# Es index name issue coming from Logstash

**URL:** <https://discuss.elastic.co/t/es-index-name-issue-coming-from-logstash/147868>\
**Category:** Logstash\
**Created:** [September 9, 2018, 9:13pm UTC](https://discuss.elastic.co/t/es-index-name-issue-coming-from-logstash/147868 "2018-09-09T21:13:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![prasket](https://avatars.discourse-cdn.com/v4/letter/p/d9b06d/32.png) [@prasket](https://discuss.elastic.co/u/prasket)\
**Post date:** [September 9, 2018, 9:13pm UTC](https://discuss.elastic.co/t/es-index-name-issue-coming-from-logstash/147868/1 "2018-09-09T21:13:01Z")

</div>

Hello - I am trying to extend my Elastic Stack to include my pfsense logs. Right now Logstash is working with beats setup and I have Filebeat on all my instances. I have added my new inputs for syslog and logs are coming in but the index names are funky due to what I am guessing is them not having the arguments replaced. Here is the new syslog index name.

```
%{[@metadata][beat]}-2018.09.09

```

Below is my output config which came from the Elastic website documentation on setting up Logstash and Filebeat.

```
output {
 elasticsearch {
  hosts => "es.prasket.home"
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
       }
}

```

Any tips or suggestions on how to get the index name's to be meaningful while using Filebeat?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 7, 2018, 9:20pm UTC](https://discuss.elastic.co/t/es-index-name-issue-coming-from-logstash/147868/2 "2018-10-07T21:20:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
