# Disable index rotation in logstash

**URL:** <https://discuss.elastic.co/t/disable-index-rotation-in-logstash/28988>\
**Category:** Logstash\
**Created:** [September 10, 2015, 5:44am UTC](https://discuss.elastic.co/t/disable-index-rotation-in-logstash/28988 "2015-09-10T05:44:25Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hayder\_Abbass](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hayder_abbass/32/4559_2.png) [@Hayder\_Abbass](https://discuss.elastic.co/u/Hayder_Abbass)\
**Post date:** [September 10, 2015, 5:44am UTC](https://discuss.elastic.co/t/disable-index-rotation-in-logstash/28988/1 "2015-09-10T05:44:25Z")

</div>

Hello,

By default, logstash create indices in the format logstash-YYYY.MM.DD, which essentially creates one index per day. Is it possible to disable this feature and force logstash to push data to a specific index name?

Thanks for your help 🙂

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 10, 2015, 5:46am UTC](https://discuss.elastic.co/t/disable-index-rotation-in-logstash/28988/2 "2015-09-10T05:46:48Z")

</div>

Yes, just change the `index` name in the output.

But my question would be; Why do you want to do this?

---

<div class="post-metadata">

**Author:** ![Hayder\_Abbass](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hayder_abbass/32/4559_2.png) [@Hayder\_Abbass](https://discuss.elastic.co/u/Hayder_Abbass)\
**Post date:** [September 10, 2015, 5:56am UTC](https://discuss.elastic.co/t/disable-index-rotation-in-logstash/28988/3 "2015-09-10T05:56:30Z")

</div>

Thanks for your help Mark. I had like to push all log data in one index per customer. We will normally have a maximum of 5 million records per index. Do you think it is a good idea? (I'm a total noob in ElasticSearch).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 10, 2015, 5:57am UTC](https://discuss.elastic.co/t/disable-index-rotation-in-logstash/28988/4 "2015-09-10T05:57:45Z")

</div>

No, because how are you going to age data out easily?

You're better off using time based indices!

---

<div class="post-metadata">

**Author:** ![Hayder\_Abbass](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hayder_abbass/32/4559_2.png) [@Hayder\_Abbass](https://discuss.elastic.co/u/Hayder_Abbass)\
**Post date:** [September 10, 2015, 6:16am UTC](https://discuss.elastic.co/t/disable-index-rotation-in-logstash/28988/5 "2015-09-10T06:16:24Z")

</div>

Thats an interesting point. Actually, we have to retain logs for 2 years. I'm not sure if rotating indexes every day is a good idea as we are going to have hundreds of indices per customer. Do you think it is a good idea? Also, is there a performance gain if we store indexes by day?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 10, 2015, 10:03am UTC](https://discuss.elastic.co/t/disable-index-rotation-in-logstash/28988/6 "2015-09-10T10:03:26Z")

</div>

Move to weekly/monthly instead of daily.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:29am UTC](https://discuss.elastic.co/t/disable-index-rotation-in-logstash/28988/7 "2017-07-06T05:29:31Z")

</div>


