# Elasticsearch index name question

**URL:** <https://discuss.elastic.co/t/elasticsearch-index-name-question/22262>\
**Category:** Elasticsearch\
**Created:** [February 19, 2015, 10:59am UTC](https://discuss.elastic.co/t/elasticsearch-index-name-question/22262 "2015-02-19T10:59:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Silvana\_Vezzoli](https://avatars.discourse-cdn.com/v4/letter/s/59ef9b/32.png) [@Silvana\_Vezzoli](https://discuss.elastic.co/u/Silvana_Vezzoli)\
**Post date:** [February 19, 2015, 10:59am UTC](https://discuss.elastic.co/t/elasticsearch-index-name-question/22262/1 "2015-02-19T10:59:39Z")

</div>

I use a Monitoring Framework designed as a solution to monitor  
heterogeneous networks and systems in terms of services (platforms,  
applications for TELCO systems).

This framework collects in synchronous way the required data from several  
devices, it stores them in a Mongo Data Base and then transfers all stored  
collections from MongoDB to Elasticsearch via river-mongodb plugin.

We can have a huge amount of data stored in a single index of  
Elasticsearch, for example, about 5.2 millions of documents can be  
collected in a single MongoDB collection for only 8 hours of monitoring and  
so the number of documents in a single index grows rapidly.

At present, I have installed on Centos 6.5 server an Elasticsearch Cluster  
configuration with one node and five indices but only one index for all  
synchronous data.

My problem is to be able to create different indices in Elasticsearch where  
I can share the synchronous data, and so I would like to know if it is  
possible to create an index name with a timestamp appended to it, like so  
Logstash uses the timestamp from an event to derive the related  
Elasticsearch index name.

Some idea, suggestion, help?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/37bb3713-56d9-443c-b3a5-9056092b958d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/37bb3713-56d9-443c-b3a5-9056092b958d%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 19, 2015, 10:01pm UTC](https://discuss.elastic.co/t/elasticsearch-index-name-question/22262/2 "2015-02-19T22:01:34Z")

</div>

This is possible but not automatically within ES.  
LS knows it needs to switch to a new index at 0000UTC, you need to find a  
way to get the river or some other code to do this.

On 19 February 2015 at 21:59, Silvana Vezzoli [silvana.vezzoli@gmail.com](mailto:silvana.vezzoli@gmail.com)  
wrote:

> I use a Monitoring Framework designed as a solution to monitor  
> heterogeneous networks and systems in terms of services (platforms,  
> applications for TELCO systems).
> 
> This framework collects in synchronous way the required data from several  
> devices, it stores them in a Mongo Data Base and then transfers all stored  
> collections from MongoDB to Elasticsearch via river-mongodb plugin.
> 
> We can have a huge amount of data stored in a single index of  
> Elasticsearch, for example, about 5.2 millions of documents can be  
> collected in a single MongoDB collection for only 8 hours of monitoring and  
> so the number of documents in a single index grows rapidly.
> 
> At present, I have installed on Centos 6.5 server an Elasticsearch Cluster  
> configuration with one node and five indices but only one index for all  
> synchronous data.
> 
> My problem is to be able to create different indices in Elasticsearch  
> where I can share the synchronous data, and so I would like to know if it  
> is possible to create an index name with a timestamp appended to it, like  
> so Logstash uses the timestamp from an event to derive the related  
> Elasticsearch index name.
> 
> Some idea, suggestion, help?
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/37bb3713-56d9-443c-b3a5-9056092b958d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/37bb3713-56d9-443c-b3a5-9056092b958d%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/37bb3713-56d9-443c-b3a5-9056092b958d%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/37bb3713-56d9-443c-b3a5-9056092b958d%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEYi1X-cqwvKHdQETdZtWOTOUmwPWayYWKiNwmo6JXETno0%3DEg%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEYi1X-cqwvKHdQETdZtWOTOUmwPWayYWKiNwmo6JXETno0%3DEg%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Silvana\_Vezzoli](https://avatars.discourse-cdn.com/v4/letter/s/59ef9b/32.png) [@Silvana\_Vezzoli](https://discuss.elastic.co/u/Silvana_Vezzoli)\
**Post date:** [February 23, 2015, 1:35pm UTC](https://discuss.elastic.co/t/elasticsearch-index-name-question/22262/3 "2015-02-23T13:35:30Z")

</div>

Thanks, Mark.  
But supposing that I find the way to get the river to filter the documents  
to be indexed in ES on a daily base (for example), my question is if it is  
possible to create a dynamic index name in Elasticsearch based on some  
variable value (curl -XPUT '[http://localhost:9200/](http://localhost:9200/)  
${elasticsearch.index.name}/').  
It seems that at present itsn't possible, do it could be a new  
Elasticsearch feature?

Il giorno giovedì 19 febbraio 2015 23:02:12 UTC+1, Mark Walkom ha scritto:

> This is possible but not automatically within ES.  
> LS knows it needs to switch to a new index at 0000UTC, you need to find a  
> way to get the river or some other code to do this.
> 
> On 19 February 2015 at 21:59, Silvana Vezzoli \<[silvana...@gmail.com](mailto:silvana...@gmail.com)  
> \<javascript:\>\> wrote:
> 
> > I use a Monitoring Framework designed as a solution to monitor  
> > heterogeneous networks and systems in terms of services (platforms,  
> > applications for TELCO systems).
> > 
> > This framework collects in synchronous way the required data from  
> > several devices, it stores them in a Mongo Data Base and then transfers all  
> > stored collections from MongoDB to Elasticsearch via river-mongodb plugin.
> > 
> > We can have a huge amount of data stored in a single index of  
> > Elasticsearch, for example, about 5.2 millions of documents can be  
> > collected in a single MongoDB collection for only 8 hours of monitoring and  
> > so the number of documents in a single index grows rapidly.
> > 
> > At present, I have installed on Centos 6.5 server an Elasticsearch  
> > Cluster configuration with one node and five indices but only one index for  
> > all synchronous data.
> > 
> > My problem is to be able to create different indices in Elasticsearch  
> > where I can share the synchronous data, and so I would like to know if it  
> > is possible to create an index name with a timestamp appended to it, like  
> > so Logstash uses the timestamp from an event to derive the related  
> > Elasticsearch index name.
> > 
> > Some idea, suggestion, help?
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/37bb3713-56d9-443c-b3a5-9056092b958d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/37bb3713-56d9-443c-b3a5-9056092b958d%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/37bb3713-56d9-443c-b3a5-9056092b958d%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/37bb3713-56d9-443c-b3a5-9056092b958d%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/eca8a3b0-dbf4-46f6-894f-1b73458335be%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/eca8a3b0-dbf4-46f6-894f-1b73458335be%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 23, 2015, 8:35pm UTC](https://discuss.elastic.co/t/elasticsearch-index-name-question/22262/4 "2015-02-23T20:35:42Z")

</div>

You could use index templates -

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

On 24 February 2015 at 00:35, svezzoli [silvana.vezzoli@gmail.com](mailto:silvana.vezzoli@gmail.com) wrote:

> Thanks, Mark.  
> But supposing that I find the way to get the river to filter the documents  
> to be indexed in ES on a daily base (for example), my question is if it is  
> possible to create a dynamic index name in Elasticsearch based on some  
> variable value (curl -XPUT '[http://localhost:9200/$](http://localhost:9200/$){  
> elasticsearch.index.name}/').  
> It seems that at present itsn't possible, do it could be a new  
> Elasticsearch feature?
> 
> Il giorno giovedì 19 febbraio 2015 23:02:12 UTC+1, Mark Walkom ha scritto:
> 
> > This is possible but not automatically within ES.  
> > LS knows it needs to switch to a new index at 0000UTC, you need to find a  
> > way to get the river or some other code to do this.
> > 
> > On 19 February 2015 at 21:59, Silvana Vezzoli [silvana...@gmail.com](mailto:silvana...@gmail.com)  
> > wrote:
> > 
> > > I use a Monitoring Framework designed as a solution to monitor  
> > > heterogeneous networks and systems in terms of services (platforms,  
> > > applications for TELCO systems).
> > > 
> > > This framework collects in synchronous way the required data from  
> > > several devices, it stores them in a Mongo Data Base and then transfers all  
> > > stored collections from MongoDB to Elasticsearch via river-mongodb plugin.
> > > 
> > > We can have a huge amount of data stored in a single index of  
> > > Elasticsearch, for example, about 5.2 millions of documents can be  
> > > collected in a single MongoDB collection for only 8 hours of monitoring and  
> > > so the number of documents in a single index grows rapidly.
> > > 
> > > At present, I have installed on Centos 6.5 server an Elasticsearch  
> > > Cluster configuration with one node and five indices but only one index for  
> > > all synchronous data.
> > > 
> > > My problem is to be able to create different indices in Elasticsearch  
> > > where I can share the synchronous data, and so I would like to know if it  
> > > is possible to create an index name with a timestamp appended to it, like  
> > > so Logstash uses the timestamp from an event to derive the related  
> > > Elasticsearch index name.
> > > 
> > > Some idea, suggestion, help?
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> > > msgid/elasticsearch/37bb3713-56d9-443c-b3a5-9056092b958d%  
> > > [40googlegroups.com](http://40googlegroups.com)  
> > > [https://groups.google.com/d/msgid/elasticsearch/37bb3713-56d9-443c-b3a5-9056092b958d%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/37bb3713-56d9-443c-b3a5-9056092b958d%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/eca8a3b0-dbf4-46f6-894f-1b73458335be%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/eca8a3b0-dbf4-46f6-894f-1b73458335be%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/eca8a3b0-dbf4-46f6-894f-1b73458335be%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/eca8a3b0-dbf4-46f6-894f-1b73458335be%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEYi1X8YaFvF%2Bbz-LE8%3D1q%3DpTCU1PnaDmUUgxn4B2fBf-MaKzg%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEYi1X8YaFvF%2Bbz-LE8%3D1q%3DpTCU1PnaDmUUgxn4B2fBf-MaKzg%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:30am UTC](https://discuss.elastic.co/t/elasticsearch-index-name-question/22262/5 "2017-07-06T00:30:40Z")

</div>


