# I have configuration of logstash for syslog , it is collecting from multiple devices, how can i create separate indices for each device

**URL:** <https://discuss.elastic.co/t/i-have-configuration-of-logstash-for-syslog-it-is-collecting-from-multiple-devices-how-can-i-create-separate-indices-for-each-device/357339>\
**Category:** Logstash\
**Tags:** elastic-stack-monitoring\
**Created:** [April 13, 2024, 8:31am UTC](https://discuss.elastic.co/t/i-have-configuration-of-logstash-for-syslog-it-is-collecting-from-multiple-devices-how-can-i-create-separate-indices-for-each-device/357339 "2024-04-13T08:31:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sandeep\_Baljepally](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeep_baljepally/32/133479_2.png) [@Sandeep\_Baljepally](https://discuss.elastic.co/u/Sandeep_Baljepally)\
**Post date:** [April 13, 2024, 8:31am UTC](https://discuss.elastic.co/t/i-have-configuration-of-logstash-for-syslog-it-is-collecting-from-multiple-devices-how-can-i-create-separate-indices-for-each-device/357339/1 "2024-04-13T08:31:06Z")

</div>

here is my snippet:

```auto
      syslog {
        port => 9111
        syslog_field => "syslog"
        grok_pattern => "<%{POSINT:priority}>%{SYSLOGTIMESTAMP:timestamp} %{SYSLOGHOST:host} %{DATA:loglevel}: %{GREEDYDATA:message}"
        add_field => { "log_type" => "syslog" } # Add log_type field to syslog messages
    filter {
      if [log_type] == "syslog" {
        json {
          source => "message"
        }
     
        grok {
          match => { "message" => "%{SYSLOGTIMESTAMP:timestamp} %{SYSLOGHOST:host} %{DATA:loglevel}: %{GREEDYDATA:message}" }
        }
     
        mutate {
          add_field => { "index_name" => "syslog_logs" } # Set the index name for syslog field
        }
      }

```

---

<div class="post-metadata">

**Author:** ![Sandeep\_Baljepally](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeep_baljepally/32/133479_2.png) [@Sandeep\_Baljepally](https://discuss.elastic.co/u/Sandeep_Baljepally)\
**Post date:** [April 13, 2024, 1:12pm UTC](https://discuss.elastic.co/t/i-have-configuration-of-logstash-for-syslog-it-is-collecting-from-multiple-devices-how-can-i-create-separate-indices-for-each-device/357339/2 "2024-04-13T13:12:16Z")

</div>

[2024-04-13T13:11:05,050][ERROR][logstash.outputs.opensearch][main][f07d574eba8e9bf8cf56e3e76bd091de1fadf988ff2f6edda9713b5a1dcdd0ac] Could not index event to OpenSearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"syslog\_log-{"ip":"10.1.29.43"}-2024.04.13", :routing=\>nil}, {"service"=\>{"type"=\>"system"}, "message"=\>"[2024-04-13 13:11:04] INFO: This is an example testing message from Python code using syslog in Logstash", "log\_type"=\>"syslog", "@version"=\>"1", "event"=\>{"original"=\>nil}, "host"=\>{"ip"=\>"10.1.29.43"}, "tags"=\>["\_grokparsefailure\_sysloginput", "\_jsonparsefailure", "\_grokparsefailure"], "log"=\>{"syslog"=\>{"facility"=\>{"name"=\>"kernel", "code"=\>0}, "priority"=\>0, "severity"=\>{"name"=\>"Emergency", "code"=\>0}}}, "index\_name"=\>"syslog\_log-{"ip":"10.1.29.43"}", "@timestamp"=\>2024-04-13T13:11:04.779830728Z}], :response=\>{"index"=\>{"\_index"=\>"syslog\_log-{"ip":"10.1.29.43"}-2024.04.13", "\_id"=\>nil, "status"=\>400, "error"=\>{"type"=\>"invalid\_index\_name\_exception", "reason"=\>"Invalid index name [syslog\_log-{"ip":"10.1.29.43"}-2024.04.13], must not contain the following characters [, ", \*, \, \<, |, ,, \>, /, ?]", "index"=\>"syslog\_log-{"ip":"10.1.29.43"}-2024.04.13", "index\_uuid"=\>"_na_"}}}}  
getting this error with

```auto
syslog {
        port => 9111
        syslog_field => "syslog"
        grok_pattern => "<%{POSINT:priority}>%{SYSLOGTIMESTAMP:timestamp} %{SYSLOGHOST:host} %{DATA:loglevel}: %{GREEDYDATA:message}"
        add_field => { "log_type" => "syslog" } # Add log_type field to syslog messages
    filter {
      if [log_type] == "syslog" {
        json {
          source => "message"
        }
     
        grok {
          match => { "message" => "%{SYSLOGTIMESTAMP:timestamp} %{SYSLOGHOST:host} %{DATA:loglevel}: %{GREEDYDATA:message}" }
        }
     
        mutate {
          add_field => { "index_name" => "syslog_logs-%{host}" } # Set the index name for syslog field
        }
      }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2024, 1:12pm UTC](https://discuss.elastic.co/t/i-have-configuration-of-logstash-for-syslog-it-is-collecting-from-multiple-devices-how-can-i-create-separate-indices-for-each-device/357339/3 "2024-04-13T13:12:16Z")

</div>

OpenSearch/OpenDistro are AWS run products and differ from the original Elasticsearch and Kibana products that Elastic builds and maintains. You may need to contact them directly for further assistance. See [What is OpenSearch and the OpenSearch Dashboard? | Elastic](https://www.elastic.co/elasticsearch/opensearch) for more details.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 13, 2024, 2:20pm UTC](https://discuss.elastic.co/t/i-have-configuration-of-logstash-for-syslog-it-is-collecting-from-multiple-devices-how-can-i-create-separate-indices-for-each-device/357339/4 "2024-04-13T14:20:49Z")

</div>

> [@Sandeep\_Baljepally](#):
>
> reason"=\>"Invalid index name [syslog\_log-{"ip":"10.1.29.43"}-2024.04.13], must not contain the following characters [, ", \*, , \<, |, ,, \>, /, ?]"

Try `"index_name" => "syslog_logs-%{[host][ip]}"` or `mutate { gsub => ["host", '"', ""] }`
