# How to write to a multiple indexes using single elasticsearch output?

**URL:** <https://discuss.elastic.co/t/how-to-write-to-a-multiple-indexes-using-single-elasticsearch-output/227870>\
**Category:** Logstash\
**Created:** [April 14, 2020, 8:20am UTC](https://discuss.elastic.co/t/how-to-write-to-a-multiple-indexes-using-single-elasticsearch-output/227870 "2020-04-14T08:20:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![artur\_m](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/artur_m/32/66255_2.png) [@artur\_m](https://discuss.elastic.co/u/artur_m)\
**Post date:** [April 14, 2020, 8:20am UTC](https://discuss.elastic.co/t/how-to-write-to-a-multiple-indexes-using-single-elasticsearch-output/227870/1 "2020-04-14T08:20:20Z")

</div>

Hey folks, i'm pretty new guy for ELK stack, so don't judge me too much.

So we have a basic fresh ELK setup v 7.6.2 with basic licence enabled.

We are using filebeat to gather logs and send them to logstash.

After that we need to write those logs to a 3 different indexes depending on field (field.env:[stage|preprod|prod])

We created this field using filebeat config with entry like this:

```auto
fields:
 env: stage

```

ILM policy is on by default (but i assume we can live without it in future)

So we tried something like this - [https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#\_writing\_to\_different\_indices\_best\_practices](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#_writing_to_different_indices_best_practices)

And my logstash config was smthing like that:

```auto
input {
  beats {
    port => 5044
    host => " ******"
  }
}

filter {
      if [field.env] == stage {
        mutate { add_field => { "[@metadata][logstash-2020.04.06-000001]" => "stage-%{+YYYY.MM}" } }
      } else if [field.env] == "preprod" {
        mutate { add_field => { "[@metadata][logstash-2020.04.06-000001]" => "preprod-%{+YYYY.MM.dd}" } }
      } else {
        mutate { add_field => { "[@metadata][logstash-2020.04.06-000001]" => "prod-%{+YYYY}" } }
      }
}

output {
    elasticsearch {
    hosts => ["127.0.0.1:9200"]
    user => "elastic"
    password => " ******"
    }
}

```

logstash-2020.04.06-000001 - is a default index created by logstash

After creating this config file all stack was restarted, all services were up and running without any errors.

But, logstash was continuing to write all logs to default index, witch is logstash-2020.04.06-000001.

So i need an advise:

1. what logstash config need to look like to create and write to a different indexes with mentioned requirements?
2. what do we need to turn off to be able to do that, like ILM or smthng?

Thank you for your help!!!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 14, 2020, 12:53pm UTC](https://discuss.elastic.co/t/how-to-write-to-a-multiple-indexes-using-single-elasticsearch-output/227870/2 "2020-04-14T12:53:35Z")

</div>

> [@artur\_m](#):
>
> if [field.env] == stage {

That should be

```
if [fields][env] == "stage" {

```

---

<div class="post-metadata">

**Author:** ![artur\_m](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/artur_m/32/66255_2.png) [@artur\_m](https://discuss.elastic.co/u/artur_m)\
**Post date:** [April 14, 2020, 1:18pm UTC](https://discuss.elastic.co/t/how-to-write-to-a-multiple-indexes-using-single-elasticsearch-output/227870/3 "2020-04-14T13:18:38Z")

</div>

Will try it asap, anything else?  
May be something i need to modify in "output" section?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 12, 2020, 1:18pm UTC](https://discuss.elastic.co/t/how-to-write-to-a-multiple-indexes-using-single-elasticsearch-output/227870/4 "2020-05-12T13:18:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
