# Setup filebeat to send different logs to different indexes (to elasticsearch)

**URL:** <https://discuss.elastic.co/t/setup-filebeat-to-send-different-logs-to-different-indexes-to-elasticsearch/338709>\
**Category:** Elasticsearch\
**Created:** [July 18, 2023, 6:36pm UTC](https://discuss.elastic.co/t/setup-filebeat-to-send-different-logs-to-different-indexes-to-elasticsearch/338709 "2023-07-18T18:36:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![perfecto25](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/perfecto25/32/38070_2.png) [@perfecto25](https://discuss.elastic.co/u/perfecto25)\
**Post date:** [July 18, 2023, 6:36pm UTC](https://discuss.elastic.co/t/setup-filebeat-to-send-different-logs-to-different-indexes-to-elasticsearch/338709/1 "2023-07-18T18:36:10Z")

</div>

Hello, I setup a filebeat 8.8.2 on redhat host and configured my filebeat.yml like this, Im sending all my log data to ES directly,

```auto
filebeat.inputs:
- type: filestream
  id: my_id
  enabled: true
  paths:
    - /home/custom/logs/*

filebeat.modules:
- module: system
  enabled: True
  syslog.enabled: true
  auth.enabled: true

setup.template:
  enabled: true
  name: "my-custom-filebeat"
  pattern: "my-custom-filebeat-%{+yyyy.MM.dd}"
  fields: "/etc/filebeat/filebeat_fields.yml"
  overwrite: false
  settings:
    index.number_of_shards: 2
    index.number_of_replicas: 1
    setup.template.enabled: true
    index.codec: best_compression

setup.kibana:
  host: "https://elk:5601"
  api_key: "xxxx"
  ssl:
    certificate_authorities: "/etc/pki/elastic/ca.crt"
    verification_mode: "certificate"

output.elasticsearch:
  hosts: ["https://elk:9200"]
  protocol: "https"
  api_key: "xxxxxx"
  ssl:
    certificate_authorities: ["/etc/pki/elastic/ca.crt"]
    verification_mode: "certificate"
    

  indices:
    - index: "syslog-%{+yyyy.MM.dd}"
      when.equals:
        event.module: "system"
  index: "my-custom-filebeat-%{+yyyy.MM.dd}"

```

basically I am sending custom logs to my-custom-filebeat-YYYY-mm-dd index

and want to send anything from System module to syslog-YYYY-mm-dd index

I am seeing the filestream data for custom logs coming into my custom index (the filebeat is creating the index template for it), but I dont see anything coming in for Syslog index, it doesnt exist.

1. should I create syslog index template manually?
2. is there a way to add multiple "setup.template" parameters to automatically setup these indexes from filebeat?

How do others configure these settings?

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 15, 2023, 6:36pm UTC](https://discuss.elastic.co/t/setup-filebeat-to-send-different-logs-to-different-indexes-to-elasticsearch/338709/2 "2023-08-15T18:36:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
