# Elasticsearch indices

**URL:** <https://discuss.elastic.co/t/elasticsearch-indices/98245>\
**Category:** Elasticsearch\
**Created:** [August 24, 2017, 2:05pm UTC](https://discuss.elastic.co/t/elasticsearch-indices/98245 "2017-08-24T14:05:25Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![zen.xen](https://avatars.discourse-cdn.com/v4/letter/z/e495f1/32.png) [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Post date:** [August 24, 2017, 2:05pm UTC](https://discuss.elastic.co/t/elasticsearch-indices/98245/1 "2017-08-24T14:05:26Z")

</div>

Hello,  
I have installed ELK 5.5.x on Windows 2012 with `winlogbeat`, it works but logs in `..\Elasticsearch\data\nodes\0\indices` look like this `5uv-yuK5T4CNkTC2G7x4Mg` but they should look like this `winlogbeat-2017.08.24`. What and where should I configure to fix it?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 24, 2017, 2:20pm UTC](https://discuss.elastic.co/t/elasticsearch-indices/98245/2 "2017-08-24T14:20:48Z")

</div>

Do _not_ interact with any of the files or directories in the `path.data` (in your case the `..\Elasticsearch\data\` path). Any and all interactions with indices and snapshots should be through the API calls. Interacting with the files and directories directly will result in data corruption.

In past iterations, the index directories _were_ named the same as the index. This is no longer the case. Then as now, you should only interact with indices via API calls.

---

<div class="post-metadata">

**Author:** ![zen.xen](https://avatars.discourse-cdn.com/v4/letter/z/e495f1/32.png) [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Post date:** [August 24, 2017, 2:44pm UTC](https://discuss.elastic.co/t/elasticsearch-indices/98245/3 "2017-08-24T14:44:00Z")

</div>

Is there any tool to manage indices or how to use API calls?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 24, 2017, 3:22pm UTC](https://discuss.elastic.co/t/elasticsearch-indices/98245/4 "2017-08-24T15:22:25Z")

</div>

There's [Elasticsearch Curator](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/index.html) for managing indices, though it is strongly focused on time-series data (which `winlogbeat` generates).

Otherwise, read up on the [Indices APIs](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices.html) in the official Elasticsearch documentation.

---

<div class="post-metadata">

**Author:** ![zen.xen](https://avatars.discourse-cdn.com/v4/letter/z/e495f1/32.png) [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Post date:** [August 28, 2017, 9:17am UTC](https://discuss.elastic.co/t/elasticsearch-indices/98245/5 "2017-08-28T09:17:29Z")

</div>

Thanks for help, now I can manage indices.  
I have one more question, maybe in this thread or I can create new one, do you know any tool for alerting?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 28, 2017, 1:41pm UTC](https://discuss.elastic.co/t/elasticsearch-indices/98245/6 "2017-08-28T13:41:46Z")

</div>

If it's a different question, a new thread should be opened. That said, [Alerting](https://www.elastic.co/products/x-pack/alerting) is a part of [X-Pack](https://www.elastic.co/products/x-pack).

---

<div class="post-metadata">

**Author:** ![zen.xen](https://avatars.discourse-cdn.com/v4/letter/z/e495f1/32.png) [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Post date:** [August 28, 2017, 4:52pm UTC](https://discuss.elastic.co/t/elasticsearch-indices/98245/7 "2017-08-28T16:52:50Z")

</div>

Alerting is a paid part of X-Pack, is there something free?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 28, 2017, 5:28pm UTC](https://discuss.elastic.co/t/elasticsearch-indices/98245/8 "2017-08-28T17:28:23Z")

</div>

Writing your own queries and running them in cron? Having them yield the results every so often...

---

<div class="post-metadata">

**Author:** ![zen.xen](https://avatars.discourse-cdn.com/v4/letter/z/e495f1/32.png) [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Post date:** [August 28, 2017, 7:18pm UTC](https://discuss.elastic.co/t/elasticsearch-indices/98245/9 "2017-08-28T19:18:15Z")

</div>

thank you for suggestion

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 25, 2017, 7:18pm UTC](https://discuss.elastic.co/t/elasticsearch-indices/98245/10 "2017-09-25T19:18:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
