# Create Index with filebeat

**URL:** <https://discuss.elastic.co/t/create-index-with-filebeat/211964>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 16, 2019, 9:12am UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964 "2019-12-16T09:12:19Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [December 16, 2019, 9:12am UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964/1 "2019-12-16T09:12:19Z")

</div>

Hello ,

I want to create a index and push data directly to elasticsearch with filebeat but i am not able to create a index its showing me the error can someone help me out.

Exiting: setup.template.name and setup.template.pattern have to be set if index name is modified

---

<div class="post-metadata">

**Author:** ![carmezsa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carmezsa/32/59443_2.png) [@carmezsa](https://discuss.elastic.co/u/carmezsa)\
**Post date:** [December 16, 2019, 10:45am UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964/2 "2019-12-16T10:45:24Z")

</div>

Can you write the code of "filbeat" that you are using?  
Can you add the logs of filebeat with the erorr?  
It can help us to identify the error.  
thanks.

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [December 16, 2019, 10:49am UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964/3 "2019-12-16T10:49:38Z")

</div>

Hello @carmezsa my filebeat config is

filebeat.inputs:

- type: log  
paths:
  - /home/MO\*  
multiline.pattern: '^[0-9]{2}/[0-9]{2}/[0-9]{4}'  
multiline.negate: true  
multiline.match: after  
output.elasticsearch:  
hosts: ["localhost:9200"]  
index: "test1"

and my error is

Exiting: setup.template.name and setup.template.pattern have to be set if index name is modified

---

<div class="post-metadata">

**Author:** ![gabriel\_tessier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel_tessier/32/27911_2.png) [@gabriel\_tessier](https://discuss.elastic.co/u/gabriel_tessier)\
**Post date:** [December 19, 2019, 5:39am UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964/4 "2019-12-19T05:39:01Z")

</div>

Hi @shrikantgulia

As written in the error message you need to set the same name for the setup.template.name and name, something like:

```
filebeat.inputs:

   - type: log
   paths: /home/MO*
   ....
   index: "test1-%{+yyyy.MM.dd}"

setup.template.pattern: "test1"
setup.template.name: "test1-*"

```

This will fix the error as I had the same problem earlier but for me the index name is still filebeat-xxxx the index name don't change.

More information in the doc:

> To use a different name, you set the [`index`](https://www.elastic.co/guide/en/beats/filebeat/master/elasticsearch-output.html#index-option-es) option in the Elasticsearch output. The value that you specify should include the root name of the index plus version and date information. You also need to configure the `setup.template.name` and `setup.template.pattern` options to match the new name.

> **[Load the Elasticsearch index template | Filebeat Reference \[master\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-template.html)**

Also better to use a daily index it cost nothing and prevent to forget when you will move to production. 😀

Tested on 7.5.1

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [December 19, 2019, 5:54am UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964/5 "2019-12-19T05:54:30Z")

</div>

Hello @gabriel_tessier,

I dont want to use the default Index  
So what should i do?  
When i do setup.template.pattern: "test1"  
setup.template.name: "test1-\*"

it is showing error that no template with test1 present  
because i didnt create template.

Q is it compulsory to create a template?

cant it be possible without creating template

---

<div class="post-metadata">

**Author:** ![gabriel\_tessier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel_tessier/32/27911_2.png) [@gabriel\_tessier](https://discuss.elastic.co/u/gabriel_tessier)\
**Post date:** [December 19, 2019, 6:03am UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964/6 "2019-12-19T06:03:00Z")

</div>

@shrikantgulia

> [@shrikantgulia](#):
>
> When i do setup.template.pattern: "test1"  
> setup.template.name: "test1-\*"
> 
> it is showing error that no template with test1 present  
> because i didnt create template.

I didn't create any template and setting setup.template.pattern and name prevent the error.  
But I'm still with the default index like you.

I didn't read that you need to create template in the documentation.

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [December 19, 2019, 7:13am UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964/7 "2019-12-19T07:13:34Z")

</div>

Hello @gabriel_tessier

my config file is ![Capture11](https://us1.discourse-cdn.com/elastic/original/3X/6/f/6f2c0c24385c5d87a1f47c9f5a206f1e15683f1c.png)

still i am getting my data in filebeat default index  
Can someone help me please

---

<div class="post-metadata">

**Author:** ![gabriel\_tessier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel_tessier/32/27911_2.png) [@gabriel\_tessier](https://discuss.elastic.co/u/gabriel_tessier)\
**Post date:** [December 19, 2019, 7:17am UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964/8 "2019-12-19T07:17:53Z")

</div>

Hi @shrikantgulia

You have an indentation problem you need to put setup.template at the beggining of the line not under output elastic.

please see my first post and the link to the documentation. As you poted a picture I can't edit.

Just remove the space before setup.template.pattern and setup.template.name

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [December 19, 2019, 7:22am UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964/9 "2019-12-19T07:22:29Z")

</div>

@gabriel_tessier

Can you Please post the config file here if possible  
please

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [December 19, 2019, 7:24am UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964/10 "2019-12-19T07:24:28Z")

</div>

This is the new config file which i tried  
still not getting the expected result

![Capture12](https://us1.discourse-cdn.com/elastic/original/3X/8/6/86d4e391a3bcd65ef01614119e2a307410648fe1.png)

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [December 23, 2019, 7:38am UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964/11 "2019-12-23T07:38:00Z")

</div>

Can someone Please help me with it

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [December 30, 2019, 7:50am UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964/12 "2019-12-30T07:50:19Z")

</div>

Can someone help me out with it

---

<div class="post-metadata">

**Author:** ![thomas.whc](https://avatars.discourse-cdn.com/v4/letter/t/b4bc9f/32.png) [@thomas.whc](https://discuss.elastic.co/u/thomas.whc)\
**Post date:** [January 8, 2020, 3:46pm UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964/13 "2020-01-08T15:46:32Z")

</div>

I am also facing the same issue (unable to change index name) and the doc doesn't help me enough clarifying the good use of setup.template.\* options in the filebeat config file.  
I'm finally wondering if what we try to do is the right thing.  
Maybe some best practices for dealing with filebeat indexes would help us?

Sorry don't mean to hijack your topic, but I think it is related and I don't want to see it closed.

---

<div class="post-metadata">

**Author:** ![thomas.whc](https://avatars.discourse-cdn.com/v4/letter/t/b4bc9f/32.png) [@thomas.whc](https://discuss.elastic.co/u/thomas.whc)\
**Post date:** [January 8, 2020, 4:08pm UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964/14 "2020-01-08T16:08:03Z")

</div>

@shrikantgulia I guess you are experiencing the same issue as this one: [https://github.com/elastic/beats/issues/11866](https://github.com/elastic/beats/issues/11866)

With ILM (Index Lifecycle Management) enabled, `output.elasticsearch.index` option will be ignored. And ILM is activated by default with clusters that support this feature.

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [January 25, 2020, 6:27am UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964/15 "2020-01-25T06:27:01Z")

</div>

Not Woking  
Can some one Please guide me over this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 22, 2020, 6:27am UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964/16 "2020-02-22T06:27:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
