# Seperate ES indexes or Add a new field in logstash

**URL:** <https://discuss.elastic.co/t/seperate-es-indexes-or-add-a-new-field-in-logstash/40476>\
**Category:** Logstash\
**Created:** [January 29, 2016, 12:31pm UTC](https://discuss.elastic.co/t/seperate-es-indexes-or-add-a-new-field-in-logstash/40476 "2016-01-29T12:31:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![elastic-fan](https://avatars.discourse-cdn.com/v4/letter/e/779978/32.png) [@elastic-fan](https://discuss.elastic.co/u/elastic-fan)\
**Post date:** [January 29, 2016, 12:31pm UTC](https://discuss.elastic.co/t/seperate-es-indexes-or-add-a-new-field-in-logstash/40476/1 "2016-01-29T12:31:09Z")

</div>

Hi,  
i am trying to collect logs from 2 different servers which are located far away, should i be creating 2 seperate indexes for each of them in ES or is there a way i can filter the logs coming out of those and add a new field in that log in every line in logstash which has a specific entry..which one is recommended

---

<div class="post-metadata">

**Author:** ![ben.joyce](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ben.joyce/32/7393_2.png) [@ben.joyce](https://discuss.elastic.co/u/ben.joyce)\
**Post date:** [January 29, 2016, 12:57pm UTC](https://discuss.elastic.co/t/seperate-es-indexes-or-add-a-new-field-in-logstash/40476/2 "2016-01-29T12:57:11Z")

</div>

If the two logs are for different systems/components, I'd probably use two  
indexes. If it's two servers hosting the same system, then one index makes  
more sense. I add fields to my index to identify the server the log  
originated from.

---

<div class="post-metadata">

**Author:** ![elastic-fan](https://avatars.discourse-cdn.com/v4/letter/e/779978/32.png) [@elastic-fan](https://discuss.elastic.co/u/elastic-fan)\
**Post date:** [January 29, 2016, 1:04pm UTC](https://discuss.elastic.co/t/seperate-es-indexes-or-add-a-new-field-in-logstash/40476/3 "2016-01-29T13:04:24Z")

</div>

how can i add that dynamically from the logs

---

<div class="post-metadata">

**Author:** ![ben.joyce](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ben.joyce/32/7393_2.png) [@ben.joyce](https://discuss.elastic.co/u/ben.joyce)\
**Post date:** [January 29, 2016, 6:32pm UTC](https://discuss.elastic.co/t/seperate-es-indexes-or-add-a-new-field-in-logstash/40476/4 "2016-01-29T18:32:55Z")

</div>

Here's an example config:

file  
{  
type =\> "mysystem"  
path =\> "yourlogfile.txt"  
start\_position =\> "end"  
codec =\> multiline  
{  
pattern =\> "^[0-9]{4}-[0-9]{2}-[0-9]{2}  
[0-9]{2}:[0-9]{2}:[0-9]{2},[0-9]{0,3} [[0-9]{1,}]  
(DEBUG|WARN|ERROR|INFO|FATAL)"  
negate =\> true  
what =\> previous  
}  
add\_field =\> ["index\_name", "myindex"]  
add\_field =\> ["market", "UK"]  
add\_field =\> ["environment", "Production"]  
add\_field =\> ["host\_name", "SERVER1"]  
add\_field =\> ["component", "API"]  
}

On your other server you'd do:

add\_field =\> ["host\_name", "SERVER2"]

Then in your output section:

elasticsearch  
{  
action =\> "index"  
hosts =\> "your\_elasticsearch\_server"  
index =\> "logstash-%{index\_name}-%{+YYYY.MM.dd}"  
}

You should end up with data from two servers (SERVER1 and SERVER2) going to  
one index, "logstash-myindex-2016-01-29" etc.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:13am UTC](https://discuss.elastic.co/t/seperate-es-indexes-or-add-a-new-field-in-logstash/40476/5 "2017-07-06T05:13:44Z")

</div>


