# Output to multiple indexes Filebeat 6.5

**URL:** <https://discuss.elastic.co/t/output-to-multiple-indexes-filebeat-6-5/167341>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 6, 2019, 5:39pm UTC](https://discuss.elastic.co/t/output-to-multiple-indexes-filebeat-6-5/167341 "2019-02-06T17:39:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Stancho](https://avatars.discourse-cdn.com/v4/letter/s/b38774/32.png) [@Stancho](https://discuss.elastic.co/u/Stancho)\
**Post date:** [February 6, 2019, 5:39pm UTC](https://discuss.elastic.co/t/output-to-multiple-indexes-filebeat-6-5/167341/1 "2019-02-06T17:39:55Z")

</div>

Hi,

i am trying to configure filebeat to put data into multiple indexes. That is why I define for every prospector a field "category" (fields.category: myApp) and use this field in the parameters "setup.template.name=filebeat-%{[fields.category]}", "setup.template.pattern=filebeat-%{[fields.category]}-\*" and "output.logstash.index=filebeat-%{[fields.category]}". Unfortunately only one index is being created with the name "filebeat-%{[fields.category]}-2019.02.06". Could you please tell me what I am doing wrong?

I am deploying filebeat with kubernetes helm and my filebeat.yml looks like this.  
Thank you!

```
filebeat.config:
  modules:
    path: ${path.config}/modules.d/*.yml
    reload.enabled: true
  prospectors:
    path: ${path.config}/prospectors.d/*.yml
    reload.enabled: true
filebeat.prospectors:
- combine_partial: true
  containers:
    ids:
    - '*'
    path: /var/lib/docker/containers/
    stream: all
  enabled: true
  fields:
    category: myApp
  include_lines:
  - ^[0-9]{4}-[0-9]{2}-[0-9]{2}.*\[custom-regex.*
  multiline:
    match: after
    negate: true
    pattern: ^[0-9]{4}-[0-9]{2}-[0-9]{2}
  processors:
  - add_docker_metadata: null
  - add_kubernetes_metadata:
      in_cluster: true
  type: docker
http.enabled: true
http.port: 5066
logging.level: debug
output:
  file:
    enabled: false
  logstash:
    hosts:
    - logstash:5044
    index: filebeat-%{[fields.category]}
output.file:
  filename: filebeat
  number_of_files: 5
  path: /usr/share/filebeat/data
  rotate_every_kb: 10000
processors:
- add_cloud_metadata: null
setup:
  template:
    name: filebeat-%{[fields.category]}
    pattern: filebeat-%{[fields.category]}-*
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 6, 2019, 9:20pm UTC](https://discuss.elastic.co/t/output-to-multiple-indexes-filebeat-6-5/167341/2 "2019-02-06T21:20:34Z")

</div>

I am pretty sure you need to use Logstash to do this, beats will only ever send to one index.

---

<div class="post-metadata">

**Author:** ![Stancho](https://avatars.discourse-cdn.com/v4/letter/s/b38774/32.png) [@Stancho](https://discuss.elastic.co/u/Stancho)\
**Post date:** [February 7, 2019, 4:02pm UTC](https://discuss.elastic.co/t/output-to-multiple-indexes-filebeat-6-5/167341/3 "2019-02-07T16:02:48Z")

</div>

Hi @warkolm , thank you very much!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 7, 2019, 4:16pm UTC](https://discuss.elastic.co/t/output-to-multiple-indexes-filebeat-6-5/167341/4 "2019-03-07T16:16:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
