# Issue with sending apache logs to elasticsearch with different indices

**URL:** <https://discuss.elastic.co/t/issue-with-sending-apache-logs-to-elasticsearch-with-different-indices/335424>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 7, 2023, 9:49am UTC](https://discuss.elastic.co/t/issue-with-sending-apache-logs-to-elasticsearch-with-different-indices/335424 "2023-06-07T09:49:21Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Akshaychdev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akshaychdev/32/121943_2.png) [@Akshaychdev](https://discuss.elastic.co/u/Akshaychdev)\
**Post date:** [June 7, 2023, 9:49am UTC](https://discuss.elastic.co/t/issue-with-sending-apache-logs-to-elasticsearch-with-different-indices/335424/1 "2023-06-07T09:49:21Z")

</div>

I am new to ELK and I want to use filebeat to fetch and transfer apache access and error logs to elasticsearch index directly. However, I need to send the logs to different indices (rather than the default **`filebeat*`** index), and I also need to enable ILM for both indices. How can I achieve this?

Here is what I have done so far:

- I have enabled the apache module in filebeat and configured the **`apache.yml`** file in **`modules.d`** directory. Here is a sample of my configuration:

```yaml
- module: apache
  # Access logs
  access:
    enabled: true
    var.paths: ["/home/mypath/LOGS/ACCESS/**"]

  # Error logs
  error:
    enabled: true
    var.paths: ["/home/mypath/LOGS/ERROR/**"]

```

- I have not enabled any direct filebeat.inputs in the **`filebeat.yml`** file, only via modules. Here is a sample of my configuration:

```yaml
filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: true
  reload.period: 60s

setup.template.settings:
  index.number_of_shards: 1

name: "elk-filebeat"
tags: ["elk-filebeat", "web-tier"]

# Elasticsearch output configuration
output.elasticsearch:
  hosts: ["https://<ip>:9200"]
  protocol: "https"
  username: "elastic"
  password: "#######"
  ssl.certificate_authorities: "/cert/path/elasticsearch-ca.pem"

	# indices settings
  indices:
    - index: "apache-access-%{[agent.version]}-%{+yyyy.MM.dd}"
      when.equals:
        event.module: "apache"
        event.dataset: "apache.access"

    - index: "apache-error-%{[agent.version]}-%{+yyyy.MM.dd}"
      when.equals:
        event.module: "apache"
        event.dataset: "apache.error"

# Index lifecycle management(Need correction How to manage for 2 indices???)
setup.ilm:
  enabled: true
  policy_name: "apache"
  overwrite: true
  rollover_alias: "apache-%{[agent.version]}"
  pattern: "{now/d}-0000001"

processors:
  - add_host_metadata:
      when.not.contains.tags: forwarded
  - add_cloud_metadata: ~
  - add_docker_metadata: ~
  - add_kubernetes_metadata: ~

logging.level: error
logging.selectors: ["*"]
logging.to_files: true
logging.files:
  path: /var/log/filebeat
  name: filebeat.log
  keepfiles: 7
  permissions: 0644

```

I have searched online and found that to send logs to different indices, I need to set **`setup.ilm.enabled: false`** (because ilm is enabled by default). But this would disable ILM for all indices, which is not what I want.

Is there a way to send apache access logs to **`apache-access*`** index and apache error logs to **`apache-error*`** index, and also enable ILM for both indices?

References

- [Filebeat writing to its own index](https://discuss.elastic.co/t/filebeat-writing-to-its-own-index/310842)
- [Filebeat Apache Module Change Index Name](https://discuss.elastic.co/t/filebeat-apache-module-change-index-name/176955)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2023, 11:49am UTC](https://discuss.elastic.co/t/issue-with-sending-apache-logs-to-elasticsearch-with-different-indices/335424/2 "2023-07-05T11:49:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
