# Elastic Agent configuration for creating new index based on kubernetes namespace

**URL:** <https://discuss.elastic.co/t/elastic-agent-configuration-for-creating-new-index-based-on-kubernetes-namespace/314886>\
**Category:** Elastic Agent\
**Tags:** filebeat\
**Created:** [September 21, 2022, 5:47pm UTC](https://discuss.elastic.co/t/elastic-agent-configuration-for-creating-new-index-based-on-kubernetes-namespace/314886 "2022-09-21T17:47:32Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![umesh2020](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/umesh2020/32/126038_2.png) [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Post date:** [September 21, 2022, 5:47pm UTC](https://discuss.elastic.co/t/elastic-agent-configuration-for-creating-new-index-based-on-kubernetes-namespace/314886/1 "2022-09-21T17:47:32Z")

</div>

Hi  
In filebeat configuration, I could use the following config to create a separate index per kubernetes namespace.

```auto
    output.elasticsearch:
      indices:
        - index: '%{[kubernetes.namespace]}-%{[agent.version]}-%{+yyyy.MM.dd}'
          when:
            or:
            - equals.kubernetes.namespace: "namespace1"
            - equals.kubernetes.namespace: "namespace2"

```

How do I achieve the same result using ElasticAgent ? I am using version 7.17.5 of Kibana.

Appreciate your help.

---

<div class="post-metadata">

**Author:** ![Tetiana\_Kravchenko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tetiana_kravchenko/32/102683_2.png) [@Tetiana\_Kravchenko](https://discuss.elastic.co/u/Tetiana_Kravchenko)\
**Post date:** [September 22, 2022, 1:24pm UTC](https://discuss.elastic.co/t/elastic-agent-configuration-for-creating-new-index-based-on-kubernetes-namespace/314886/2 "2022-09-22T13:24:29Z")

</div>

Hi @umesh2020

Are you using [standalone elastic-agent](https://www.elastic.co/guide/en/fleet/current/running-on-kubernetes-standalone.html) ? if yes - I think you should be able to define an output - similar as defined [here](https://github.com/elastic/elastic-agent/blob/main/deploy/kubernetes/elastic-agent-standalone-kubernetes.yaml#L11-L18), and then [`use_output` setting](https://github.com/elastic/elastic-agent/blob/main/deploy/kubernetes/elastic-agent-standalone-kubernetes.yaml#L34)

For fleet managed elastic-agent, I think you should be able to define another output with desired configuration and use this output for added integration (under Advanced options)

---

<div class="post-metadata">

**Author:** ![umesh2020](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/umesh2020/32/126038_2.png) [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Post date:** [September 22, 2022, 1:32pm UTC](https://discuss.elastic.co/t/elastic-agent-configuration-for-creating-new-index-based-on-kubernetes-namespace/314886/3 "2022-09-22T13:32:35Z")

</div>

> [@Tetiana\_Kravchenko](#):
>
> integration

I am using fleet managed elastic-agent. Can you point me to some relevant links ?

---

<div class="post-metadata">

**Author:** ![umesh2020](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/umesh2020/32/126038_2.png) [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Post date:** [September 22, 2022, 1:35pm UTC](https://discuss.elastic.co/t/elastic-agent-configuration-for-creating-new-index-based-on-kubernetes-namespace/314886/4 "2022-09-22T13:35:45Z")

</div>

> [@Tetiana\_Kravchenko](#):
>
> output

Also, my namespaces are dynamically created, so is there a REST API that I can use to dynamically define these outputs ? In filebeat, I used to update the configuration using helm whenever a new environment is created.

---

<div class="post-metadata">

**Author:** ![Tetiana\_Kravchenko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tetiana_kravchenko/32/102683_2.png) [@Tetiana\_Kravchenko](https://discuss.elastic.co/u/Tetiana_Kravchenko)\
**Post date:** [September 22, 2022, 1:57pm UTC](https://discuss.elastic.co/t/elastic-agent-configuration-for-creating-new-index-based-on-kubernetes-namespace/314886/5 "2022-09-22T13:57:22Z")

</div>

You can check [output setting](https://www.elastic.co/guide/en/fleet/7.17/fleet-settings.html#output-settings) and add desired configuration under `Elasticsearch output configuration`

I am not sure if in version 7.17 there was an option to create another output - seems it was added in [8.x](https://www.elastic.co/guide/en/fleet/8.4/fleet-settings.html#output-settings), so adjusting the default output should be enough.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 20, 2022, 1:57pm UTC](https://discuss.elastic.co/t/elastic-agent-configuration-for-creating-new-index-based-on-kubernetes-namespace/314886/6 "2022-10-20T13:57:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
