# Does Filebeat plan to support Data Streams?

**URL:** <https://discuss.elastic.co/t/does-filebeat-plan-to-support-data-streams/296851>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 10, 2022, 2:07pm UTC](https://discuss.elastic.co/t/does-filebeat-plan-to-support-data-streams/296851 "2022-02-10T14:07:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![brsolomon](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@brsolomon](https://discuss.elastic.co/u/brsolomon)\
**Post date:** [February 10, 2022, 2:07pm UTC](https://discuss.elastic.co/t/does-filebeat-plan-to-support-data-streams/296851/1 "2022-02-10T14:07:56Z")

</div>

Does Filebeat plan to support Data Streams, and if so, what is the expected development timeline?

Per docs,

> Prior to Elasticsearch 7.9, you’d typically use an [index alias with a write index](https://www.elastic.co/guide/en/elasticsearch/reference/current/getting-started-index-lifecycle-management.html#manage-time-series-data-without-data-streams) to manage time series data. Data streams replace this functionality, require less maintenance, and automatically integrate with [data tiers](https://www.elastic.co/guide/en/elasticsearch/reference/current/data-tiers.html).

Yet as of 7.17.x, Filebeat still seems to only offer the option to use an index alias with daily indices.

(If I am misinterpreting this and there is some way to configure filebeat.yml for Data Streams, please let me know. Currently running `filebeat setup --index-management` does not seem to be configurable to support `data_stream: {}` in the resulting index template.)

Related: [Filebeat and Data stream](https://discuss.elastic.co/t/filebeat-and-data-stream/253841)

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [February 10, 2022, 2:15pm UTC](https://discuss.elastic.co/t/does-filebeat-plan-to-support-data-streams/296851/2 "2022-02-10T14:15:38Z")

</div>

From 8.0 all Beats send events to data streams.

If you want to use data streams in 7.17, you can edit the index template to add `"data_stream": {}` and load it manually. Then disable ILM and set `output.elasticsearch.index` to the name of the data stream.

---

<div class="post-metadata">

**Author:** ![brsolomon](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@brsolomon](https://discuss.elastic.co/u/brsolomon)\
**Post date:** [February 10, 2022, 2:24pm UTC](https://discuss.elastic.co/t/does-filebeat-plan-to-support-data-streams/296851/3 "2022-02-10T14:24:14Z")

</div>

> [@kvch](#):
>
> you can edit the index template to add `"data_stream": {}` and load it manually

To be clear do you mean a `PUT /_template/<index-template>` where the request body includes the entire existing index template plus `data_stream: {}` added? Or does `PUT /_template/<index-template>` support a partial-update (PATCH) where I can just add that single field?

---

<div class="post-metadata">

**Author:** ![brsolomon](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@brsolomon](https://discuss.elastic.co/u/brsolomon)\
**Post date:** [February 10, 2022, 2:33pm UTC](https://discuss.elastic.co/t/does-filebeat-plan-to-support-data-streams/296851/4 "2022-02-10T14:33:20Z")

</div>

Answering my own question regarding partial updates: appears the answer is [no](https://github.com/elastic/elasticsearch/issues/57499).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 10, 2022, 4:34pm UTC](https://discuss.elastic.co/t/does-filebeat-plan-to-support-data-streams/296851/5 "2022-03-10T16:34:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
