# What is the easiest way to create indexes for different nginx logs in logstash

**URL:** <https://discuss.elastic.co/t/what-is-the-easiest-way-to-create-indexes-for-different-nginx-logs-in-logstash/362031>\
**Category:** Logstash\
**Created:** [June 25, 2024, 1:56pm UTC](https://discuss.elastic.co/t/what-is-the-easiest-way-to-create-indexes-for-different-nginx-logs-in-logstash/362031 "2024-06-25T13:56:06Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ffamous](https://avatars.discourse-cdn.com/v4/letter/f/a6a055/32.png) [@ffamous](https://discuss.elastic.co/u/ffamous)\
**Post date:** [June 25, 2024, 1:56pm UTC](https://discuss.elastic.co/t/what-is-the-easiest-way-to-create-indexes-for-different-nginx-logs-in-logstash/362031/1 "2024-06-25T13:56:06Z")

</div>

Hello. I have more than one nginx logs in folder which filebeat send to logstash and want to make index for each of them depends of the log name.

 ![изображение](https://us1.discourse-cdn.com/elastic/original/3X/0/1/01beda09a7526509d7e615a33590d8b36ca263c0.png)

My logstash.conf looks like this:

```auto
input {
  beats {
    port => 5044
  }
}

filter {
  grok {
    match => { "message" => "%{IP:remote_address} - \[%{HTTPDATE:timestamp}\] %{HOSTNAME:host} %{WORD:http_method} %{URIPATHPARAM:request} %{NOTSPACE:http_version} %{NUMBER:request_time} %{DATA:upstream_response_time} %{POSINT:request_length} %{POSINT:status} %{POSINT:bytes_sent} %{DATA:http_referer} \[%{GREEDYDATA:http_user_agent}\]" }
  }
  date {
    match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]
  }
}

output {
  elasticsearch {
    hosts => "es01:9200"
    ssl_enabled => true
    cacert => "/usr/share/logstash/config/certs/ca/ca.crt"
    user => "elastic"
    password => "password"
    index => "%.log"
  }
  stdout { codec => rubydebug }
}

```

What is the best way to reach the goal to send logs to different indexes depends of logs file name? Thx

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 25, 2024, 2:12pm UTC](https://discuss.elastic.co/t/what-is-the-easiest-way-to-create-indexes-for-different-nginx-logs-in-logstash/362031/2 "2024-06-25T14:12:25Z")

</div>

filebeat will include the source filename in [log][file][path]. You can parse that using a dissect or grok filter and reference the result in the index option of the elasticsearch filter using a sprintf reference.

Putting every file into its own index may create too many indexes/shards and negatively impact performance. Check the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/size-your-shards.html).

---

<div class="post-metadata">

**Author:** ![ffamous](https://avatars.discourse-cdn.com/v4/letter/f/a6a055/32.png) [@ffamous](https://discuss.elastic.co/u/ffamous)\
**Post date:** [June 25, 2024, 2:16pm UTC](https://discuss.elastic.co/t/what-is-the-easiest-way-to-create-indexes-for-different-nginx-logs-in-logstash/362031/3 "2024-06-25T14:16:29Z")

</div>

Ohh, thank you so much, I will check it rn 🙏

---

<div class="post-metadata">

**Author:** ![ffamous](https://avatars.discourse-cdn.com/v4/letter/f/a6a055/32.png) [@ffamous](https://discuss.elastic.co/u/ffamous)\
**Post date:** [June 27, 2024, 8:47am UTC](https://discuss.elastic.co/t/what-is-the-easiest-way-to-create-indexes-for-different-nginx-logs-in-logstash/362031/4 "2024-06-27T08:47:35Z")

</div>

Hello, is it possible to get something like this [log][file][path] in logstash.conf but to id of filestream type?  
 ![изображение](https://us1.discourse-cdn.com/elastic/original/3X/4/f/4f86be6cdd251f6989bddbe0a25d87c9ae1eb6b8.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 27, 2024, 11:00am UTC](https://discuss.elastic.co/t/what-is-the-easiest-way-to-create-indexes-for-different-nginx-logs-in-logstash/362031/5 "2024-06-27T11:00:38Z")

</div>

I don't think there is an option to add the filestream id as metadata.

---

<div class="post-metadata">

**Author:** ![ffamous](https://avatars.discourse-cdn.com/v4/letter/f/a6a055/32.png) [@ffamous](https://discuss.elastic.co/u/ffamous)\
**Post date:** [June 27, 2024, 11:03am UTC](https://discuss.elastic.co/t/what-is-the-easiest-way-to-create-indexes-for-different-nginx-logs-in-logstash/362031/6 "2024-06-27T11:03:30Z")

</div>

Sad to hear, looks like I should regex path field instead. Thank you for answering 🙏
