# Replace rsyslog with Filebeat?

**URL:** <https://discuss.elastic.co/t/replace-rsyslog-with-filebeat/204540>\
**Category:** Beats\
**Created:** [October 21, 2019, 7:07pm UTC](https://discuss.elastic.co/t/replace-rsyslog-with-filebeat/204540 "2019-10-21T19:07:20Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![pmercado](https://avatars.discourse-cdn.com/v4/letter/p/59ef9b/32.png) [@pmercado](https://discuss.elastic.co/u/pmercado)\
**Post date:** [October 22, 2019, 11:29am UTC](https://discuss.elastic.co/t/replace-rsyslog-with-filebeat/204540/2 "2019-10-22T11:29:13Z")

</div>

Hi @ajhstn,

reading docs it looks possible.  
Have you tried adding multiple syslog inputs?

can this help on using different indexes?

> [@Change index per pipeline](https://discuss.elastic.co/t/change-index-per-pipeline/144901):
>
> I'm very new to elasticsearch, so I may be approaching this problem incorrectly. I've got a couple logs with different log formats. It's pretty easy to create a pipeline with a grok pattern for each, but I'd like to send each log type to a different index. I assume this is a common pattern. How do other folks handle this? Ideally I'd like to do this with just filebeat and elasticsearch.

---

_[View the full topic](https://discuss.elastic.co/t/replace-rsyslog-with-filebeat/204540)._
