# Multiple Indexes in logstash from multiple filebeats -hostname

**URL:** <https://discuss.elastic.co/t/multiple-indexes-in-logstash-from-multiple-filebeats-hostname/88976>\
**Category:** Logstash\
**Created:** [June 12, 2017, 6:07am UTC](https://discuss.elastic.co/t/multiple-indexes-in-logstash-from-multiple-filebeats-hostname/88976 "2017-06-12T06:07:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vijayant\_Panda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vijayant_panda/32/18963_2.png) [@Vijayant\_Panda](https://discuss.elastic.co/u/Vijayant_Panda)\
**Post date:** [June 12, 2017, 6:07am UTC](https://discuss.elastic.co/t/multiple-indexes-in-logstash-from-multiple-filebeats-hostname/88976/1 "2017-06-12T06:07:58Z")

</div>

Hi I am a complete newbie to ELK. I have downloaded set up ELK in local.Now i am able to search one log file(from filebeats) in Kibana UI with logstash-\* index. In my json logs I have a filed called hostname:xxxx . i need to create different indexes based on hostname( eg from production server,sit servver,test server). so that from the kibana i can use different indexes name based on host name(eg logstashproduction-\* ). can you please tell me step by step changes it needs in config- filebeats,logstash config?

[1.Do](http://1.Do) i need to create new index template? since the filebeats are in multiple client servers how can i get the respective filebeats type in logstash based on different host name.

2.can some one tell me the process how it works for different indexes.I have gone through few similar posted questions but unable to get overall picture.

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 12, 2017, 8:06pm UTC](https://discuss.elastic.co/t/multiple-indexes-in-logstash-from-multiple-filebeats-hostname/88976/2 "2017-06-12T20:06:22Z")

</div>

This has been discussed in another thread:

> [@How to configure different indexes in logstash](https://discuss.elastic.co/t/how-to-configure-different-indexes-in-logstash/58665):
>
> Hi Team, Can anyone help me in confugiring multiple indexes so that logs are shipped to different indices based on the environment type(PROD,SIT & DEV). Currently my stepup is working with default filebeat-\* index Logstash configuration input { beats { port =\> "5044" ssl =\> true ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt" ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key" } } filter { if [type] == "syslog" { grok { match =\> { "message" =\> "%{SYSLOGTIMESTAM…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2017, 8:06pm UTC](https://discuss.elastic.co/t/multiple-indexes-in-logstash-from-multiple-filebeats-hostname/88976/3 "2017-07-10T20:06:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
