# Can hour and minute be appended to index name?

**URL:** <https://discuss.elastic.co/t/can-hour-and-minute-be-appended-to-index-name/258830>\
**Category:** Logstash\
**Created:** [December 16, 2020, 9:27am UTC](https://discuss.elastic.co/t/can-hour-and-minute-be-appended-to-index-name/258830 "2020-12-16T09:27:17Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![danibe](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@danibe](https://discuss.elastic.co/u/danibe)\
**Post date:** [December 16, 2020, 9:27am UTC](https://discuss.elastic.co/t/can-hour-and-minute-be-appended-to-index-name/258830/1 "2020-12-16T09:27:18Z")

</div>

I am trying to create index names with minute resolution since I am still experimenting with ELK and would like to see the effect of various changes in my logstash filter, without having to delete an existing filter (and without overwriting the previous one that was created minutes ago). So I have been trying the following index naming schema, but it seems that Elastic/logstash doesn't like it:

```auto
    output {
      elasticsearch {
        hosts => ["http://localhost:9200"]
        index => "CPU-over-time-%{+YYYY.MM.dd}-%{+HH.mm}"
      }
    }

```

It only accepts `-%{+YYYY.MM.dd}`.

That is, for `index => "CPU-over-time-%{+YYYY.MM.dd}-%{+HH.mm}"` it will generate an index named `CPU-over-time-`. i.e. without the timestamp appended to it.

Why? Is there a way around this to accomplish what I want?

Thanks.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 16, 2020, 4:46pm UTC](https://discuss.elastic.co/t/can-hour-and-minute-be-appended-to-index-name/258830/2 "2020-12-16T16:46:40Z")

</div>

sprintf references can contain hours and minutes

```
input { generator { count => 1 lines => [''] } }
filter { mutate { add_field => { "someField" => "CPU-over-time-%{+YYYY.MM.dd}-%{+HH.mm}" } } }
output { stdout { codec => rubydebug { metadata => false } } }

```

gets me

```
 "someField" => "CPU-over-time-2020.12.16-16.45",

```

What does elasticsearch object to?

---

<div class="post-metadata">

**Author:** ![danibe](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@danibe](https://discuss.elastic.co/u/danibe)\
**Post date:** [December 17, 2020, 6:44am UTC](https://discuss.elastic.co/t/can-hour-and-minute-be-appended-to-index-name/258830/3 "2020-12-17T06:44:17Z")

</div>

@Badger Thanks for your reply. My problem is not with 'filter' but rather with 'output'. More precisely, the **index name** part of 'output'. I edited my question above to clarify what I am getting for index **name**.

That is, for `index => "CPU-over-time-%{+YYYY.MM.dd}-%{+HH.mm}"` it will generate an index named `CPU-over-time-` . i.e. without the timestamp appended to it.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 17, 2020, 1:52pm UTC](https://discuss.elastic.co/t/can-hour-and-minute-be-appended-to-index-name/258830/4 "2020-12-17T13:52:43Z")

</div>

> [@danibe](#):
>
> My problem is not with 'filter' but rather with 'output'.

Exactly the same interpolation evaluation function is used in both situtations, so if it works in one it will work in the other. If the entire sprintf refence is missing that suggests that you have removed the [@timestamp] field from the message before sending it to the output.

---

<div class="post-metadata">

**Author:** ![danibe](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@danibe](https://discuss.elastic.co/u/danibe)\
**Post date:** [December 17, 2020, 2:16pm UTC](https://discuss.elastic.co/t/can-hour-and-minute-be-appended-to-index-name/258830/5 "2020-12-17T14:16:39Z")

</div>

@Badger You are right, I did remove the [@timestamp] field from the message before sending it to the output. Thanks for the amazing pinpointing diagnosis.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 14, 2021, 2:16pm UTC](https://discuss.elastic.co/t/can-hour-and-minute-be-appended-to-index-name/258830/6 "2021-01-14T14:16:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
