# How to push a specific log to an existing index?

**URL:** <https://discuss.elastic.co/t/how-to-push-a-specific-log-to-an-existing-index/170331>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 28, 2019, 11:46am UTC](https://discuss.elastic.co/t/how-to-push-a-specific-log-to-an-existing-index/170331 "2019-02-28T11:46:28Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![iamashutosh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iamashutosh/32/39977_2.png) [@iamashutosh](https://discuss.elastic.co/u/iamashutosh)\
**Post date:** [February 28, 2019, 11:46am UTC](https://discuss.elastic.co/t/how-to-push-a-specific-log-to-an-existing-index/170331/1 "2019-02-28T11:46:28Z")

</div>

Hello Team,

I have a specific log that I want to push to elasticsearch's index.

Log name: example-2018-02-04.log  
index name: filebeat-2019.02.04

Here is my filebeat.yml:

> filebeat:  
> prospectors:  
> -  
> input\_type: log  
> paths:  
> - /home/testuser/example-2019-02-04.log  
> fields:  
> type: console\_log  
> environment: Production  
> layer: App  
> servername: prod-app  
> document\_type: console\_log  
> multiline.pattern: '^._|._|._|._| \d{2}:\d{2}:\d{2} (?:AM|PM)'  
> multiline.negate: true  
> multiline.match: after  
> -  
> input\_type: log  
> paths:  
> - /home/ubuntu/example-2019-02-04.log  
> fields:  
> type: access\_log  
> environment: Production  
> layer: App  
> servername: prod-app  
> document\_type: access\_log  
> multiline.pattern: '^._|._|._|._| \d{2}:\d{2}:\d{2} (?:AM|PM)'  
> multiline.negate: true  
> multiline.match: after
> 
> output:  
> logstash:  
> hosts: ["[http://localhost:5044](http://localhost:5044)"]  
> bulk\_max\_size: 2048
> 
> shipper:  
> logging:  
> to\_syslog: false  
> to\_files: true  
> files:  
> path: /var/log/filebeat  
> name: filebeat.log  
> keepfiles: 7  
> rotateeverybytes: 10485760 # = 10MB  
> level: info

When I try to search for logs on 4th feb, 2019 I get the below error:

```
Discover: Bad Gateway
Less Info
OK
SearchError: Bad Gateway
at https://xxxxxx.com/bundles/commons.bundle.js:3:2878241
at processQueue (https://xxxxxx.com/bundles/vendors.bundle.js:277:199684)
at https://xxxxxx.com/bundles/vendors.bundle.js:277:200647
at Scope.$digest (https://xxxxxx.com/bundles/vendors.bundle.js:277:210409)
at Scope.$apply (https://xxxxxx.com/bundles/vendors.bundle.js:277:213216)
at done (https://lxxxxxx.com/bundles/vendors.bundle.js:277:132715)
at completeRequest (https://xxxxxx.com/bundles/vendors.bundle.js:277:136327)
at XMLHttpRequest.requestLoaded (https://xxxxxx.com/bundles/vendors.bundle.js:277:135223)

```

Every day a new index is created, but I want to push to an old one.

Regards,  
Ashutosh.

---

<div class="post-metadata">

**Author:** ![NerdSec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nerdsec/32/22056_2.png) [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Post date:** [March 1, 2019, 4:27am UTC](https://discuss.elastic.co/t/how-to-push-a-specific-log-to-an-existing-index/170331/2 "2019-03-01T04:27:44Z")

</div>

> [@iamashutosh](#):
>
> output:  
> logstash:  
> hosts: ["[http://localhost:5044](http://localhost:5044)"]  
> bulk\_max\_size: 2048

Hi Ashutosh,

You are sending data to Logstash. Are you handling this accordingly in Logstash?

We discussed something similar to this in this thread:

[https://discuss.elastic.co/t/logstash-conditional-indexes/170080/6](https://discuss.elastic.co/t/logstash-conditional-indexes/170080/6)

Cheers!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2019, 6:27am UTC](https://discuss.elastic.co/t/how-to-push-a-specific-log-to-an-existing-index/170331/3 "2019-03-29T06:27:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
