# In my filebeat enable system module and application logs

**URL:** <https://discuss.elastic.co/t/in-my-filebeat-enable-system-module-and-application-logs/257985>\
**Category:** Logstash\
**Created:** [December 8, 2020, 11:58am UTC](https://discuss.elastic.co/t/in-my-filebeat-enable-system-module-and-application-logs/257985 "2020-12-08T11:58:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![prakash22](https://avatars.discourse-cdn.com/v4/letter/p/f1d935/32.png) [@prakash22](https://discuss.elastic.co/u/prakash22)\
**Post date:** [December 8, 2020, 11:58am UTC](https://discuss.elastic.co/t/in-my-filebeat-enable-system-module-and-application-logs/257985/1 "2020-12-08T11:58:31Z")

</div>

I am sending these logs to logstash. But here both application, system logs are going to one index. But I want send to two indexes.  
This is logstash pipeline.

input {  
beats {  
port =\> 5044  
ssl =\> false  
}  
}

output {  
elasticsearch {  
hosts =\> "[http://localhost:9200](http://localhost:9200)"  
user =\> elastic  
password =\> wU8WRmKo1pPI0CqS193d  
index =\> "odooserverlog"  
}  
}

Please help me on this...

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 9, 2020, 3:16am UTC](https://discuss.elastic.co/t/in-my-filebeat-enable-system-module-and-application-logs/257985/2 "2020-12-09T03:16:01Z")

</div>

You will need to use a conditional in the output and split them based on the source Beat.

> [@prakash22](#):
>
> index =\> "odooserverlog"

Are you using ILM here, or is this just a single index?  
If it's a single index, that is not an ideal approach as you will have to delete old data from within the index, which is inefficient.

---

<div class="post-metadata">

**Author:** ![prakash22](https://avatars.discourse-cdn.com/v4/letter/p/f1d935/32.png) [@prakash22](https://discuss.elastic.co/u/prakash22)\
**Post date:** [December 9, 2020, 7:01am UTC](https://discuss.elastic.co/t/in-my-filebeat-enable-system-module-and-application-logs/257985/3 "2020-12-09T07:01:01Z")

</div>

Yes I want to use condition in the output. Can you please suggest the logstash pipeline file.  
My requirement is application logs sent to odooserverlog index  
filebeat system module logs has sent to another index

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 6, 2021, 7:01am UTC](https://discuss.elastic.co/t/in-my-filebeat-enable-system-module-and-application-logs/257985/4 "2021-01-06T07:01:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
