# Filebeat 8.17.10 disable template data\_stream

**URL:** <https://discuss.elastic.co/t/filebeat-8-17-10-disable-template-data-stream/383429>\
**Category:** Logs\
**Created:** [November 13, 2025, 5:09pm UTC](https://discuss.elastic.co/t/filebeat-8-17-10-disable-template-data-stream/383429 "2025-11-13T17:09:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![almteref](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/almteref/32/97409_2.png) [@almteref](https://discuss.elastic.co/u/almteref)\
**Post date:** [November 13, 2025, 5:09pm UTC](https://discuss.elastic.co/t/filebeat-8-17-10-disable-template-data-stream/383429/1 "2025-11-13T17:09:20Z")

</div>

Hi

I have filebae version 8.17.10 running on k8s

And send logs to elasticsearch with the same version

This is my configuration

filebeat:  
inputs:

- type: filestream  
id: vouchers-logs-stream  
paths:
  - /path/to/logs/\*.log  
json:  
keys\_under\_root: true  
add\_error\_key: true  
overwrite\_keys: true  
message\_key: message  
parsers:
  - ndjson:  
target: ""  
add\_error\_key: true  
output:  
elasticsearch:  
hosts: ["..."]  
username: "..."  
password: "..."  
index: voucher-app-logs-%{[agent.version]}-%{+yyyy.MM.dd}  
setup:  
template:  
name: "voucher-app-logs"  
pattern: "voucher-app-logs\*"  
overwrite: false  
ilm:  
enabled: true  
policy\_name: "voucher-app-logs-lifecycle-policy"

When I start it I see in kibana index management the created template enabled data stream i want to disable it can i do it from filebeat configuration not from kibana ?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 14, 2025, 1:54am UTC](https://discuss.elastic.co/t/filebeat-8-17-10-disable-template-data-stream/383429/2 "2025-11-14T01:54:14Z")

</div>

Hi @almteref

I don't think you can do exactly what you want to do through filebeat, if I understand you wanted filebeat to generate the template, but you want to change the data stream setting. I don't think you can do that..

You can load your own template if you like see here

> **[Load the Elasticsearch index template | Beats](https://www.elastic.co/docs/reference/beats/filebeat/filebeat-template#load-custom-template)**
>
> Elasticsearch uses index templates to define: Settings that control the behavior of your data stream and backing indices. The settings include the lifecycle...

---

<div class="post-metadata">

**Author:** ![almteref](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/almteref/32/97409_2.png) [@almteref](https://discuss.elastic.co/u/almteref)\
**Post date:** [November 18, 2025, 3:08am UTC](https://discuss.elastic.co/t/filebeat-8-17-10-disable-template-data-stream/383429/3 "2025-11-18T03:08:07Z")

</div>

What i want to create index by the filebeat with this name : events-listners-k8s-pp-2025.11.18-00001

And apply the ilm and template

This works in the elasticsearch and filebeat version 7.x

But with version 8.x not working now , in ilm there is no pattern setting %{now/d}-00001

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 18, 2025, 3:55am UTC](https://discuss.elastic.co/t/filebeat-8-17-10-disable-template-data-stream/383429/4 "2025-11-18T03:55:08Z")

</div>

Yes I pretty sure I know it you want...

No pretty sure you're not going to be able to do it. How you want... Metricbeat defaults to data streams now

You can also just set up a data stream and specify the ILM it to roll over everyday AND the backing index will have the same format.

Or just load your own template with your own automaton.

> ## [Load your own index template](https://www.elastic.co/docs/reference/beats/filebeat/filebeat-template#load-custom-template)
> 
> To load your own index template, set the following options:
> 
> ```auto
> setup.template.name: "your_template_name"
> setup.template.fields: "path/to/fields.yml"
> 
> ```
> 
> If the template already exists, it’s not overwritten unless you configure Filebeat to do so.
> 
> You can load templates for both data streams and indices

You could also just load a template via the REST API with your own automation.

That is my suggestion at this point.
