# Dynamic value substitution for date is NULL

**URL:** <https://discuss.elastic.co/t/dynamic-value-substitution-for-date-is-null/293144>\
**Category:** Logstash\
**Tags:** ilm-index-lifecycle-management\
**Created:** [December 29, 2021, 5:01pm UTC](https://discuss.elastic.co/t/dynamic-value-substitution-for-date-is-null/293144 "2021-12-29T17:01:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![4art4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/4art4/32/98919_2.png) [@4art4](https://discuss.elastic.co/u/4art4)\
**Post date:** [December 29, 2021, 5:01pm UTC](https://discuss.elastic.co/t/dynamic-value-substitution-for-date-is-null/293144/1 "2021-12-29T17:01:16Z")

</div>

To quote [the docs](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html):

```auto
Writing to different indices: best practices
You cannot use dynamic variable substitution when ilm_enabled is true and when using ilm_rollover_alias.

```

So what I think I want to do is make each new batch of documents be ingested in a new index, where the name starts the same. Eg:

logstash-2021.12.10  
logstash-2021.12.11  
logstash-2021.12.12

The example output config of

```auto
index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"

```

worked at first, creating "logstash-2021.12.10-000001". Im not 100% sure where the "-000001" came from, but that does not bug me too much.

but this no longer works. It creates the index of a literal "%{[@metadata][beat]}-%{[@metadata][version]}-".

**Notice that the date part is entirely missing.**

I found the able about ilm, and attempted to turn it off with:

```auto
POST /_ilm/stop

```

So... first: dont I need dynamic index names for ilm? And what setting is preventing this?

---

<div class="post-metadata">

**Author:** ![4art4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/4art4/32/98919_2.png) [@4art4](https://discuss.elastic.co/u/4art4)\
**Post date:** [December 29, 2021, 5:07pm UTC](https://discuss.elastic.co/t/dynamic-value-substitution-for-date-is-null/293144/2 "2021-12-29T17:07:36Z")

</div>

OK, I figured out the missing date part... My filter included:

```auto
remove_field => ["message", "@timestamp", "@version", "host"]

```

I was trying to have 'clean data'. lol!

Ill leave this here incase someone else needs to see my error.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 26, 2022, 5:07pm UTC](https://discuss.elastic.co/t/dynamic-value-substitution-for-date-is-null/293144/3 "2022-01-26T17:07:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
