# Syslog to different indexes

**URL:** <https://discuss.elastic.co/t/syslog-to-different-indexes/238050>\
**Category:** Logstash\
**Created:** [June 22, 2020, 9:17am UTC](https://discuss.elastic.co/t/syslog-to-different-indexes/238050 "2020-06-22T09:17:15Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![arun\_k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arun_k/32/50946_2.png) [@arun\_k](https://discuss.elastic.co/u/arun_k)\
**Post date:** [June 22, 2020, 9:17am UTC](https://discuss.elastic.co/t/syslog-to-different-indexes/238050/1 "2020-06-22T09:17:15Z")

</div>

Hi Team

Am using filebeat to collect logs (mainly syslog) from multiple NW devices belongs to multiple tenants

How can i configure logstash conf to index this to seperate indexes based on customers?  
Log source x,y(syslog) should be indexed to index customer 1  
logsource a,b(syslog) should be indexed to index name :customer 2

All devices are sending logs to same filebeat server

---

<div class="post-metadata">

**Author:** ![d.silwon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/d.silwon/32/65853_2.png) [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Post date:** [June 22, 2020, 12:41pm UTC](https://discuss.elastic.co/t/syslog-to-different-indexes/238050/2 "2020-06-22T12:41:23Z")

</div>

Hi @arun_k,

Here you are sample of my logstash config:  
output {  
if "filebeat" in [agent][type] and "org\_id='oracle' comp\_id='rdbms'" not in [message] {  
elasticsearch {  
hosts =\> ["[https://elk01:9200](https://elk01:9200)"]  
user =\> 'XXX'  
password =\> 'XXX'  
ilm\_enabled =\> false  
manage\_template =\> false  
index =\> "syslog-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}  
if "filebeat" in [agent][type] and "org\_id='oracle' comp\_id='rdbms'" in [message] {  
elasticsearch {  
hosts =\> ["[https://elk01:9200](https://elk01:9200)"]  
user =\> 'XXX'  
password =\> 'XXX'  
ilm\_enabled =\> false  
manage\_template =\> false  
index =\> "oracle-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}  
if "winlogbeat" in [agent][type] {  
elasticsearch {  
hosts =\> ["[https://elk01:9200](https://elk01:9200)"]  
user =\> 'XXX'  
password =\> 'XXX'  
ilm\_enabled =\> false  
manage\_template =\> false  
index =\> "winlog-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}  
stdout {  
codec =\> rubydebug  
}

You can use similar way to separate the logs.

Best Regards,  
Dan

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2020, 12:41pm UTC](https://discuss.elastic.co/t/syslog-to-different-indexes/238050/3 "2020-07-20T12:41:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
