Multiple Paths for different Indexes


(Sameer Panicker) #1

Can I configure multiple log path for multiple indexes. At present I have indexes named as IISLogs and ServiceLogs. I am using FB -> ES -> KB.

Is it possible to configure C:\My IIS LOGS\.log -> IISLOGS and C:\My Service LOGS\.log -> ServiceLogs. If Yes, where can I do this ?


(Sameer Panicker) #2

Any update on this ?


(ruflin) #3

In filebeat it is not possible to send data to multiple indices when sent directly to elasticsearch. When sending to Logstash first, Logstash can split up your log files and send them to different indices. Best is to use in filebeat 2 different prospectors for the log files and set a different document_type or field, so this can be used in Logstash to do the logic.


(Sameer Panicker) #4

How can I have multiple indexes in the output field ? Can I add IF and ELSE checks ?


(ruflin) #5

That is not possible with filebeat. You can do this kind of transformations with Logstash.


(Sameer Panicker) #6

Yes i am asking for logstash configuration only....


(ruflin) #7

For if statements it is best to have a look at the LS docs here: https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html


(system) #8