# Target index by input

**URL:** <https://discuss.elastic.co/t/target-index-by-input/360970>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 6, 2024, 1:42pm UTC](https://discuss.elastic.co/t/target-index-by-input/360970 "2024-06-06T13:42:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![daniu](https://avatars.discourse-cdn.com/v4/letter/d/bc8723/32.png) [@daniu](https://discuss.elastic.co/u/daniu)\
**Post date:** [June 6, 2024, 1:42pm UTC](https://discuss.elastic.co/t/target-index-by-input/360970/1 "2024-06-06T13:42:33Z")

</div>

I'm trying to setup filebeat so that I have two log sources that end up in different indexes of the target logstash. All involved services' (filebeat, logstash, elastic) versions are 8.12.0.

I've found [this question](https://discuss.elastic.co/t/sending-output-to-two-indices/282909) with the solution "you can set the index per input" (as [documented here](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-filestream.html)).

However, setting up my input section like this doesn't seem to work; the data seems to get lost altogether. My filebeat config:

```auto
filebeat.inputs:
  - type: filestream
    id: "filestream-id"
    enabled: true
    index: "index-id"
    paths:
      - /usr/share/filebeat/logs/*.log

fields_under_root: true

processors:
  - dissect:
      tokenizer: "/usr/share/filebeat/logs/%{service_name}.log"
      field: "log.file.path"
      target_prefix: ""

output.logstash:
  hosts: ["loghost:5044"]

```

However, the `index-id` that is set up doesn't appear on the elk host. This is the config of the target logstash:

```auto
input {
  beats {
    port => 5044
    codec => "json"
  }
}

filter {
  mutate {
    remove_field => ["[event][original]"]
  }
}

output {
  elasticsearch {
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    hosts=> "${ELASTIC_HOSTS}"
    user=> "${ELASTIC_USER}"
    password=> "${ELASTIC_PASSWORD}"
    cacert=> "certs/ca/ca.crt"
  }
  stdout {
    codec => rubydebug
  }
}

```

Everything works fine if I move the `index: ...` entry from the `filebeat.inputs` section to `output.logstash`; but I want to eventually add more inputs on that host that should end up in another index.

Am I doing something wrong?

---

<div class="post-metadata">

**Author:** ![Gelinski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gelinski/32/142412_2.png) [@Gelinski](https://discuss.elastic.co/u/Gelinski)\
**Post date:** [June 13, 2024, 2:07am UTC](https://discuss.elastic.co/t/target-index-by-input/360970/2 "2024-06-13T02:07:02Z")

</div>

> [@daniu](#):
>
> `index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"`

Try this

```auto
index => "%{[@metadata][index]}-%{+YYYY.MM.dd}"

```
