# Multi index in filbeat Logstash output

**URL:** <https://discuss.elastic.co/t/multi-index-in-filbeat-logstash-output/249412>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 21, 2020, 7:03pm UTC](https://discuss.elastic.co/t/multi-index-in-filbeat-logstash-output/249412 "2020-09-21T19:03:36Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ganta\_chandra\_teja](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ganta_chandra_teja/32/75963_2.png) [@ganta\_chandra\_teja](https://discuss.elastic.co/u/ganta_chandra_teja)\
**Post date:** [September 21, 2020, 7:03pm UTC](https://discuss.elastic.co/t/multi-index-in-filbeat-logstash-output/249412/1 "2020-09-21T19:03:36Z")

</div>

Tried multi index in filebeat 7.5.2 but didn't work. Please suggest.

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /app/logs/ldapsync/dnp_ldap_interface_error.log
  processors:
  - dissect:
      tokenizer: ' %{timestamp} ERROR [%{task}] (%{code}) - %{Text}'
      field: "message"
      target_prefix: ""
  tags: ["ldap_error"]

- type: log
  enabled: true
  paths:
    - /app/logs/ldapsync/dnp_ldap_interface.log
  processors:
  - dissect:
      tokenizer: ' %{timestamp} %{category} [%{task}] (%{code}) - %{Text}'
      field: "message"
      target_prefix: ""
  tags: ["ldap"]

- type: log
  enabled: true
  paths:
    - /app/logs/AuditLog*nat.bt.com.txt
    - /app/logs/BusLog*nat.bt.com.txt
    - /app/logs/ErrLog*nat.bt.com.txt
  exclude_files: ['.gz$']
  multiline.pattern: ^[[<L:RECORD>]]
  multiline.negate: false
  multiline.match: after
  processors:
  - dissect:
      tokenizer: '<L:RECORD><L:EPOCH>%{App_Epoch}</L:EPOCH><L:DATE>%{Date}</L:DATE><L:TIME>%{App_Time}</L:TIME><L:HOST>%{Host}</L:HOST><L:IP>%{Ip}</L:IP><L:SERVER>%{Server}</L:SERVER><L:PORT>%{Port}</L:PORT><L:MESSAGEID>%{Messageid}</L:MESSAGEID><L:CATEGORY>%{Category}</L:CATEGORY><L:SEVERITY>%{Severity}</L:SEVERITY><L:E2EDATA>%{E2E.Data}</L:E2EDATA><L:TEXT>%{Text}</L:TEXT><L:APP_CONTEXT>Client IP: %{ClientIp}</L:APP_CONTEXT><L:API_VER>BPTM Java API v3.3.9.9</L:API_VER><L:LOCATION>%{Location}</L:LOCATION><L:TIER>%{Tier}</L:TIER><L:RECORD_VER>3.1</L:RECORD_VER></L:RECORD>'
      field: "message"
      target_prefix: ""
  tags: ["bptm"]

#----------------------------- Logstash output --------------------------------
output.logstash:
  # The Logstash hosts
  hosts: ["XXXXXXXX:50495"]
  index: "app1234-abc-ldapsyncerror"
    when.contains:
      tags: ldap_error
  index: "app1234-abc-ldapsynctiming"
    when.contains:
      tags: ldap
  index: "app1234-abc-bptm"
    when.contains:
      tags: bptm
  ssl.certificate_authorities: ["/app/Elasticsearch/filebeat-7.5.2/logstash-forwarder.crt"]
#================================ Logging =====================================
  logging.level: info

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 19, 2020, 9:03pm UTC](https://discuss.elastic.co/t/multi-index-in-filbeat-logstash-output/249412/2 "2020-10-19T21:03:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
