# Change Index name with enabled ILM

**URL:** <https://discuss.elastic.co/t/change-index-name-with-enabled-ilm/233930>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 22, 2020, 4:11pm UTC](https://discuss.elastic.co/t/change-index-name-with-enabled-ilm/233930 "2020-05-22T16:11:56Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kosodrom](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kosodrom/32/99278_2.png) [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Post date:** [May 22, 2020, 4:11pm UTC](https://discuss.elastic.co/t/change-index-name-with-enabled-ilm/233930/1 "2020-05-22T16:11:56Z")

</div>

Hi guys,

from this documentation: [Configure the Elasticsearch output | Filebeat Reference [7.4] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/7.4/elasticsearch-output.html#index-option-es) i learned:

> The `index` setting is ignored when index lifecycle management is enabled. If you’re sending events to a cluster that supports index lifecycle management, see [_Configure index lifecycle management_](https://www.elastic.co/guide/en/beats/filebeat/7.4/ilm.html) to learn how to change the index name.

When I now follow the link I cannot find any information related to the **index name**. I see how I can change template name, pattern, alias but no index name. Or do I understand the ILM behaviour too little so I cannot read the information somehow between the lines?

Can you please point me to the part where I can learn how to change index name, while keeping the automatic ILM settings that filebeat provides out of the box?

THank you

---

<div class="post-metadata">

**Author:** ![Kosodrom](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kosodrom/32/99278_2.png) [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Post date:** [May 25, 2020, 3:53pm UTC](https://discuss.elastic.co/t/change-index-name-with-enabled-ilm/233930/2 "2020-05-25T15:53:12Z")

</div>

Do I understand right that using the Filebeat's own ILM control I am only able to change the alias? Would it mean that all logs that i push with filebeat will be indexed in one index ?

---

<div class="post-metadata">

**Author:** ![Adriann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adriann/32/77780_2.png) [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Post date:** [May 25, 2020, 5:11pm UTC](https://discuss.elastic.co/t/change-index-name-with-enabled-ilm/233930/3 "2020-05-25T17:11:37Z")

</div>

Hi Kosodrom,

I am not sure if I get your question right. But from what understand so far an index name and index alias is a sort of the same thing. The index can have many aliases.

Filebeat.yml

> setup.ilm.rollover\_alias: "filebeat-netflow"  
> setup.ilm.pattern: "{now/d}-rolled"  
> setup.ilm.check\_exists: true  
> setup.ilm.policy\_file: /etc/filebeat/ilm\_policy\_netflow.txt

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/2/e2b3ce554c3edea4085ba13a637f4b1cb874b5c2.png)

I probably have some error in my ilm policy file (that's why there is index from 05.25 and rolled one) but nether then less you can see after an index is rolled the alias/name is changed.

You can read more about index aliases [here](https://www.elastic.co/guide/en/elasticsearch/reference/7.7/indices-aliases.html)

---

<div class="post-metadata">

**Author:** ![Kosodrom](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kosodrom/32/99278_2.png) [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Post date:** [May 26, 2020, 7:28am UTC](https://discuss.elastic.co/t/change-index-name-with-enabled-ilm/233930/4 "2020-05-26T07:28:04Z")

</div>

Adriann, thanks for your answer.

As far as I understood index name sort of unique identifier of your index and alias is well .. alias.

Let's for example say I have 3 different log sources, that has nothing to do with each other and I want all ship all of them via filbeat (3 filebeats. One filebeat per source). That would mean to me (as far as I understand it right now) that all these logs will be written in one single index. I could disable this behavior in filebeat of course and define templates, ilm policy and index name on my own, but lets assume I want to use the standard filebeat way.

So at the end I have 1 index with 3 totally different sources inside. I could now create some aliases but still those aliases would exist just for this one index. If this is confirmed true I need to disable this if the alias configuration really behaves as a totaly indepandant index I will keep this configuraiton.

---

<div class="post-metadata">

**Author:** ![michielM](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michielm/32/46127_2.png) [@michielM](https://discuss.elastic.co/u/michielM)\
**Post date:** [May 26, 2020, 9:20am UTC](https://discuss.elastic.co/t/change-index-name-with-enabled-ilm/233930/5 "2020-05-26T09:20:14Z")

</div>

I'm not sure if I got your question right.  
Do you want every source to have a different index name?  
If so I used this configuration for it at the bottom of my auditbeat.yml  
#=============================== Index management =============================  
setup.ilm.enabled: false

output.elasticsearch.index: "auditbeat-customname-%{[agent.version]}-%{+yyyy.MM.dd}"  
setup.template.name: "auditbeat-customname"  
setup.template.pattern: "auditbeat-customname-_"  
setup.dashboards.index: "auditbeat-cutsomname-_"

The problem I am facing with this currently is the fact that because I disabled ILM, my indexes are created daily, so if you have 3 sources with 3 indexes, you would have 3 new indexes every day... This is a problem I am trying to solve at this point. I hope this helps!

---

<div class="post-metadata">

**Author:** ![Adriann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adriann/32/77780_2.png) [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Post date:** [May 26, 2020, 9:58am UTC](https://discuss.elastic.co/t/change-index-name-with-enabled-ilm/233930/6 "2020-05-26T09:58:56Z")

</div>

To split data from any module to different indexes you can use below syntax

```
output.elasticsearch:
      indices:
        - index: "filebeat-netflow-%{+yyyy.MM.dd}"
          when.equals:
            event.module: "netflow"

        - index: "filebeat-cisco-%{+yyyy.MM.dd}"
          when.equals:
            event.module: "cisco"

```

[Here](https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html) you can read more about that

---

<div class="post-metadata">

**Author:** ![Kosodrom](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kosodrom/32/99278_2.png) [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Post date:** [May 26, 2020, 10:04am UTC](https://discuss.elastic.co/t/change-index-name-with-enabled-ilm/233930/7 "2020-05-26T10:04:23Z")

</div>

That's exactly what I want to achive: 3 new indeces everyday. One index everyday per source. Actually my assumption was to do the exact same configuration as you did, but in the documentation there is this:

> The `index` setting is ignored when index lifecycle management is enabled. If you’re sending events to a cluster that supports index lifecycle management, see [_Index lifecycle management (ILM)_](https://www.elastic.co/guide/en/beats/filebeat/current/ilm.html) to learn how to change the index name.

Did you disabled ILM in your auditbeat?

Same question goes to Adriann: Did you disabled ILM in order to be able to set the index name in the output?

Thanks guys

---

<div class="post-metadata">

**Author:** ![michielM](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michielm/32/46127_2.png) [@michielM](https://discuss.elastic.co/u/michielM)\
**Post date:** [May 26, 2020, 10:08am UTC](https://discuss.elastic.co/t/change-index-name-with-enabled-ilm/233930/8 "2020-05-26T10:08:22Z")

</div>

Yes, I disabled ILM in auditbeat, it's the first line of the config I uploaded above 🙂

---

<div class="post-metadata">

**Author:** ![Adriann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adriann/32/77780_2.png) [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Post date:** [May 26, 2020, 10:28am UTC](https://discuss.elastic.co/t/change-index-name-with-enabled-ilm/233930/9 "2020-05-26T10:28:17Z")

</div>

I did not and at some point it was working fine, now it's a mess.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 23, 2020, 10:28am UTC](https://discuss.elastic.co/t/change-index-name-with-enabled-ilm/233930/10 "2020-06-23T10:28:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
