# Separate index per application or name space

**URL:** <https://discuss.elastic.co/t/separate-index-per-application-or-name-space/194257>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 7, 2019, 2:24pm UTC](https://discuss.elastic.co/t/separate-index-per-application-or-name-space/194257 "2019-08-07T14:24:40Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![maxozerov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maxozerov/32/48068_2.png) [@maxozerov](https://discuss.elastic.co/u/maxozerov)\
**Post date:** [August 7, 2019, 4:43pm UTC](https://discuss.elastic.co/t/separate-index-per-application-or-name-space/194257/2 "2019-08-07T16:43:49Z")

</div>

Hello, Raju!  
This separation is similar made (with example) and discussed [here](https://discuss.elastic.co/t/filebeat-not-filtering-for-separate-index/193742).  
Or Elastic Doc example:

```
output.elasticsearch:
  hosts: ["http://localhost:9200"]
  indices:
    - index: "warning-%{[agent.version]}-%{+yyyy.MM.dd}"
      when.contains:
        message: "WARN"
    - index: "error-%{[agent.version]}-%{+yyyy.MM.dd}"
      when.contains:
        message: "ERR"

```

So, need [conditions](https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#conditions)  
Approximate my copy-paste:

```auto
 indices:
    - index: 'filebeat-{{ .Values.elasticsearch.indexSuffix}}-%{[data.kubernetes.labels.app]}-%{+yyyy.MM.dd}' 
      when:
        or:
          - equals:
              data.kubernetes.labels.app: 'cool bro'

```

---

_[View the full topic](https://discuss.elastic.co/t/separate-index-per-application-or-name-space/194257)._
