Logstash Index Data based on Certificate of Beat

We plan to store Log Files of multiple Systems to our Elasticsearch. To reduce the Operational overhead I would like to store the Data in different Indicies according to the Certificate which the Beats use. Has someone done this before? Is it even possible?