# Badly formatted index, after interpolation still contains placeholder

**URL:** <https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder/345205>\
**Category:** Logstash\
**Tags:** ilm-index-lifecycle-management, datastreams\
**Created:** [October 17, 2023, 12:12pm UTC](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder/345205 "2023-10-17T12:12:13Z")\
**Posts on this page:** 1\
**Showing post:** 10

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 17, 2023, 4:14pm UTC](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder/345205/10 "2023-10-17T16:14:26Z")

</div>

Just found a similar issue with a solution, check this [post](https://discuss.elastic.co/t/manage-several-data-stream-s-in-the-elasitcsearch-output-with-interpolation/332981/2).

You will need to some `data_stream` fields, basically you will need to create the fields:

- `datas_tream.type`
- `data_stream.dataset`
- `data_stream.namespace`

You need this in your filter block:

```auto
mutate {
    add_field => {
      "[data_stream][type]" => "logs"
      "[data_stream][dataset]" => "ssc-misc-%{[instance_name]}-%{[instance_IP]}"
      "[data_stream][namespace]" => "nonprod"
    }
  }

```

And remove those settings from the output.

---

_[View the full topic](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder/345205)._
