# Custom Index Name for FileBeat

**URL:** <https://discuss.elastic.co/t/custom-index-name-for-filebeat/200073>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 18, 2019, 6:57pm UTC](https://discuss.elastic.co/t/custom-index-name-for-filebeat/200073 "2019-09-18T18:57:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ghaith\_Haddad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghaith_haddad/32/49288_2.png) [@Ghaith\_Haddad](https://discuss.elastic.co/u/Ghaith_Haddad)\
**Post date:** [September 18, 2019, 6:57pm UTC](https://discuss.elastic.co/t/custom-index-name-for-filebeat/200073/1 "2019-09-18T18:57:17Z")

</div>

Hello everyone,

So i have ELK configured on a server and filebeat configured on a bunch of other servers which will be sending their log files to the ELK server. Now i need to be able to differentiate each servers' logs by the index name, but im not sure how can i do that.

Does the index name gets configured at the filebeat client or does it happen when it reaches logstash?

Thanks in advance for any help or guides.

Cheers!

---

<div class="post-metadata">

**Author:** ![pmercado](https://avatars.discourse-cdn.com/v4/letter/p/59ef9b/32.png) [@pmercado](https://discuss.elastic.co/u/pmercado)\
**Post date:** [September 19, 2019, 7:49am UTC](https://discuss.elastic.co/t/custom-index-name-for-filebeat/200073/2 "2019-09-19T07:49:45Z")

</div>

Hi @Ghaith_Haddad,

if you want to set a custom index template name at each Filebeat

```auto
    setup.template.name: "filebeat-server1"
    setup.template.pattern: "filebeat-server1-*" 

```

But I would say it is a better choice to look for a field that traces each server instance if you want to manage all logs in a single index.  
Have you tried [add\_host\_metadata](https://www.elastic.co/guide/en/beats/filebeat/current/add-host-metadata.html) ?  
Also, adding your [own fields](https://www.elastic.co/guide/en/beats/filebeat/current/add-fields.html) could help here

---

<div class="post-metadata">

**Author:** ![ericv](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ericv/32/54588_2.png) [@ericv](https://discuss.elastic.co/u/ericv)\
**Post date:** [September 30, 2019, 3:52am UTC](https://discuss.elastic.co/t/custom-index-name-for-filebeat/200073/3 "2019-09-30T03:52:53Z")

</div>

Hi,

I'm struggling with the exact same issue. I've specified an index name under output, and am pointing `setup.template.name` and `setup.template.pattern` to the one I created based on the filebeat template.

```auto
setup.template.name: "yt-management"
setup.template.pattern: "yt-management-*"

```

and output has:

```auto
output.elasticsearch:
  index: "yt-management-%{+yyyy.MM.dd}"

```

What am I missing here? My log output states

```auto
Sep 30 03:47:16 tw-man-srv01.prd01.activeinfra.net filebeat[21582]: 2019-09-30T03:47:16.684Z INFO [index-management] idxmgmt/std.go:178 Set output.elasticsearch.index to 'filebeat-7.3.2' as ILM is enabled.

```

even though I specify a custom index name.  
Any help is greatly appreciated, been struggling with this two days already.

Kind regards,

Eric V.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 28, 2019, 3:53am UTC](https://discuss.elastic.co/t/custom-index-name-for-filebeat/200073/4 "2019-10-28T03:53:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
