Changing index pattern refuses to start


(Morten Bjoernsvik) #1

Hi
according to: https://www.elastic.co/guide/en/beats/winlogbeat/master/elasticsearch-output.html

But if I add

index: "winlogbeat-%{[beat.version]}-%{+yyyy.MM.dd}"

winlogbeat do not start up


(Morten Bjoernsvik) #2

needed to add to winlogbeat.yml:

  setup.template.name: 'winlogbeat-%{[beat.version]}'
  setup.template.pattern: 'winlogbeat-%{[beat.version]}-*'

They seem very default to me.


(Andrew Kroh) #3

Anytime you change the output.elasticsearch.index you also need to configure the setup.template.name and setup.template.pattern to ensure they are all pointing at the right index.

https://www.elastic.co/guide/en/beats/winlogbeat/master/elasticsearch-output.html#index-option-es


(system) #4

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.