# Reparsing / processing old indexes with new separation files in Logstash depending on path logs

**URL:** <https://discuss.elastic.co/t/reparsing-processing-old-indexes-with-new-separation-files-in-logstash-depending-on-path-logs/302807>\
**Category:** Logstash\
**Created:** [April 20, 2022, 12:01pm UTC](https://discuss.elastic.co/t/reparsing-processing-old-indexes-with-new-separation-files-in-logstash-depending-on-path-logs/302807 "2022-04-20T12:01:23Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![dapmI](https://avatars.discourse-cdn.com/v4/letter/d/96bed5/32.png) [@dapmI](https://discuss.elastic.co/u/dapmI)\
**Post date:** [April 20, 2022, 12:01pm UTC](https://discuss.elastic.co/t/reparsing-processing-old-indexes-with-new-separation-files-in-logstash-depending-on-path-logs/302807/1 "2022-04-20T12:01:23Z")

</div>

Hello,

I'm currently in the process to separate indexes depending on the path logs. Here we had to separate logs depending on the source files to better apply lifecycle policy. Currently we have one common index with logs type:

_Note: here is only a sample of the full settings._  
filebeat.yml:

```auto
- type: log
  paths:
    - /var/log/messages
  fields:
    log_type: logs

- type: log
  paths: 
     - /var/log/secure
  fields:
    log_type: security

```

logstash.yml

```auto
input { [...] }

filter{
mutate {
    copy => {
     "[fields][log_type]" => "[@metadata][log_type]"
    }
  }
}

output{
if [@metadata][log_type] {
    elasticsearch {
      hosts => "http://localhost:9200"
      manage_template => false
      index => "%{[@metadata][beat]}-%{[@metadata][log_type]}-%{+YYYY.MM.dd}"
    }
  }
}

```

Here since the new indexes are created successfully like filebeat-logs- or filebeat-security-, we still have old index like filebeat--.  
My question here is that I would like to reprocess the document with this new logstash setup so that the old indexes will be split according to the "log\_type".

Current Setup:

- ELK node with Elasticsearch / Kibana / Logstash
- Server sending logs with filebeat

Thank you in advance for your help and advice.

Benjamin

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2022, 12:02pm UTC](https://discuss.elastic.co/t/reparsing-processing-old-indexes-with-new-separation-files-in-logstash-depending-on-path-logs/302807/2 "2022-05-18T12:02:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
