Follow these instructions here (there is a bug in the 8.5. docs)
Ok try this.... this is a complete working sample
This will setup the template and ILM policy with your custom name, where you can control the daily rollover.
Do not try to create a data stream with the -%{+yyyy.MM.dd} syntax ... just go to the new ILM policy and set the rollover daily and the backing index will roll over daily... example in this case
.ds-customname-8.5.3-2023.11.26-000001
The commented-out last line you can uncomment that when you run setup but you MUST comment it back out or it will reload the dashboards every time which takes a very long time and it will look like filebeat is not working ... also on only use that if you plan to reuse a modules dashboards
Just one query.
The log file had 10k entries, but decode json option, i believe is adding more index's and i have 40k hits. is this something that we can control.
Did you try my solution... It is more flexible than yours but whatever works for you... Adding the date on the index name may not work real great in the long run.
You will need to provide more details are you sure your did not load the data more than once?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.