# Logstash can't create separate indexes

**URL:** <https://discuss.elastic.co/t/logstash-cant-create-separate-indexes/251270>\
**Category:** Logstash\
**Created:** [October 7, 2020, 12:38pm UTC](https://discuss.elastic.co/t/logstash-cant-create-separate-indexes/251270 "2020-10-07T12:38:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bhavin\_Varsur](https://avatars.discourse-cdn.com/v4/letter/b/ecccb3/32.png) [@Bhavin\_Varsur](https://discuss.elastic.co/u/Bhavin_Varsur)\
**Post date:** [October 7, 2020, 12:38pm UTC](https://discuss.elastic.co/t/logstash-cant-create-separate-indexes/251270/1 "2020-10-07T12:38:07Z")

</div>

I have two filebeat inputs which have tags and fields.  
In my pipeline.conf I used filter logs by theirs tags.  
but when the time of index create logstash takes index name as a %{[fields][log\_type]}-2020-10-07.  
How can I solve this? Can I able to create two separate index?  
here are my files.

filebeat.yml :

```
- type: log 
  enabled: true
  paths:
    - D:\Git\gbase.API\Logs\*.log
  tags: ["gbaseapi"]
  fields: {log_type: gbase}

- type: log 
  enabled: true
  paths:
    - D:\Git\finance.api\FinanceAPI\logs\*.log
  tags: ["financeapi"]
  fields: {log_type: finance}

multiline.pattern: '^[[:space:]]'
multiline.negate: false
multiline.match: after

```

mypipeline.conf :

```
input {
 beats {
    type=>"mytest"
    port => 5044
  }
} 
filter{
	if "gbaseapi" in [tags]
	{
	   if [level] in ["Error", "Fatal"] 
	    {
			grok { match=> ["message","%{DATESTAMP:timestamp} \[%{WORD:processId}\] %{LOGLEVEL:level} %{USERNAME:logger} %{USER:user} %{IPV4:clientIp} %{URI:requestUrl} %{USER:method} %{GREEDYDATA:message}"] }
	    }
		else
		{
			grok { match=> ["message","%{DATESTAMP:timestamp} \[%{WORD:processId}\] %{LOGLEVEL:level} %{USERNAME:logger} %{USER:user} %{IPV4:clientIp} %{GREEDYDATA:message}" ] }
		}
	     mutate { gsub => ["message", "\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}.\d{4} ",""]} 
	     mutate { gsub => ["message", "%{level}",""]}
	     mutate { gsub => ["message", "%{logger}",""]}
	     mutate { gsub => ["message", "%{clientIp}",""]}
	}
	if "financeapi" in [tags]
	{
	   if [level] in ["Error", "Fatal"] 
	    {
			grok { match=> ["message","%{DATESTAMP:time} \[%{WORD:processId}\] %{LOGLEVEL:level} %{USERNAME:logger} %{USER:user} %{IPV4:clientIp} %{URI:requestUrl} %{USER:method} %{GREEDYDATA:message}"]}
	    }
		else
		{
			grok { match=> ["message","%{DATESTAMP:time} \[%{WORD:processId}\] %{LOGLEVEL:level} %{USERNAME:logger} %{USER:user} %{IPV4:clientIp} %{GREEDYDATA:message}" ]}
		}
	    mutate { gsub => ["message", "\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}.\d{4} ",""]}
	    mutate { gsub => ["message", "%{level}",""]}
	    mutate { gsub => ["message", "%{logger}",""]}
	    mutate { gsub => ["message", "%{clientIp}",""]}
	}
   date {
		match => ["time" , "dd/MMM/yyyy:HH:mm:ss Z"]
		target=> "@time"
	}
}
output {
		elasticsearch 
		{
			hosts => ["http://localhost:9200"]
			index => "%{[fields][log_type]}-%{+YYYY.MM.dd}"
			user => "something"
			password => "something"		
		}
  stdout { codec => rubydebug }
 }
```

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [October 7, 2020, 1:09pm UTC](https://discuss.elastic.co/t/logstash-cant-create-separate-indexes/251270/2 "2020-10-07T13:09:44Z")

</div>

Hi,

That's a nice try to use field value but i dont think it's implemetend at the moment.

I use if conditions like this

```auto
if logtype == "XXX"
 index XXX
else if logtype == "YYY"
 index YYY

```

i hope it will fit your usecase

---

<div class="post-metadata">

**Author:** ![Bhavin\_Varsur](https://avatars.discourse-cdn.com/v4/letter/b/ecccb3/32.png) [@Bhavin\_Varsur](https://discuss.elastic.co/u/Bhavin_Varsur)\
**Post date:** [October 8, 2020, 3:31am UTC](https://discuss.elastic.co/t/logstash-cant-create-separate-indexes/251270/3 "2020-10-08T03:31:32Z")

</div>

It work like a charm ! Thank you so much !!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 5, 2020, 3:31am UTC](https://discuss.elastic.co/t/logstash-cant-create-separate-indexes/251270/4 "2020-11-05T03:31:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
