# Custom Index Name - Logstash

**URL:** <https://discuss.elastic.co/t/custom-index-name-logstash/44222>\
**Category:** Logstash\
**Created:** [March 12, 2016, 5:57am UTC](https://discuss.elastic.co/t/custom-index-name-logstash/44222 "2016-03-12T05:57:39Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sameer\_Dharur](https://avatars.discourse-cdn.com/v4/letter/s/58956e/32.png) [@Sameer\_Dharur](https://discuss.elastic.co/u/Sameer_Dharur)\
**Post date:** [March 12, 2016, 5:57am UTC](https://discuss.elastic.co/t/custom-index-name-logstash/44222/1 "2016-03-12T05:57:40Z")

</div>

Hello!

I see that logstash is creating a new index on the Elasticsearch server everyday with the name 'logstash-yyyy.mm.dd'

However, I don't want a new file like this everyday and just want to give a custom name for the index where every day's data gets stored.

How do I do this?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 12, 2016, 8:34am UTC](https://discuss.elastic.co/t/custom-index-name-logstash/44222/2 "2016-03-12T08:34:28Z")

</div>

Check out [https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-index](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-index)

---

<div class="post-metadata">

**Author:** ![Sameer\_Dharur](https://avatars.discourse-cdn.com/v4/letter/s/58956e/32.png) [@Sameer\_Dharur](https://discuss.elastic.co/u/Sameer_Dharur)\
**Post date:** [March 14, 2016, 7:09am UTC](https://discuss.elastic.co/t/custom-index-name-logstash/44222/3 "2016-03-14T07:09:40Z")

</div>

I have modified my config to the following but still getting the same default date-based name for the index. Any suggestions?

input {  
file {  
path =\> "C:/ELK/logstash-2.2.2/sample.log"  
type =\> "sample"  
start\_position =\> "beginning"  
sincedb\_path =\> "C:/ELK/logstash-2.2.2/dbfilea"

}  
}

filter {  
grok { match =\> { "message" =\> "%{DAY:day}\s%{MONTH:month}\s%{MONTHDAY:monthday}\s%{YEAR:year}\s%{TIME:time}\sGMT(?[+-]\d\d\d\d)\s([^)]+)\s%{NUMBER:temp}\s%{NUMBER:light}\s%{GREEDYDATA:room}"} }

}

output {

elasticsearch {

index =\> "TempLightLogs"

}

stdout{}

}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 14, 2016, 7:13am UTC](https://discuss.elastic.co/t/custom-index-name-logstash/44222/4 "2016-03-14T07:13:32Z")

</div>

That should not happen with the configuration above. Please check again. This configuration change obviously only applies to new data.

---

<div class="post-metadata">

**Author:** ![Sameer\_Dharur](https://avatars.discourse-cdn.com/v4/letter/s/58956e/32.png) [@Sameer\_Dharur](https://discuss.elastic.co/u/Sameer_Dharur)\
**Post date:** [March 14, 2016, 9:45am UTC](https://discuss.elastic.co/t/custom-index-name-logstash/44222/5 "2016-03-14T09:45:43Z")

</div>

It worked fine.

However, I have now lost the .raw fields that I very eagerly needed to carry out visualizations in the desired manner. Any idea how I can retrieve them?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 14, 2016, 10:17am UTC](https://discuss.elastic.co/t/custom-index-name-logstash/44222/6 "2016-03-14T10:17:19Z")

</div>

You need to setup a template to manage those, take a look at the `_templates` API endpoint and copy the logstash one over to something for your use.

---

<div class="post-metadata">

**Author:** ![xsallowed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xsallowed/32/28971_2.png) [@xsallowed](https://discuss.elastic.co/u/xsallowed)\
**Post date:** [December 18, 2016, 12:29pm UTC](https://discuss.elastic.co/t/custom-index-name-logstash/44222/7 "2016-12-18T12:29:19Z")

</div>

I am trying to define a custom index through my logstash but it doesn't work

input {  
file {  
path =\> " **Path**" #hiding it for confidentiality  
type =\> "csv"  
start\_position =\> beginning}  
}

filter {  
csv {  
columns=\> ["Title","Impact","Test Outcome","Recommendation","References","Affected asset","Risk Rating","Attack vector","Attack complexity","Privileges required","User interaction","Scope","Confidentiality","Integrity","Availability","Exploit code maturity","Remediation level","Report confidence","Confidentiality requirement","Integrity requirement","Availability requirement","Modified attack vector","Modified attack complexity","Modified privileges required","Modified user interaction","Modified scope","Modified confidentiality","Modified integrity","Modified availability","Design Issue","Configuration issue","Coding Issue"]  
separator=\> ","  
remove\_field =\> ["message"]}  
}   
output {  
elasticsearch { hosts =\> ["localhost:9200"]  
index =\> "xx"  
document\_type =\> "Assessment"  
}  
stdout { codec =\> rubydebug }  
}

Can anyone suggest what could be the issue with this config??

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 18, 2016, 1:48pm UTC](https://discuss.elastic.co/t/custom-index-name-logstash/44222/8 "2016-12-18T13:48:47Z")

</div>

Please start a new thread for your question and describe exactly what is not working.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:29am UTC](https://discuss.elastic.co/t/custom-index-name-logstash/44222/9 "2017-07-06T04:29:49Z")

</div>


