In filebeat it is not possible to send data to multiple indices when sent directly to elasticsearch. When sending to Logstash first, Logstash can split up your log files and send them to different indices. Best is to use in filebeat 2 different prospectors for the log files and set a different document_type or field, so this can be used in Logstash to do the logic.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.