# Filebeat 6.4.3 config issue

**URL:** <https://discuss.elastic.co/t/filebeat-6-4-3-config-issue/156366>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 12, 2018, 11:33pm UTC](https://discuss.elastic.co/t/filebeat-6-4-3-config-issue/156366 "2018-11-12T23:33:45Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![sunny1](https://avatars.discourse-cdn.com/v4/letter/s/c0e974/32.png) [@sunny1](https://discuss.elastic.co/u/sunny1)\
**Post date:** [November 12, 2018, 11:33pm UTC](https://discuss.elastic.co/t/filebeat-6-4-3-config-issue/156366/1 "2018-11-12T23:33:45Z")

</div>

I am installing filebeat 6.4.3. For yml file i have custom index name. When i start filebeat it says setup.template.name and setup.template.patter have to be set if index name is modified. I am not sure how to pass these fields in yml file. Below is the yml config for me: Can someone please help me fix this.

```
#=========================== Filebeat inputs =============================

filebeat.inputs:

- type: log
  json.keys_under_root: true
  json.add_error_key: true

  enabled: true

  paths:
    - C:\LMSTestResults\LMS_Results\SunnyTestResults*.json

  fields:
   document_type: "sunny_mongo_results"
   

#============================= Filebeat modules ===============================

filebeat.config.modules:
  # Glob pattern for configuration loading
  path: ${path.config}/modules.d/*.yml

  # Set to true to enable config reloading
  reload.enabled: false

  # Period on which files under path should be checked for changes
  #reload.period: 10s

#==================== Elasticsearch template setting ==========================

setup.template.settings:
  index.number_of_shards: 3
  #index.codec: best_compression
  #_source.enabled: false

#============================== Kibana =====================================

# Starting with Beats version 6.0.0, the dashboards are loaded via the Kibana API.
# This requires a Kibana endpoint configuration.
setup.kibana:

  host: "localhost:5601"

#================================ Outputs =====================================

# Configure what output to use when sending the data collected by the beat.

#-------------------------- Elasticsearch output ------------------------------
output.elasticsearch:
  # Array of hosts to connect to.
  hosts: ["localhost:9200"]
  index: "%{[fields][document_type]}"
  setup.template.enabled: false
  setup.template.name: ""
  setup.template.pattern: "*"

#================================ Logging =====================================

# Sets log level. The default log level is info.
# Available log levels are: error, warning, info, debug
logging.level: debug
```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 13, 2018, 12:41pm UTC](https://discuss.elastic.co/t/filebeat-6-4-3-config-issue/156366/2 "2018-11-13T12:41:58Z")

</div>

You have to add `name` and `pattern` to the `setup.template` namespace. See the `filebeat.reference.yml` for examples.

---

<div class="post-metadata">

**Author:** ![sunny1](https://avatars.discourse-cdn.com/v4/letter/s/c0e974/32.png) [@sunny1](https://discuss.elastic.co/u/sunny1)\
**Post date:** [November 14, 2018, 12:38am UTC](https://discuss.elastic.co/t/filebeat-6-4-3-config-issue/156366/3 "2018-11-14T00:38:04Z")

</div>

Thanks for ur reply, but i am not able to get what i need to set for pattern and template. I looked at examples but most examples had constant for index which i dont have so not able to get correct syntax.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 14, 2018, 3:32pm UTC](https://discuss.elastic.co/t/filebeat-6-4-3-config-issue/156366/4 "2018-11-14T15:32:01Z")

</div>

Filebeat provisions the template mapping on startup. That is, they indeed quire some constant prefix.

Alternatively you can use `filebeat export config`, modify the template mapping (json file), and use the `setup.template.json...` settings to have filebeat load you template.

See [Elasticsearch Index Templates](https://www.elastic.co/guide/en/elasticsearch/reference/6.5/indices-templates.html) docs to learn more about templates.  
Also check out docs on [manual loading the template](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html#load-template-manually).

---

<div class="post-metadata">

**Author:** ![sunny1](https://avatars.discourse-cdn.com/v4/letter/s/c0e974/32.png) [@sunny1](https://discuss.elastic.co/u/sunny1)\
**Post date:** [November 14, 2018, 6:14pm UTC](https://discuss.elastic.co/t/filebeat-6-4-3-config-issue/156366/5 "2018-11-14T18:14:51Z")

</div>

Thanks Steffens.

I tried to give constant for my index as below but still same error to set name and pattern.

```
output.elasticsearch:
  # Array of hosts to connect to.
  hosts: ["localhost:9200"]
  index: "SG-%{[fields][document_type]}"
  setup.template.enabled: false
  setup.template.name: "SG"
  setup.template.pattern: "SG-*"
```

---

<div class="post-metadata">

**Author:** ![sunny1](https://avatars.discourse-cdn.com/v4/letter/s/c0e974/32.png) [@sunny1](https://discuss.elastic.co/u/sunny1)\
**Post date:** [November 14, 2018, 6:32pm UTC](https://discuss.elastic.co/t/filebeat-6-4-3-config-issue/156366/6 "2018-11-14T18:32:43Z")

</div>

I also tried to set template manually using below command but same error

`.\filebeat.exe setup --template -E output.logstash.enabled=false -E 'output.elasticsearch.hosts=["localhost:9200"]'`

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 15, 2018, 3:22pm UTC](https://discuss.elastic.co/t/filebeat-6-4-3-config-issue/156366/7 "2018-11-15T15:22:46Z")

</div>

Do you have any error message(s) to share with us?

---

<div class="post-metadata">

**Author:** ![sunny1](https://avatars.discourse-cdn.com/v4/letter/s/c0e974/32.png) [@sunny1](https://discuss.elastic.co/u/sunny1)\
**Post date:** [November 19, 2018, 7:03pm UTC](https://discuss.elastic.co/t/filebeat-6-4-3-config-issue/156366/8 "2018-11-19T19:03:13Z")

</div>

Sorry no errors, but all it ask is to set pattern and name which i already did.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 20, 2018, 10:26am UTC](https://discuss.elastic.co/t/filebeat-6-4-3-config-issue/156366/9 "2018-11-20T10:26:28Z")

</div>

The indentation seems wrong. The `setup` settings are not part of the elasticsearch output:

```auto
setup.template.enabled: false
setup.template.name: "SG"
setup.template.pattern: "SG-*"

output.elasticsearch:
  # Array of hosts to connect to.
  hosts: ["localhost:9200"]
  index: "SG-%{[fields][document_type]}"

```

---

<div class="post-metadata">

**Author:** ![sunny1](https://avatars.discourse-cdn.com/v4/letter/s/c0e974/32.png) [@sunny1](https://discuss.elastic.co/u/sunny1)\
**Post date:** [November 21, 2018, 12:51am UTC](https://discuss.elastic.co/t/filebeat-6-4-3-config-issue/156366/10 "2018-11-21T00:51:09Z")

</div>

Thanks Steffens, some of the examples i had seen had name and pattern being part of elasticsearch output.

But as you mentioned did the change and it helped.  
Thanks again,  
Sunny

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 19, 2018, 12:51am UTC](https://discuss.elastic.co/t/filebeat-6-4-3-config-issue/156366/11 "2018-12-19T00:51:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
