: "custom_location_90"

```

In my logstash.conf file

```auto
input {
  beats {
    port => 5044
  }
 syslog {
    port => 514
  }
}

output{
         http
                {
                 url=>"https://myurl/log-service/api/v1.0/logs"
                 index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
                 http_method=>"post"
                 content_type=>"application/json"
                 format=>"json_batch"
                 retry_failed=>false
                 http_compression=>true
                 headers => {
                     "Content-Type" => "application/json"
                     "Authorization" => "apiKey XXXXX"}
                 }
                 }

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 27, 2023, 12:43pm UTC](https://discuss.elastic.co/t/how-to-forward-index-from-filebeat-to-elasticsearch-via-logstash-using-http-output/328587/2 "2023-03-27T12:43:55Z")

</div>

> [@majan3k](#):
>
> https doesn't have index parameter so now I don't know how to create indexes and pass them to my log analytics tool.

Can you provide more context about this? If you are using elasticsearch you need to use the `elasticsearch` output, since you are using the `http` output it looks like that you are not using elasticsearch, so the concept of index makes no sense in this case.

---

<div class="post-metadata">

**Author:** ![majan3k](https://avatars.discourse-cdn.com/v4/letter/m/48db29/32.png) [@majan3k](https://discuss.elastic.co/u/majan3k)\
**Post date:** [March 29, 2023, 7:05am UTC](https://discuss.elastic.co/t/how-to-forward-index-from-filebeat-to-elasticsearch-via-logstash-using-http-output/328587/3 "2023-03-29T07:05:39Z")

</div>

> [@leandrojmp](#):
>
> Can you provide more context about this? If you are using elasticsearch you need to use the `elasticsearch` output, since you are using the `http` output it looks like that you are not using elasticsearch, so the concept of index makes no sense in this case.

We are using BMC Helix Log Analytics. This is 3rd part tool vendor, which implemented for their solution Elasticsearch and Kibana and according to their documentation http output should be used to send data from Logstash.  
[Collecting logs by using Logstash and Filebeat - Documentation for BMC Helix Log Analytics 22.4 - BMC Documentation](https://docs.bmc.com/docs/helixlognanalytics/224/collecting-logs-by-using-logstash-and-filebeat-1131460658.html?src=search)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 29, 2023, 1:54pm UTC](https://discuss.elastic.co/t/how-to-forward-index-from-filebeat-to-elasticsearch-via-logstash-using-http-output/328587/4 "2023-03-29T13:54:23Z")

</div>

If you followed their documentation and it still doesn't work, you probably will need to check with BMC on a forum for this tool or wait to see if someone that also uses this tool have a similar error and knows how to solve.

But from the documentation you shared there is nothing about indice name, probably you need to configure it in the tool or you may not even have this option, you need to check with BMC as this is not related to Logstash.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2023, 1:55pm UTC](https://discuss.elastic.co/t/how-to-forward-index-from-filebeat-to-elasticsearch-via-logstash-using-http-output/328587/5 "2023-04-26T13:55:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
