# Logstash - setting ElasticSearch index based on different input type

**URL:** <https://discuss.elastic.co/t/logstash-setting-elasticsearch-index-based-on-different-input-type/113078>\
**Category:** Logstash\
**Created:** [December 23, 2017, 1:02pm UTC](https://discuss.elastic.co/t/logstash-setting-elasticsearch-index-based-on-different-input-type/113078 "2017-12-23T13:02:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bikash\_Behuria](https://avatars.discourse-cdn.com/v4/letter/b/f14d63/32.png) [@Bikash\_Behuria](https://discuss.elastic.co/u/Bikash_Behuria)\
**Post date:** [December 23, 2017, 1:02pm UTC](https://discuss.elastic.co/t/logstash-setting-elasticsearch-index-based-on-different-input-type/113078/1 "2017-12-23T13:02:22Z")

</div>

Hi ,

I have two input plugins in Logstash i.e. filebeat , and kafka topics for two different type and sources of logs.

Now i want to filter , process the logs and send to different Elasticsearch indexes . Now since I am very new to this area , not been able to find solution. My conf looks like below , can someone suggest me

Thanks-Bikash

input {  
beats {  
port =\> 5044  
type =\> "iislogs"  
}

kafka {  
bootstrap\_servers =\> "localhost:9092"  
topics =\> "ApplicationError"  
type =\> "applicationerror"  
}  
}

Filter {

if[type] == "iislogs" {   
grok {  
match =\>["message", "%{TIMESTAMP\_ISO8601:log\_timestamp} %{WORD:serviceName}]  
}

if[type] == "applicationerror" {   
grok {  
#...for application error parsing  
}

}

## Here in output i want to send this to different indexes based on input type

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> %{type}  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![arisbanach](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@arisbanach](https://discuss.elastic.co/u/arisbanach)\
**Post date:** [December 27, 2017, 2:08pm UTC](https://discuss.elastic.co/t/logstash-setting-elasticsearch-index-based-on-different-input-type/113078/2 "2017-12-27T14:08:30Z")

</div>

I think you just need quotation marks around the type variable in your output, but I could be wrong. What error do you get?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 24, 2018, 2:08pm UTC](https://discuss.elastic.co/t/logstash-setting-elasticsearch-index-based-on-different-input-type/113078/3 "2018-01-24T14:08:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
