# Logstash and multi filebeat index (different)

**URL:** <https://discuss.elastic.co/t/logstash-and-multi-filebeat-index-different/86413>\
**Category:** Logstash\
**Created:** [May 19, 2017, 11:40am UTC](https://discuss.elastic.co/t/logstash-and-multi-filebeat-index-different/86413 "2017-05-19T11:40:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Globule](https://avatars.discourse-cdn.com/v4/letter/g/8491ac/32.png) [@Globule](https://discuss.elastic.co/u/Globule)\
**Post date:** [May 19, 2017, 11:40am UTC](https://discuss.elastic.co/t/logstash-and-multi-filebeat-index-different/86413/1 "2017-05-19T11:40:04Z")

</div>

HI ,

I have set a wazuh ids server and a elk server a part... No problem with logstash and filebeat, no problem with kibana dashboard, but I have in logstash a config for parse filebeat wazuh log... and now I want to add multi filebeat index so as:

- nginx
- apache2
- mysql
- system

my logstash config for filebeat (wazuh log):

# Wazuh - Logstash configuration file

## Remote Wazuh Manager - Filebeat input

input {  
beats {  
port =\> 5000  
codec =\> "json\_lines"  
}  
}  
filter {  
geoip {  
source =\> "srcip"  
target =\> "GeoLocation"  
fields =\> ["city\_name", "continent\_code", "country\_code2", "country\_name", "region\_name", "location"]  
}  
date {  
match =\> ["timestamp", "ISO8601"]  
target =\> "@timestamp"  
}  
mutate {  
remove\_field =\> ["timestamp", "beat", "fields", "input\_type", "tags", "count", "@version", "log", "offset", "type"]  
}  
}  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "wazuh-alerts-%{+YYYY.MM.dd}"  
document\_type =\> "wazuh"  
template =\> "/etc/logstash/wazuh-elastic5-template.json"  
template\_name =\> "wazuh"  
template\_overwrite =\> true  
}  
}

and now I want to send to logstash filebeat modules apache, nginx, but how do that? Do I need to configure different logstash input beat with different index and document\_type or I can do all in one config file?

I need to parse log apache, and nginx -\> need grok?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 29, 2017, 8:17pm UTC](https://discuss.elastic.co/t/logstash-and-multi-filebeat-index-different/86413/2 "2017-05-29T20:17:52Z")

</div>

A short answer is to look into using conditionals to select which filters and outputs to use for various kinds of inputs data.

[https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 26, 2017, 8:17pm UTC](https://discuss.elastic.co/t/logstash-and-multi-filebeat-index-different/86413/3 "2017-06-26T20:17:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
