# Custom index name for auditbeat

**URL:** <https://discuss.elastic.co/t/custom-index-name-for-auditbeat/229968>\
**Category:** Beats\
**Created:** [April 27, 2020, 1:52pm UTC](https://discuss.elastic.co/t/custom-index-name-for-auditbeat/229968 "2020-04-27T13:52:51Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![michielM](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michielm/32/46127_2.png) [@michielM](https://discuss.elastic.co/u/michielM)\
**Post date:** [April 27, 2020, 1:52pm UTC](https://discuss.elastic.co/t/custom-index-name-for-auditbeat/229968/1 "2020-04-27T13:52:52Z")

</div>

Hi everyone,

I'm setting up a custom index name for auditbeat.  
This part has worked so far, but if I want to load the default kibana dashboards from auditbeat, I keep getting the error: **"Could not locate that index-pattern"**  
I configured like this:  
setup.ilm.enabled: false

output.elasticsearch.index: "auditbeat-customname-%{[agent.version]}-%{+yyyy.MM.dd}"  
setup.template.name: "auditbeat-customname"  
setup.template.pattern: "auditbeat-customname-_"  
setup.dashboards.index: "auditbeat-customname-_"

How do I need to configure kibana to load data from the dashboards?  
I think I've searched about everywhere and still can't seem to find a solution...

---

<div class="post-metadata">

**Author:** ![dedemorton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dedemorton/32/84409_2.png) [@dedemorton](https://discuss.elastic.co/u/dedemorton)\
**Post date:** [April 27, 2020, 5:07pm UTC](https://discuss.elastic.co/t/custom-index-name-for-auditbeat/229968/2 "2020-04-27T17:07:02Z")

</div>

Try using a wildcard in the pattern:

```auto
setup.template.pattern: "auditbeat-customname-*"

```

---

<div class="post-metadata">

**Author:** ![dedemorton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dedemorton/32/84409_2.png) [@dedemorton](https://discuss.elastic.co/u/dedemorton)\
**Post date:** [April 27, 2020, 5:14pm UTC](https://discuss.elastic.co/t/custom-index-name-for-auditbeat/229968/3 "2020-04-27T17:14:11Z")

</div>

Looking more closely, I think maybe your asterisk got swallowed in your post because you didn't format the code example as code.

I've run into your situation a few times (where the index pattern does not get created). It's hard to reproduce. I was able to create the index pattern manually in Kibana, and that seemed to work. See the Kibana docs: [https://www.elastic.co/guide/en/kibana/current/index-patterns.html](https://www.elastic.co/guide/en/kibana/current/index-patterns.html)

---

<div class="post-metadata">

**Author:** ![dedemorton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dedemorton/32/84409_2.png) [@dedemorton](https://discuss.elastic.co/u/dedemorton)\
**Post date:** [April 27, 2020, 7:13pm UTC](https://discuss.elastic.co/t/custom-index-name-for-auditbeat/229968/4 "2020-04-27T19:13:29Z")

</div>

Update: I was able to reproduce your problem, and the fix I suggested here didn't work. I think this might be a bug. Let me follow up with the development team to verify.

---

<div class="post-metadata">

**Author:** ![dedemorton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dedemorton/32/84409_2.png) [@dedemorton](https://discuss.elastic.co/u/dedemorton)\
**Post date:** [April 27, 2020, 7:47pm UTC](https://discuss.elastic.co/t/custom-index-name-for-auditbeat/229968/5 "2020-04-27T19:47:35Z")

</div>

OK, here's the skinny:

There was a bug in this feature, but it should be fixed in the next release (7.7): [https://github.com/elastic/beats/pull/17749](https://github.com/elastic/beats/pull/17749)

I confirmed that you can work around the problem by creating the index pattern (auditbeat-customname-\*) manually in Kibana. Just make sure you also set the custom index pattern id under advanced:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/6/66639c6198287054e0bf0113ca90f4a5496c5c43.png)

---

<div class="post-metadata">

**Author:** ![michielM](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michielm/32/46127_2.png) [@michielM](https://discuss.elastic.co/u/michielM)\
**Post date:** [April 28, 2020, 9:18am UTC](https://discuss.elastic.co/t/custom-index-name-for-auditbeat/229968/6 "2020-04-28T09:18:04Z")

</div>

Thanks! Creating the index manually fixed it for me. Worth updating to 7.7 when this releases?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 26, 2020, 11:30am UTC](https://discuss.elastic.co/t/custom-index-name-for-auditbeat/229968/7 "2020-05-26T11:30:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
