When using Logstash it's easy to tell the system to create indices by day (also then making it easy to delete old data). I've tried to figure out how to do the same thing when sending the beats data directly to Elasticsearch instead of through Logstash and havn't had any luck.
Can someone point me to documentation on how to do this?
I.E. Currently when using Elastic Ingest the indices are named auditbeat-7.6.2-2020.04.19-000001 (for example) with the date appearing to be when Elastic was started. I would like to create one index for each day, for all the different beats (auditbeat, metricbeat, filebeat, etc).