# Define default index pattern from a yml file

**URL:** https://discuss.elastic.co/t/define-default-index-pattern-from-a-yml-file/354334
**Category:** Kibana
**Tags:** docker
**Created:** [February 28, 2024, 11:43am UTC](https://discuss.elastic.co/t/define-default-index-pattern-from-a-yml-file/354334 "2024-02-28T11:43:19Z")
**Posts on this page:** 13
**Page:** 1

<div class="post-metadata">

### Author: ![Amir\_Dar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amir_dar/32/132154_2.png) [@Amir\_Dar](https://discuss.elastic.co/u/Amir_Dar)
#### Post date: [February 28, 2024, 11:43am UTC](https://discuss.elastic.co/t/define-default-index-pattern-from-a-yml-file/354334/1 "2024-02-28T11:43:19Z")

</div>

Hi All  
we are running ELK (version 8.7.0) over docker containers.  
Whenever we are doing a restart to those containers (manually or due to some failure) the index pattern we defined in the kibana is getting reset and the next time we log in to the kibana we have to set it again

i'm trying to figure out if there is some configuration we can define in our kibana.yml \ elasticsearch.yml files that will automatically set the initial index pattern

when consulting chat gpt it suggested defining in the elasticsearch.yml:

```auto
# Elasticsearch Configuration
cluster.name: my_cluster
node.name: node-1
network.host: 0.0.0.0
discovery.type: single-node

# Custom Index Pattern
index_patterns:
  - name: all_indices
    pattern: "*-*"

```

and in the kibana.yml:

```auto
# Kibana Configuration
server.port: 5601
server.host: "0.0.0.0"
elasticsearch.hosts: ["http://elasticsearch:9200"]

# Custom Index Pattern
kibana.index: ".kibana"
kibana.defaultAppId: "discover"
kibana.indexPatterns: '["all_indices"]'

```

however, this leads to an error when trying to run the kibana container since it won't recognize the kibana.indexPatterns configuration.

so, is there any way to do so?

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [February 28, 2024, 12:37pm UTC](https://discuss.elastic.co/t/define-default-index-pattern-from-a-yml-file/354334/2 "2024-02-28T12:37:02Z")

</div>

> [@Amir\_Dar](#):
>
> Whenever we are doing a restart to those containers (manually or due to some failure) the index pattern we defined in the kibana is getting reset and the next time we log in to the kibana we have to set it again

You mean, the data views? This is stored in Elasticsearch, if it is gone every time you restart your containers something is not right in the way you are running it.

Are you using persistent storage, right? Please share your `docker-compose.yml`.

> [@Amir\_Dar](#):
>
> when consulting chat gpt it suggested

None of those settins exists, Chat GPT is unreliable as it can hallucinate and _invent_ settings and commands that do not exist, I do not recommend applying any setting suggested by chat gpt without checking the documentation, depend on what you change it may break your cluster or lead to data loss.

---

<div class="post-metadata">

### Author: ![Amir\_Dar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amir_dar/32/132154_2.png) [@Amir\_Dar](https://discuss.elastic.co/u/Amir_Dar)
#### Post date: [February 28, 2024, 12:58pm UTC](https://discuss.elastic.co/t/define-default-index-pattern-from-a-yml-file/354334/3 "2024-02-28T12:58:26Z")

</div>

The elastic part inside our docker-compose.yml :

```auto
version: '3.5'
services:
    elasticsearch:
        container_name: elasticsearch
        hostname: elasticsearch
        image: 'docker.elastic.co/elasticsearch/elasticsearch:8.7.0'
        restart: unless-stopped
        environment:
            - cluster.name=docker-cluster
            - bootstrap.memory_lock=true
        ulimits:
            memlock: {soft: -1, hard: -1}
        volumes:
            - '${NANOLOCK_HOME}/elasticsearch/elasticsearch.yml:/usr/share/elasticsearch/config/elasticsearch.yml:z'
            - '${NANOLOCK_HOME}/elasticsearch/jvm.options:/usr/share/elasticsearch/config/jvm.options:z'
            - '${NANOLOCK_HOME}/elasticsearch/data:/usr/share/elasticsearch/data:z'
            - '${NANOLOCK_HOME}/elasticsearch/logs:/usr/share/elasticsearch/logs:z'
        healthcheck:
            test: [CMD-SHELL, 'wget -q -O - http://localhost:9200 || exit 1']
            interval: 10m
            timeout: 60s  
        networks:
          nanolock:
            ipv4_address: XXX.XX.X.XXX

```

as you can see we have a volume with elasticsearch.yml file:

```auto
path.data: /usr/share/elasticsearch/data
path.logs: /usr/share/elasticsearch/logs
network.host: 0.0.0.0
transport.host: 127.0.0.1
http.host: 0.0.0.0
script.allowed_types: inline
xpack.monitoring.templates.enabled: false
#xpack.monitoring.enabled: false
xpack.security.enabled: true

```

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [February 28, 2024, 1:12pm UTC](https://discuss.elastic.co/t/define-default-index-pattern-from-a-yml-file/354334/4 "2024-02-28T13:12:10Z")

</div>

> [@Amir\_Dar](#):
>
> The elastic part inside our docker-compose.yml

You need to share the entire `docker-compose.yml`, not just the elasticsearch part.

---

<div class="post-metadata">

### Author: ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)
#### Post date: [February 29, 2024, 8:08am UTC](https://discuss.elastic.co/t/define-default-index-pattern-from-a-yml-file/354334/5 "2024-02-29T08:08:06Z")

</div>

Hi @Amir_Dar ! Welcome to the community!

Advanced settings (including the default index pattern) can be customized in the following format in `kibana.yml`:

```auto
uiSettings:
  overrides:
    "defaultIndex": "<id here>"
    <... other settings>

```

---

<div class="post-metadata">

### Author: ![Amir\_Dar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amir_dar/32/132154_2.png) [@Amir\_Dar](https://discuss.elastic.co/u/Amir_Dar)
#### Post date: [February 29, 2024, 12:05pm UTC](https://discuss.elastic.co/t/define-default-index-pattern-from-a-yml-file/354334/7 "2024-02-29T12:05:29Z")

</div>

thanks for the quick reply.  
just to make sure I get it, does the "" mean the actual index pattern I want to use? for example, "logs-\*"?

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [February 29, 2024, 2:11pm UTC](https://discuss.elastic.co/t/define-default-index-pattern-from-a-yml-file/354334/8 "2024-02-29T14:11:10Z")

</div>

> [@Amir\_Dar](#):
>
> ```auto
> # Custom Index Pattern
> index_patterns:
> - name: all_indices
> pattern: "*-*"
> 
> ```

Not sure where Chat GPT came up with that...

Also word of Caution using ChatGPT specifically with Elasticsearch the Data Set it used in several years old and Elasticsearch has changed significantly since then, so use it with caution I would always cross-reference the suggestions against our official docs.

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [February 29, 2024, 2:44pm UTC](https://discuss.elastic.co/t/define-default-index-pattern-from-a-yml-file/354334/9 "2024-02-29T14:44:01Z")

</div>

> [@Amir\_Dar](#):
>
> just to make sure I get it, does the "" mean the actual index pattern I want to use? for example, "logs-\*"?

I don't think this has any relation with your issue, you still need to share your entire `docker-compose.yml` to make it clear how you are running your stack.

---

<div class="post-metadata">

### Author: ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)
#### Post date: [March 2, 2024, 8:44am UTC](https://discuss.elastic.co/t/define-default-index-pattern-from-a-yml-file/354334/10 "2024-03-02T08:44:41Z")

</div>

If your were referring to my suggestion with

```auto
uiSettings:
  overrides:
    "defaultIndex": "<id here>"
    <... other settings>

```

then no, it should be id of Index Pattern saved object (or Data View saved object in recent kibana versions) and not a pattern itself.

---

<div class="post-metadata">

### Author: ![Amir\_Dar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amir_dar/32/132154_2.png) [@Amir\_Dar](https://discuss.elastic.co/u/Amir_Dar)
#### Post date: [March 4, 2024, 12:15pm UTC](https://discuss.elastic.co/t/define-default-index-pattern-from-a-yml-file/354334/11 "2024-03-04T12:15:00Z")

</div>

How do we save index pattern\data view in order to see the ID, so we can use it as you suggested?

---

<div class="post-metadata">

### Author: ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)
#### Post date: [March 5, 2024, 9:23am UTC](https://discuss.elastic.co/t/define-default-index-pattern-from-a-yml-file/354334/12 "2024-03-05T09:23:04Z")

</div>

You can define and save it from Stack Management \> Index Patterns (Data Views) page. The ID will be in the URL.

---

<div class="post-metadata">

### Author: ![Amir\_Dar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amir_dar/32/132154_2.png) [@Amir\_Dar](https://discuss.elastic.co/u/Amir_Dar)
#### Post date: [March 5, 2024, 12:01pm UTC](https://discuss.elastic.co/t/define-default-index-pattern-from-a-yml-file/354334/13 "2024-03-05T12:01:32Z")

</div>

but won't this data be lost if i restart my kibana container?  
it's not very presistent

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 2, 2024, 12:01pm UTC](https://discuss.elastic.co/t/define-default-index-pattern-from-a-yml-file/354334/14 "2024-04-02T12:01:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
