# Filebeat custom index

**URL:** <https://discuss.elastic.co/t/filebeat-custom-index/192442>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 26, 2019, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-custom-index/192442 "2019-07-26T12:56:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![richard\_N](https://avatars.discourse-cdn.com/v4/letter/r/ecb155/32.png) [@richard\_N](https://discuss.elastic.co/u/richard_N)\
**Post date:** [July 26, 2019, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-custom-index/192442/1 "2019-07-26T12:56:23Z")

</div>

I'm running filebeat 7.2 and trying to capture some exchange logs and put them in their own custom index but they always seem to end up in the default filebeat index. Below is my filebeat.yml. I've tried setting the setup.template options to several different things with no luck. I want them to go into an index 'filebeat-exchange-\*'

filebeat.inputs:

- type: log  
enabled: true  
paths:
  - C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\Hub\Connectivity\*.LOG
  - C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\Hub\ProtocolLog\SmtpReceive\*.LOG
  - C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\Hub\ProtocolLog\SmtpSend\*.LOG
  - C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\Frontend\ProtocolLog\Connectivity\*.LOG
  - C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\Frontend\ProtocolLog\SmtpSend\*.LOG
  - C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\Frontend\ProtocolLog\SmtpReceive\*.LOG
  - C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\Mailbox\Connectivity\Delivery\*.LOG
  - C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\Mailbox\Connectivity\Submission\*.LOG
  - C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\Mailbox\ProtocolLog\SmtpReceive\Delivery\*.LOG
  - C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\Mailbox\ProtocolLog\SmtpReceive\Submission\*.LOG
  - C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\Mailbox\ProtocolLog\SmtpSend\Delivery\*.LOG
  - C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\Mailbox\ProtocolLog\SmtpSend\Submission\*.LOG

setup.template:  
name: "filebeat"  
pattern: "filebeat-\*"  
overwrite: true

output.elasticsearch:  
hosts:  
- es01:9200  
- es02:9200  
- es03.9200  
index: "filebeat-exchange-%{[agent.version]}-%{+yyyy.MM.dd}"

tags: ["mail", "exchange"]

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [July 26, 2019, 3:41pm UTC](https://discuss.elastic.co/t/filebeat-custom-index/192442/2 "2019-07-26T15:41:37Z")

</div>

I think ILM may be the indirect cause here... With the 7.x versions ILM is enabled (says auto), so the default for the ilm\_rollover\_alias is "filebeat", and that field takes precidence over the index name.

Check the logs for the first startup, see if it tried to do things with "lifecycle management".

To verify if it's ILM confusion, you can set ilm\_enabled: false.

We are sending exchange logs thru Logstash because there are a lot of fields to parse and process.... and most of their logs have a different format and the thought of common fields names is complete foreign to M$.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2019, 3:41pm UTC](https://discuss.elastic.co/t/filebeat-custom-index/192442/3 "2019-08-23T15:41:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
