First: Happy New Year!
Second: I have seen various other posts on this topic, but they always seem to timeout before getting to an answer.
I an running ELK 7.13.4
I have an Elasticsearch that ingests data from multiple filbeats running on different servers. The logs are not similar from server to server, so I'd like to have separate indices for each server.
Oh, yeah, I also need ILM to age the logs and eventually remove them.
In a filebeat yaml, I have added
output.elasticsearch.index: "customename-%{+yyyy.MM.dd}"
and
setup:
template:
name: "customname"
pattern: "customname-*"
I restart filebeat, and it keeps writing to the old existing filebeat index, the new index is not created.
What have I forgotten to do?
Thanks!
Michael