Logstash multiple indexing


(mostafa) #1

Dear All,

I am using logstash for logging my F5 web logs and working fine. I want to add cisco ASA logs to the same log server, I see both logs on kibana.

Is there a way to have 2 index one for F5 and another for cisco ASA so on the same ELK I can have multiple log formats and be capable to deal with every log type separately .


(Mark Walkom) #2

Yes, look into conditionals.


(system) #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.