# Should we create New Index or Use the same index for all application logs(number of app ~ 5)

**URL:** <https://discuss.elastic.co/t/should-we-create-new-index-or-use-the-same-index-for-all-application-logs-number-of-app-5/259011>\
**Category:** Elasticsearch\
**Created:** [December 17, 2020, 3:59pm UTC](https://discuss.elastic.co/t/should-we-create-new-index-or-use-the-same-index-for-all-application-logs-number-of-app-5/259011 "2020-12-17T15:59:40Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![SHOAIB\_AHMED](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shoaib_ahmed/32/80406_2.png) [@SHOAIB\_AHMED](https://discuss.elastic.co/u/SHOAIB_AHMED)\
**Post date:** [December 17, 2020, 3:59pm UTC](https://discuss.elastic.co/t/should-we-create-new-index-or-use-the-same-index-for-all-application-logs-number-of-app-5/259011/1 "2020-12-17T15:59:40Z")

</div>

I have about 5 apps to monitor using log parsing with ELK.  
Does it make sense to create new index for each application log or only one index is sufficient to store all app logs. The logs for these apps would also contain ERROR and WARNING fields which would help visualize error and warnings separately in a great way.  
Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 17, 2020, 10:11pm UTC](https://discuss.elastic.co/t/should-we-create-new-index-or-use-the-same-index-for-all-application-logs-number-of-app-5/259011/2 "2020-12-17T22:11:53Z")

</div>

Welcome to our community! 😃

Are they all the some format, or very different?

---

<div class="post-metadata">

**Author:** ![SHOAIB\_AHMED](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shoaib_ahmed/32/80406_2.png) [@SHOAIB\_AHMED](https://discuss.elastic.co/u/SHOAIB_AHMED)\
**Post date:** [December 20, 2020, 6:19pm UTC](https://discuss.elastic.co/t/should-we-create-new-index-or-use-the-same-index-for-all-application-logs-number-of-app-5/259011/3 "2020-12-20T18:19:53Z")

</div>

some are access logs, some are airflow logs and hadoop logs etc

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 20, 2020, 11:52pm UTC](https://discuss.elastic.co/t/should-we-create-new-index-or-use-the-same-index-for-all-application-logs-number-of-app-5/259011/4 "2020-12-20T23:52:13Z")

</div>

It's a good idea to group logs that share the same structure, and you can use ECS to reformat them if you'd like,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2021, 11:52pm UTC](https://discuss.elastic.co/t/should-we-create-new-index-or-use-the-same-index-for-all-application-logs-number-of-app-5/259011/5 "2021-01-17T23:52:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
