# Multiple logs to different index - Filebeat

**URL:** <https://discuss.elastic.co/t/multiple-logs-to-different-index-filebeat/256003>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 19, 2020, 2:38pm UTC](https://discuss.elastic.co/t/multiple-logs-to-different-index-filebeat/256003 "2020-11-19T14:38:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Charakterny](https://avatars.discourse-cdn.com/v4/letter/c/57b2e6/32.png) [@Charakterny](https://discuss.elastic.co/u/Charakterny)\
**Post date:** [November 19, 2020, 2:38pm UTC](https://discuss.elastic.co/t/multiple-logs-to-different-index-filebeat/256003/1 "2020-11-19T14:38:24Z")

</div>

Hello,  
I have in one filebeat.yml two paths for two different logs and it works fine but I need to divide to two index.  
I tried as below:

```
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /var/log/nginx/*.log
  fields:
    type: "nginx"

- type: log
  enabled: true
  paths:
    - /var/log/app/*.log
  fields:
    type: "app"

Elasticsearch template setting:
setup.template.settings:
  index.number_of_shards: 4
setup.template.name: "nginx"
setup.template.pattern: "nginx-*"
setup.template.name: "app"
setup.template.pattern: "app-*"
setup.ilm.enabled: false

and in Elasticsearch output:
index: "nginx-%{+yyyy.MM.dd}-%{[fields.type]:nginx}"
index: "nginx-%{+yyyy.MM.dd}-%{[fields.type]:app}"

```

But is something wrong.  
In Elastic I can create nginx index, can't create app index and still logs are from two paths.  
I would be grateful for your advice.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 20, 2020, 12:47am UTC](https://discuss.elastic.co/t/multiple-logs-to-different-index-filebeat/256003/2 "2020-11-20T00:47:27Z")

</div>

Take a look at the example conditional output here for how to do what you want - [Filebeat conditional output logstash](https://discuss.elastic.co/t/filebeat-conditional-output-logstash/128756)

Also, please format your code/logs/config using the `</>` button, or markdown style back ticks. It helps to make things easy to read which helps us help you 🙂

---

<div class="post-metadata">

**Author:** ![Charakterny](https://avatars.discourse-cdn.com/v4/letter/c/57b2e6/32.png) [@Charakterny](https://discuss.elastic.co/u/Charakterny)\
**Post date:** [November 20, 2020, 9:09am UTC](https://discuss.elastic.co/t/multiple-logs-to-different-index-filebeat/256003/3 "2020-11-20T09:09:38Z")

</div>

Thanks, but still I don't know how to implement in my config. This example is quite different that my case. I need to have in gui two spaces with different logs from one filebeat.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2020, 9:09am UTC](https://discuss.elastic.co/t/multiple-logs-to-different-index-filebeat/256003/4 "2020-12-18T09:09:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
