# Apply index, if available

**URL:** <https://discuss.elastic.co/t/apply-index-if-available/170023>\
**Category:** Logstash\
**Created:** [February 26, 2019, 2:29pm UTC](https://discuss.elastic.co/t/apply-index-if-available/170023 "2019-02-26T14:29:02Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![johann](https://avatars.discourse-cdn.com/v4/letter/j/54ee81/32.png) [@johann](https://discuss.elastic.co/u/johann)\
**Post date:** [February 26, 2019, 2:29pm UTC](https://discuss.elastic.co/t/apply-index-if-available/170023/1 "2019-02-26T14:29:02Z")

</div>

Hi,

if I have an `beats` input from journalbeat to logstash, how can I use the index which is already set?

The beats input is coming from journalbeat -\> logstash -\> elasticsearch.

Journalbeat output: `output.logstash` with `index` option.  
In my Logstash config I have a few if-else rules.

Is there a way to set this index from journalbeat if there is any?

For example:

```
if [input] == journalbeat {
    if isset [index] {
      // keep index
    } else {
    index => "notset-%{+YYYY.MM.dd}"
    }
}

```

Thanks in advance!

Cheers,

johann

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 26, 2019, 2:42pm UTC](https://discuss.elastic.co/t/apply-index-if-available/170023/2 "2019-02-26T14:42:32Z")

</div>

> [@johann](#):
>
> if isset [index] { // keep index } else { index =\> "notset-%{+YYYY.MM.dd}" }

That should be

```
if ! [index] {
     mutate { add_field { index => "notset-%{+YYYY.MM.dd}" } }
}

```

---

<div class="post-metadata">

**Author:** ![johann](https://avatars.discourse-cdn.com/v4/letter/j/54ee81/32.png) [@johann](https://discuss.elastic.co/u/johann)\
**Post date:** [February 26, 2019, 2:58pm UTC](https://discuss.elastic.co/t/apply-index-if-available/170023/3 "2019-02-26T14:58:02Z")

</div>

Thank you, the problem is, the logstash `output.elasticsearch` sets an default index ( \* Default value is `"logstash-%{+YYYY.MM.dd}"`), if the index option is not set... ([https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-index](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-index))

So something like

```
output {
[...]
else if [_index] {
  elasticsearch {
    hosts => "elasticsearch:9200"
    index => [_index]
  }
}

```

should be necessary

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 26, 2019, 3:00pm UTC](https://discuss.elastic.co/t/apply-index-if-available/170023/4 "2019-02-26T15:00:05Z")

</div>

I am suggesting you add that in the filter so that index is always set when you get to the output.

---

<div class="post-metadata">

**Author:** ![johann](https://avatars.discourse-cdn.com/v4/letter/j/54ee81/32.png) [@johann](https://discuss.elastic.co/u/johann)\
**Post date:** [February 26, 2019, 3:23pm UTC](https://discuss.elastic.co/t/apply-index-if-available/170023/5 "2019-02-26T15:23:11Z")

</div>

Isn't the index is set by journalbeat already if I use the journalbeat output.logstash?  
Should be if I understand [https://www.elastic.co/guide/en/beats/journalbeat/6.7/logstash-output.html#logstash-index](https://www.elastic.co/guide/en/beats/journalbeat/6.7/logstash-output.html#logstash-index) correct

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 26, 2019, 3:28pm UTC](https://discuss.elastic.co/t/apply-index-if-available/170023/6 "2019-02-26T15:28:30Z")

</div>

RIght, that's why I made adding index conditional upon index not being set.

---

<div class="post-metadata">

**Author:** ![johann](https://avatars.discourse-cdn.com/v4/letter/j/54ee81/32.png) [@johann](https://discuss.elastic.co/u/johann)\
**Post date:** [February 26, 2019, 4:08pm UTC](https://discuss.elastic.co/t/apply-index-if-available/170023/8 "2019-02-26T16:08:38Z")

</div>

Unfortunately the following is not working ☹ If I use an other field than `index`, it works as aspected...

```
output {
[...]
    else if [index] or [_index] {
      elasticsearch {
                    hosts => "host"
                    index => "auto-%{index}"
      }
    } 
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 26, 2019, 4:08pm UTC](https://discuss.elastic.co/t/apply-index-if-available/170023/9 "2019-03-26T16:08:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
