# Define Index Pattern for Metricbeat in Kibana

**URL:** <https://discuss.elastic.co/t/define-index-pattern-for-metricbeat-in-kibana/82793>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [April 18, 2017, 10:46pm UTC](https://discuss.elastic.co/t/define-index-pattern-for-metricbeat-in-kibana/82793 "2017-04-18T22:46:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Steve\_1](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@Steve\_1](https://discuss.elastic.co/u/Steve_1)\
**Post date:** [April 18, 2017, 10:46pm UTC](https://discuss.elastic.co/t/define-index-pattern-for-metricbeat-in-kibana/82793/1 "2017-04-18T22:46:13Z")

</div>

Currently I have only one server from which I collect metrics by Metricbeat.  
In Kibana I created index pattern `metricbeat-*` to be able create some charts.  
But how can I create index patterns for several servers? Should I define tags in `metricbeat.yml` for every server with Metricbeat installed?

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [April 19, 2017, 5:36am UTC](https://discuss.elastic.co/t/define-index-pattern-for-metricbeat-in-kibana/82793/2 "2017-04-19T05:36:56Z")

</div>

You shouldn't need to. The data from all of the servers will land in the metricbeat index. Each metricbeat data record will include the fields `host` as well as `beat.hostname`. You can simply filter on those to view data specific to a single server.

Rob

---

<div class="post-metadata">

**Author:** ![Steve\_1](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@Steve\_1](https://discuss.elastic.co/u/Steve_1)\
**Post date:** [April 20, 2017, 12:37am UTC](https://discuss.elastic.co/t/define-index-pattern-for-metricbeat-in-kibana/82793/3 "2017-04-20T00:37:49Z")

</div>

Do you mean when making a visualization in Kibana select `Split Chart -> Sub Aggregation -> Filters` and type `beat.hostname==host_name`?

That will make title for Y-axis as `host_name:filters` instead of correct metric name, e.g. `Average system.filesystem.used.pct`.

Is there another way to filter metric data for different servers.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [April 21, 2017, 11:28am UTC](https://discuss.elastic.co/t/define-index-pattern-for-metricbeat-in-kibana/82793/4 "2017-04-21T11:28:05Z")

</div>

In case its an option for you to have different configs on each server, you can also use `fields: ...` configuration or `tags: ...` as you mentioned earlier.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2017, 11:35am UTC](https://discuss.elastic.co/t/define-index-pattern-for-metricbeat-in-kibana/82793/5 "2017-05-19T11:35:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
