# Select template for different types of logs in Filebeat

**URL:** <https://discuss.elastic.co/t/select-template-for-different-types-of-logs-in-filebeat/205207>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 25, 2019, 8:28am UTC](https://discuss.elastic.co/t/select-template-for-different-types-of-logs-in-filebeat/205207 "2019-10-25T08:28:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![flowsys](https://avatars.discourse-cdn.com/v4/letter/f/a9a28c/32.png) [@flowsys](https://discuss.elastic.co/u/flowsys)\
**Post date:** [October 25, 2019, 8:28am UTC](https://discuss.elastic.co/t/select-template-for-different-types-of-logs-in-filebeat/205207/1 "2019-10-25T08:28:36Z")

</div>

How do I configure in filebeat.yml to select different index template based on different type of filebeat inputs configured?

I was trying as below, didnt work:

> filebeat.inputs:
> 
> - type: log  
> enabled: true  
> paths:  
> - /var/log/appA.log  
> tags: ["server-alias"]  
> fields:  
> app\_name: appA
> 
> setup.template.name: "filebeat-%{[fields.app\_name]}"  
> setup.template.pattern: "filebeat-%{[fields.app\_name]}-\*"
> 
> output.elasticsearch:  
> hosts: ["node01:9200","node02:9200","node03:9200"]  
> index: "filebeat-%{[fields.app\_name]}-%{[agent.version]}-%{+yyyy.MM.dd}"

Thanks in advanced!

---

<div class="post-metadata">

**Author:** ![faec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faec/32/46988_2.png) [@faec](https://discuss.elastic.co/u/faec)\
**Post date:** [October 25, 2019, 6:21pm UTC](https://discuss.elastic.co/t/select-template-for-different-types-of-logs-in-filebeat/205207/2 "2019-10-25T18:21:20Z")

</div>

Is your goal to have a different index template for each possible value of `app_name`? As written I don't think what you're trying is possible (template patterns can't refer to event fields), but it's also rarely necessary. If the template pattern is `"filebeat-*"` then your `output.elasticsearch.index` setting should send everything to the correct index, and the different indices will all share a common index template, which is usually what you want.

If you do have a particular situation that depends on distinct index templates though, feel free to share more details and we can try and find a workaround 🙂

---

<div class="post-metadata">

**Author:** ![flowsys](https://avatars.discourse-cdn.com/v4/letter/f/a9a28c/32.png) [@flowsys](https://discuss.elastic.co/u/flowsys)\
**Post date:** [October 30, 2019, 7:45am UTC](https://discuss.elastic.co/t/select-template-for-different-types-of-logs-in-filebeat/205207/3 "2019-10-30T07:45:53Z")

</div>

> [@faec](#):
>
> everything

Thanks, your reply makes sense - " If the template pattern is `"filebeat-*"` then your `output.elasticsearch.index` setting should send everything to the correct index, and the different indices will all share a common index template, which is usually what you want."

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 27, 2019, 7:45am UTC](https://discuss.elastic.co/t/select-template-for-different-types-of-logs-in-filebeat/205207/4 "2019-11-27T07:45:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
