# Adding filebeat index patterns to use filebeat index or just use custom index without adding filebeat index patterns

**URL:** <https://discuss.elastic.co/t/adding-filebeat-index-patterns-to-use-filebeat-index-or-just-use-custom-index-without-adding-filebeat-index-patterns/97980>\
**Category:** Logstash\
**Created:** [August 22, 2017, 8:55pm UTC](https://discuss.elastic.co/t/adding-filebeat-index-patterns-to-use-filebeat-index-or-just-use-custom-index-without-adding-filebeat-index-patterns/97980 "2017-08-22T20:55:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![BentCoder](https://avatars.discourse-cdn.com/v4/letter/b/c4cdca/32.png) [@BentCoder](https://discuss.elastic.co/u/BentCoder)\
**Post date:** [August 22, 2017, 8:55pm UTC](https://discuss.elastic.co/t/adding-filebeat-index-patterns-to-use-filebeat-index-or-just-use-custom-index-without-adding-filebeat-index-patterns/97980/1 "2017-08-22T20:55:07Z")

</div>

Hi,

1. If I use `filebeat-%{+yyyy.MM.dd}` as index name, every day I get new index created in ES. I then can use `filebeat-*` in Kibana to see logs. For this, I have to add index patterns and load template.

2. If I use custom `my-custom-index` as index name, ES will have only one dedicated index. I then can use `my-custom-index` in Kibana to see logs. For this, I don't have to add or load index patterns/template.

Example:

```auto
output {
    elasticsearch {
        hosts => ["localhost:9200"]
        sniffing => true
        manage_template => false
        #index => "my-custom-index"
        #index => "filebeat-%{+yyyy.MM.dd}"
    }
}

```

**The questions is:** In terms of checking/visualising logs in Kibana, would there be any difference if I use `my-custom-index` or `filebeat-*`? I tried both and haven't seen any difference so what is the point of adding index patterns for options 1 (filebeat index version)?

Note: I asked similar question [here](https://discuss.elastic.co/t/loading-index-patterns-to-use-in-kibana/92356/7) but got all superficial/shortcut answers.

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 24, 2017, 8:01pm UTC](https://discuss.elastic.co/t/adding-filebeat-index-patterns-to-use-filebeat-index-or-just-use-custom-index-without-adding-filebeat-index-patterns/97980/2 "2017-08-24T20:01:50Z")

</div>

> In terms of checking/visualising logs in Kibana, would there be any difference if I use my-custom-index or filebeat-\*?

No.

> I tried both and haven’t seen any difference so what is the point of adding index patterns for options 1 (filebeat index version)?

The point of having one index per day (or month or hour or whatever) is that it helps keep your indexes to a reasonable size and it makes for efficient deletion of old data. Depending on how queries are made they can also be made more efficiently if you can narrow down to a subset of the data based on the time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2017, 8:02pm UTC](https://discuss.elastic.co/t/adding-filebeat-index-patterns-to-use-filebeat-index-or-just-use-custom-index-without-adding-filebeat-index-patterns/97980/3 "2017-09-21T20:02:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
