# Auditbeat login dataset generates xxxx indices

**URL:** https://discuss.elastic.co/t/auditbeat-login-dataset-generates-xxxx-indices/188790
**Category:** Beats
**Tags:** auditbeat
**Created:** [July 3, 2019, 6:00pm UTC](https://discuss.elastic.co/t/auditbeat-login-dataset-generates-xxxx-indices/188790 "2019-07-03T18:00:50Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)
#### Post date: [July 3, 2019, 6:00pm UTC](https://discuss.elastic.co/t/auditbeat-login-dataset-generates-xxxx-indices/188790/1 "2019-07-03T18:00:50Z")

</div>

Hello,

Just activated the login dataset on a few 100 hosts and noticed some time thereafter that all of a sudden I have 100+ extra indices, one for each day ranging from 2018 untill today..

There should be a way to limit the number of days for which login events are indexed or this could possibly create some messy situations. Luckily I had some spare heap.. 🙂

An option should be created imho which ignore login events 'older then x days / hours, like there is in Winlogbeat.

winlogbeat.event\_logs:

- name: Application  
ignore\_older: 72h
- name: System  
ignore\_older: 72h

Grtz

Willem

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 24, 2019, 6:00pm UTC](https://discuss.elastic.co/t/auditbeat-login-dataset-generates-xxxx-indices/188790/2 "2019-07-24T18:00:51Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
