# Custom indexes didn't create using winlogbeat-7.2.1 version

**URL:** <https://discuss.elastic.co/t/custom-indexes-didnt-create-using-winlogbeat-7-2-1-version/209496>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [November 26, 2019, 11:48am UTC](https://discuss.elastic.co/t/custom-indexes-didnt-create-using-winlogbeat-7-2-1-version/209496 "2019-11-26T11:48:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Orest\_Gulman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/orest_gulman/32/46463_2.png) [@Orest\_Gulman](https://discuss.elastic.co/u/Orest_Gulman)\
**Post date:** [November 26, 2019, 11:48am UTC](https://discuss.elastic.co/t/custom-indexes-didnt-create-using-winlogbeat-7-2-1-version/209496/1 "2019-11-26T11:48:18Z")

</div>

hi, custom indexes didn't creating using winlogbeat-7.2.1 version.

Below my winlogbeat configuration that properly works in winlogbeat 6.8.1.

```
###################### wlb Configuration ##########################

winlogbeat.event_logs:
  - name: Application
    ignore_older: 72h
    level: critical, error, warning
  - name: System
    ignore_older: 72h
    level: critical, error, warning
  - name: DFS Replication 
    ignore_older: 72h
  - name: Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
    event_id: 21
    ignore_older: 72h

setup.template:
    name: "custom-sys"
    pattern: "custom-sys-*"
    settings:
     index.number_of_shards: 1
     index.number_of_replicas: 1
     index.codec: best_compression 
 
name: "custom-app"
pattern: "custom-app-*"
settings:
 index.number_of_shards: 1
 index.number_of_replicas: 1
 index.codec: best_compression  
 
name: "custom-sec"
pattern: "custom-sec-*"
settings:
 index.number_of_shards: 1
 index.number_of_replicas: 1
 index.codec: best_compression 

output.elasticsearch:
  # Array of hosts to connect to.
indices:
 - index: "custom-sys-%{+yyyy.MM}"
   when:
     or:
      - equals.log_name: "System"    
      - equals.log_name: "DFS Replication"  
     
 - index: "custom-app-%{+yyyy.MM}"
   when.equals:
     log_name: "Application"  
     
 - index: "custom-sec-%{+yyyy.MM}"
   when.equals:
     log_name: "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational"
     
hosts: ["myelasticsearch:9200"]

```

Could you please help me to solve the issue, thanks.

---

<div class="post-metadata">

**Author:** ![Orest\_Gulman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/orest_gulman/32/46463_2.png) [@Orest\_Gulman](https://discuss.elastic.co/u/Orest_Gulman)\
**Post date:** [December 3, 2019, 3:53pm UTC](https://discuss.elastic.co/t/custom-indexes-didnt-create-using-winlogbeat-7-2-1-version/209496/2 "2019-12-03T15:53:51Z")

</div>

I'm following the documentation:  
[https://www.elastic.co/guide/en/beats/winlogbeat/current/elasticsearch-output.html](https://www.elastic.co/guide/en/beats/winlogbeat/current/elasticsearch-output.html)

```
setup.ilm.enabled: false

    winlogbeat.event_logs:
      - name: Application
        ignore_older: 72h
      - name: Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
        event_id: 21
        ignore_older: 72h

setup.template.settings:
  index.number_of_shards: 1
  index.number_of_replicas: 0

output.elasticsearch:
  hosts: ["elasticsearch:9200"]
  indices:
    - index: "wlb-test-app-%{+yyyy.MM}"
      when.equals:
        log_name: "Application" 
    - index: "wlb-test-sec-%{+yyyy.MM}"
      when.equals:
        log_name: "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational"

```

But indexes created with defaults names:

![image](https://us1.discourse-cdn.com/elastic/original/3X/f/9/f993726ebc3e7b5f235f4b11a1aab30b562f003f.png)

---

<div class="post-metadata">

**Author:** ![Orest\_Gulman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/orest_gulman/32/46463_2.png) [@Orest\_Gulman](https://discuss.elastic.co/u/Orest_Gulman)\
**Post date:** [December 3, 2019, 4:50pm UTC](https://discuss.elastic.co/t/custom-indexes-didnt-create-using-winlogbeat-7-2-1-version/209496/3 "2019-12-03T16:50:31Z")

</div>

If I specify `index:` before `indices:` I will send all logs into one Index.  
same issue:

> [@Filebeat not filtering for separate index](https://discuss.elastic.co/t/filebeat-not-filtering-for-separate-index/193742/9):
>
> I have created my whole cluster (because I have contenerized elk, kibana and filebeat) from begining with also set: setup: ilm: enabled: false but still have only one index filebeat-\*

any help?

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [December 7, 2019, 7:49pm UTC](https://discuss.elastic.co/t/custom-indexes-didnt-create-using-winlogbeat-7-2-1-version/209496/4 "2019-12-07T19:49:03Z")

</div>

Remember that indention matters so try to indenting all settings under your setup.template properly like:

```
setup.template:
    name: "custom-sys"
    pattern: "custom-sys-*"
    settings:
        index.number_of_shards: 1
        index.number_of_replicas: 1
        index.codec: best_compression 
 
     name: "custom-app"
     pattern: "custom-app-*"
     settings:
        index.number_of_shards: 1
        index.number_of_replicas: 1
        index.codec: best_compression  
 
     name: "custom-sec"
     pattern: "custom-sec-*"
     settings:
       index.number_of_shards: 1
       index.number_of_replicas: 1
       index.codec: best_compression 

```

or use full qualifying name ala:

```
setup.template.name: "custom-sys"
setup.template.pattern: "custom-sys-*"
setup.template.settings.index.number_of_shards: 1
setup.template.settingsindex.number_of_replicas: 1
setup.template.settings.index.codec: best_compression 
 
setup.template.name: "custom-app"
setup.template.pattern: "custom-app-*"
setup.template.settings.index.number_of_shards: 1
setup.template.settings.index.number_of_replicas: 1
setup.template.settings.index.codec: best_compression  
 
setup.template.name: "custom-sec"
setup.template.pattern: "custom-sec-*"
setup.template.settings.index.number_of_shards: 1
setup.template.settings.index.number_of_replicas: 1
setup.template.settings.index.codec: best_compression
```

---

<div class="post-metadata">

**Author:** ![Orest\_Gulman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/orest_gulman/32/46463_2.png) [@Orest\_Gulman](https://discuss.elastic.co/u/Orest_Gulman)\
**Post date:** [December 11, 2019, 4:32pm UTC](https://discuss.elastic.co/t/custom-indexes-didnt-create-using-winlogbeat-7-2-1-version/209496/5 "2019-12-11T16:32:49Z")

</div>

No, it's not working. The latest elasticsearch version that separate by indexes is 6.8.1

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2020, 4:32pm UTC](https://discuss.elastic.co/t/custom-indexes-didnt-create-using-winlogbeat-7-2-1-version/209496/6 "2020-01-08T16:32:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
