ELK - 7.0.1
Filebeat - 7.0.1
cat /etc/filebeat/filebeat.yml
filebeat.inputs:
- type: log
enabled: true
paths:
- '/var/lib/docker/containers/*/*.log'
json.keys_under_root: true
json.message_key: log
encoding: utf-8
document_type: docker
filebeat.config.modules:
path: ${path.config}/modules.d/*.yml
reload.enabled: false
setup.template.settings:
index.number_of_shards: 1
setup.kibana:
host: "localhost:5601"
output.elasticsearch:
hosts: ["localhost:9200"]
protocol: "http"
index: "api-access-%{+yyyy.MM.dd}"
setup.template:
name: 'api-access'
pattern: 'api-access-*'
enabled: false
processors:
- decode_json_fields:
fields: ["log"]
target: ""
overwrite_keys: true
- add_docker_metadata: ~
filebeat -c /etc/filebeat/filebeat.yml export config
filebeat:
config:
modules:
path: /etc/filebeat/modules.d/*.yml
reload:
enabled: false
inputs:
- document_type: docker
enabled: true
encoding: utf-8
json:
keys_under_root: true
message_key: log
paths:
- /var/lib/docker/containers/*/*.log
type: log
output:
elasticsearch:
hosts:
- localhost:9200
index: api-access-%{+yyyy.MM.dd}
protocol: http
path:
config: /etc/filebeat
data: /var/lib/filebeat
home: /usr/share/filebeat
logs: /var/log/filebeat
processors:
- decode_json_fields:
fields:
- log
overwrite_keys: true
target: ""
- add_docker_metadata: null
setup:
kibana:
host: localhost:5601
template:
enabled: false
name: api-access
pattern: api-access-*
settings:
index:
number_of_shards: 1
But in Index management create filebeat-7.1.0-2019.05.21-000001.
How simple change index name in filebeat?