# Separate index for each input

**URL:** <https://community.graylog.org/t/separate-index-for-each-input/11911>\
**Category:** Graylog Central (peer support)\
**Created:** [September 10, 2019, 12:28pm UTC](https://community.graylog.org/t/separate-index-for-each-input/11911 "2019-09-10T12:28:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Uporaba](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/uporaba/32/11232_2.png) [@Uporaba](https://community.graylog.org/u/Uporaba)\
**Post date:** [September 10, 2019, 12:28pm UTC](https://community.graylog.org/t/separate-index-for-each-input/11911/1 "2019-09-10T12:28:05Z")

</div>

Is there any way to make different index for different inputs?

---

<div class="post-metadata">

**Author:** ![Karlis](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/karlis/32/4798_2.png) [@Karlis](https://community.graylog.org/u/Karlis)\
**Post date:** [September 10, 2019, 1:06pm UTC](https://community.graylog.org/t/separate-index-for-each-input/11911/2 "2019-09-10T13:06:44Z")

</div>

Add static field named i.e. ‘input\_name’ to every input. Create streams to send messages to separate indexes (don’t forget to check ‘remove matches from ‘All messages’ stream’) for each input, with stream rule ‘input\_name must match (input name)’.

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [September 10, 2019, 1:19pm UTC](https://community.graylog.org/t/separate-index-for-each-input/11911/3 "2019-09-10T13:19:36Z")

</div>

you can use in the stream rules the field `gl2_source_id:>UUID<` where you place the UUID of the input on the routing field.

This will enable you to store one specifc stream in one index and you have one index for the input. As long as the messages are not stored in multiple streams with multiple indices as storage the messages will be only stored in that single index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [September 24, 2019, 1:19pm UTC](https://community.graylog.org/t/separate-index-for-each-input/11911/4 "2019-09-24T13:19:36Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
