# Injest multiple json files into elasticsearch using filebeat as a different index for each file

**URL:** <https://discuss.elastic.co/t/injest-multiple-json-files-into-elasticsearch-using-filebeat-as-a-different-index-for-each-file/194652>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 9, 2019, 4:27pm UTC](https://discuss.elastic.co/t/injest-multiple-json-files-into-elasticsearch-using-filebeat-as-a-different-index-for-each-file/194652 "2019-08-09T16:27:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sadhika7](https://avatars.discourse-cdn.com/v4/letter/s/b487fb/32.png) [@sadhika7](https://discuss.elastic.co/u/sadhika7)\
**Post date:** [August 9, 2019, 4:27pm UTC](https://discuss.elastic.co/t/injest-multiple-json-files-into-elasticsearch-using-filebeat-as-a-different-index-for-each-file/194652/1 "2019-08-09T16:27:54Z")

</div>

I am trying to injest multiple json files into elasticsearch using filebeat but each json file as a different index name in elasticsearch. Do I also need to use logstash for this?  
I am able to install a single json file into elasticsearch but wasn't sure of how I would injest multiple json files each with a different index name.  
When I tried to injest another json file and restart filebeat, the harvester did not start. Any suggestions on how I could do this?

 ![filebeat-harvester%20not%20started](https://us1.discourse-cdn.com/elastic/original/3X/1/2/1247b72a322f909b30828a6a6c876a70383ce422.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 9, 2019, 5:03pm UTC](https://discuss.elastic.co/t/injest-multiple-json-files-into-elasticsearch-using-filebeat-as-a-different-index-for-each-file/194652/2 "2019-08-09T17:03:42Z")

</div>

Why do you want to create an index per file? Having a lot of small indices and shards is very inefficient and can lead to performance problems.

---

<div class="post-metadata">

**Author:** ![sadhika7](https://avatars.discourse-cdn.com/v4/letter/s/b487fb/32.png) [@sadhika7](https://discuss.elastic.co/u/sadhika7)\
**Post date:** [August 9, 2019, 6:25pm UTC](https://discuss.elastic.co/t/injest-multiple-json-files-into-elasticsearch-using-filebeat-as-a-different-index-for-each-file/194652/3 "2019-08-09T18:25:49Z")

</div>

Hi Christian! These are pcap files and all the files have the same fields but with different call-ids and different use cases. So I wanted to differentiate these files with their index name. Is there an efficient way to do this or would it be really inefficient?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 9, 2019, 6:27pm UTC](https://discuss.elastic.co/t/injest-multiple-json-files-into-elasticsearch-using-filebeat-as-a-different-index-for-each-file/194652/4 "2019-08-09T18:27:29Z")

</div>

How many files do you have?

---

<div class="post-metadata">

**Author:** ![sadhika7](https://avatars.discourse-cdn.com/v4/letter/s/b487fb/32.png) [@sadhika7](https://discuss.elastic.co/u/sadhika7)\
**Post date:** [August 9, 2019, 6:32pm UTC](https://discuss.elastic.co/t/injest-multiple-json-files-into-elasticsearch-using-filebeat-as-a-different-index-for-each-file/194652/5 "2019-08-09T18:32:40Z")

</div>

Currently five files but will grow over time and I might have to delete the older files too if needed

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 6, 2019, 6:32pm UTC](https://discuss.elastic.co/t/injest-multiple-json-files-into-elasticsearch-using-filebeat-as-a-different-index-for-each-file/194652/6 "2019-09-06T18:32:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
