# Change the default index pattern of winlogbeat?

**URL:** <https://discuss.elastic.co/t/change-the-default-index-pattern-of-winlogbeat/136478>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [June 19, 2018, 11:22am UTC](https://discuss.elastic.co/t/change-the-default-index-pattern-of-winlogbeat/136478 "2018-06-19T11:22:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![brisingertrece](https://avatars.discourse-cdn.com/v4/letter/b/ac8455/32.png) [@brisingertrece](https://discuss.elastic.co/u/brisingertrece)\
**Post date:** [June 19, 2018, 11:22am UTC](https://discuss.elastic.co/t/change-the-default-index-pattern-of-winlogbeat/136478/1 "2018-06-19T11:22:57Z")

</div>

Hi, I am trying to change the default pattern for the indexes generated by winlogbeat.  
I have followed the indications of the official documentation, but at some point I have missed something ...

winlogbeat.yml:

#==================== Elasticsearch template setting ==========================

setup.template.settings:  
setup.template.name: "coliflower"  
setup.template.pattern: "coliflower-\*"  
...  
#-------------------------- Elasticsearch output ------------------------------  
output.elasticsearch:

# Array of hosts to connect to.

enabled: true  
hosts: ["myip:9200"]  
index: "coliflower-%{+yyyy.MM.dd}"

winlogbeat\kibana\default\index-pattern\winlogbeat.json (I change winlogbeat-\* for that):

...  
"timeFieldName": "@timestamp",  
"title": "coliflower-_"  
},  
"id": "coliflower-_",  
"type": "index-pattern",  
"version": 1  
}  
],  
"version": "6.1.0"  
}

winlogbeat\kibana\5.x\index-pattern (I change winlogbeat-\* for that):

...  
"timeFieldName": "@timestamp",  
"title": "coliflower-\*"  
}

Results log:

CRIT Exiting: setup.template.name and setup.template.pattern have to be set if index name is modified.

If I put the following in the elasticsearch output (winlogbeat.yml):

#-------------------------- Elasticsearch output ------------------------------  
output.elasticsearch:

# Array of hosts to connect to.

enabled: true  
hosts: ["myip:9200"]  
output.elasticsearch.index: "coliflower-%{+yyyy.MM.dd}"

It starts but the indexes in elastic are:

yellow open winlogbeat-6.1.1-2018.06 ...  
yellow open winlogbeat-6.1.1-2018.06 ...  
yellow open winlogbeat-6.1.1-2018.06 ...

Someone knows what I'm doing wrong, the only thing I want is to change the name...

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 19, 2018, 3:05pm UTC](https://discuss.elastic.co/t/change-the-default-index-pattern-of-winlogbeat/136478/2 "2018-06-19T15:05:25Z")

</div>

Firstly, please do not post screenshots of text. Just paste the raw text and surround it with three back-ticks to retain formatting.

Here's an example for changing the index name to use ISO weekly index naming. Adjust accordingly based on your naming requirements. But basically you need to set three settings when customizing the index naming (`setup.template.name`, `setup.template.pattern`, and `output.elasticsearch.index`).

```auto
setup.template:
  name: 'winlogbeat-%{[beat.version]}'
  pattern: 'winlogbeat-%{[beat.version]}-*'

output.elasticsearch:
  hosts: ['http://localhost:9200']
  index: 'winlogbeat-%{[beat.version]}-%{+xxxx.ww}'

```

---

<div class="post-metadata">

**Author:** ![brisingertrece](https://avatars.discourse-cdn.com/v4/letter/b/ac8455/32.png) [@brisingertrece](https://discuss.elastic.co/u/brisingertrece)\
**Post date:** [June 19, 2018, 3:35pm UTC](https://discuss.elastic.co/t/change-the-default-index-pattern-of-winlogbeat/136478/3 "2018-06-19T15:35:35Z")

</div>

This has worked perfect for me.  
Thanks Andrew

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2018, 5:42pm UTC](https://discuss.elastic.co/t/change-the-default-index-pattern-of-winlogbeat/136478/4 "2018-07-17T17:42:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
