# Tags index with logstash and filebeat

**URL:** <https://discuss.elastic.co/t/tags-index-with-logstash-and-filebeat/44682>\
**Category:** Logstash\
**Created:** [March 17, 2016, 9:15am UTC](https://discuss.elastic.co/t/tags-index-with-logstash-and-filebeat/44682 "2016-03-17T09:15:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefanocog](https://avatars.discourse-cdn.com/v4/letter/s/5fc32e/32.png) [@stefanocog](https://discuss.elastic.co/u/stefanocog)\
**Post date:** [March 17, 2016, 9:15am UTC](https://discuss.elastic.co/t/tags-index-with-logstash-and-filebeat/44682/1 "2016-03-17T09:15:34Z")

</div>

I actually use logstash-forwarder and logstash and create a dinamic index with tag with thus configuration:  
/etc/logstash/conf.d/10-output.conf

> output {  
> elasticsearch {  
> hosts =\> "localhost:9200"  
> manage\_template =\> false  
> index =\> "logstash-%{tags}-%{+YYYY.MM.dd}"  
> }  
> }

/etc/logstash-forwarder.conf

> "files": [  
> {  
> "paths": [  
> "/var/log/httpd/ssl\_access\_log",  
> "/var/log/httpd/ssl\_error\_log"  
> ],  
> "fields": { "type": "apache", "tags": "mytag" }  
> },

I convert the configuration files to filebeat in this way:  
/etc/filebeat/filebeat.yml

> filebeat:  
> prospectors:  
> -  
> paths:  
> - /var/log/httpd/access\_log  
> input\_type: log  
> document\_type: apache  
> fields:  
> tags: mytag

Now in kibana to all index, instead of _mytag_ i see _beats\_input\_codec\_plain\_applied_

---

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [April 29, 2016, 5:48pm UTC](https://discuss.elastic.co/t/tags-index-with-logstash-and-filebeat/44682/2 "2016-04-29T17:48:08Z")

</div>

Hi  
I am facing the same issue.  
did you get any solution for this problem?

br,  
Sunil

---

<div class="post-metadata">

**Author:** ![stefanocog](https://avatars.discourse-cdn.com/v4/letter/s/5fc32e/32.png) [@stefanocog](https://discuss.elastic.co/u/stefanocog)\
**Post date:** [May 2, 2016, 7:20am UTC](https://discuss.elastic.co/t/tags-index-with-logstash-and-filebeat/44682/3 "2016-05-02T07:20:07Z")

</div>

unfortunately still no.....i have to find an alternative with other fields and manage with `if` to logstash output conf file

---

<div class="post-metadata">

**Author:** ![stefanocog](https://avatars.discourse-cdn.com/v4/letter/s/5fc32e/32.png) [@stefanocog](https://discuss.elastic.co/u/stefanocog)\
**Post date:** [June 14, 2016, 3:08pm UTC](https://discuss.elastic.co/t/tags-index-with-logstash-and-filebeat/44682/4 "2016-06-14T15:08:34Z")

</div>

I have resolved inserting a filter to logstash:

```
filter {
    if "beats_input_codec_plain_applied" in [tags] {
        mutate {
            remove_tag => ["beats_input_codec_plain_applied"]
        }
    }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:53am UTC](https://discuss.elastic.co/t/tags-index-with-logstash-and-filebeat/44682/5 "2017-07-06T04:53:04Z")

</div>


