# Date in the name of an index

**URL:** <https://discuss.elastic.co/t/date-in-the-name-of-an-index/190396>\
**Category:** Logstash\
**Created:** [July 14, 2019, 8:43pm UTC](https://discuss.elastic.co/t/date-in-the-name-of-an-index/190396 "2019-07-14T20:43:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![GGUERRA](https://avatars.discourse-cdn.com/v4/letter/g/b2d939/32.png) [@GGUERRA](https://discuss.elastic.co/u/GGUERRA)\
**Post date:** [July 14, 2019, 8:43pm UTC](https://discuss.elastic.co/t/date-in-the-name-of-an-index/190396/1 "2019-07-14T20:43:03Z")

</div>

Hello everyone, I would like to ask about the generation of indices.

I have noticed that in the logstash output in many example cases it is usually written:

```
output {
     elasticsearch {
       hosts => ["x.x.x.x"]
       index => "EXAMPLE-%{+YYYY.MM.dd}" 
     }
}

```

I emphasize that the date is placed on the name. In this way day by day it will generate a new index. Is not better to have only one index? Why is this done?

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [July 14, 2019, 9:26pm UTC](https://discuss.elastic.co/t/date-in-the-name-of-an-index/190396/2 "2019-07-14T21:26:54Z")

</div>

Depending on your partitionning strategry, indices can be one, daily, weekly, monthly .....

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 14, 2019, 10:09pm UTC](https://discuss.elastic.co/t/date-in-the-name-of-an-index/190396/3 "2019-07-14T22:09:43Z")

</div>

The most efficient way to delete data is to drop an entire index. So if you want to keep 30 days of data it is fast to delete the oldest index. If you used a single index then you would need to delete using a query, which is far more expensive.

There are also reasons to keep different document types in different indexes, because elasticsearch does not handle sparse datasets well (although it is much improved in V7 I believe).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 11, 2019, 10:09pm UTC](https://discuss.elastic.co/t/date-in-the-name-of-an-index/190396/4 "2019-08-11T22:09:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
