# Filebeat Index Name Pattern - timestamp

**URL:** <https://discuss.elastic.co/t/filebeat-index-name-pattern-timestamp/296255>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 4, 2022, 6:35am UTC](https://discuss.elastic.co/t/filebeat-index-name-pattern-timestamp/296255 "2022-02-04T06:35:08Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![danielc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielc/32/78486_2.png) [@danielc](https://discuss.elastic.co/u/danielc)\
**Post date:** [February 4, 2022, 6:35am UTC](https://discuss.elastic.co/t/filebeat-index-name-pattern-timestamp/296255/1 "2022-02-04T06:35:08Z")

</div>

1. Is `%{+yyyy.MM.dd}` the system time or log file timestamp?  
[Configure the Elasticsearch output | Filebeat Reference [7.10] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/7.10/elasticsearch-output.html)

```auto
output.elasticsearch:
  hosts: ["http://localhost:9200"]
  index: "%{[fields.log_type]}-%{[agent.version]}-%{+yyyy.MM.dd}" 

```

1. What's the difference between `YYYY` and `yyyy`?

> I've got answer for this. [https://docs.oracle.com/javase/8/docs/api/java/time/format/DateTimeFormatter.html](https://docs.oracle.com/javase/8/docs/api/java/time/format/DateTimeFormatter.html)  
> YYYY - week-based-year  
> yyyy - year-of-era

---

<div class="post-metadata">

**Author:** ![danielc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielc/32/78486_2.png) [@danielc](https://discuss.elastic.co/u/danielc)\
**Post date:** [February 4, 2022, 7:42am UTC](https://discuss.elastic.co/t/filebeat-index-name-pattern-timestamp/296255/2 "2022-02-04T07:42:47Z")

</div>

> **[Change the index name | Filebeat Reference \[7.10\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/7.10/change-index-name.html)**

`Filebeat uses time series indices, by default, when index lifecycle management is disabled or unsupported. The indices are named filebeat-7.10.2-yyyy.MM.dd, where yyyy.MM.dd is the date when the events were indexed. `

What does this mean?

Scenario:  
When Filebeat starts, Elasticsearch generates a few indices like `filebeat-7.10.2-2022.01.30`, `filebeat-7.10.2-2022.01.31`, `filebeat-7.10.2-2022.02.01` at the same time. How does it happen?

---

<div class="post-metadata">

**Author:** ![danielc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielc/32/78486_2.png) [@danielc](https://discuss.elastic.co/u/danielc)\
**Post date:** [February 7, 2022, 6:53pm UTC](https://discuss.elastic.co/t/filebeat-index-name-pattern-timestamp/296255/3 "2022-02-07T18:53:37Z")

</div>

`Filebeat uses time series indices, by default, when index lifecycle management is disabled or unsupported. The indices are named filebeat-7.10.2-yyyy.MM.dd, where yyyy.MM.dd is the date when the events were indexed.`

Can anybody elaborate `where yyyy.MM.dd is the date when the events were indexed`?  
Is `yyyy.MM.dd` the same as system date?

---

<div class="post-metadata">

**Author:** ![danielc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielc/32/78486_2.png) [@danielc](https://discuss.elastic.co/u/danielc)\
**Post date:** [February 24, 2022, 4:56pm UTC](https://discuss.elastic.co/t/filebeat-index-name-pattern-timestamp/296255/4 "2022-02-24T16:56:33Z")

</div>

Is there an Elastic developer in this forum?  
I think a developer may know the answer of this question.

---

<div class="post-metadata">

**Author:** ![danielc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielc/32/78486_2.png) [@danielc](https://discuss.elastic.co/u/danielc)\
**Post date:** [February 25, 2022, 1:06am UTC](https://discuss.elastic.co/t/filebeat-index-name-pattern-timestamp/296255/5 "2022-02-25T01:06:21Z")

</div>

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /logs/access_log.*.log

output.elasticsearch:
  hosts: ["http://localhost:9200"]
  index: "filebeat-%{[agent.version]}-%{+yyyy.MM.dd}"

```

When Filebeat starts, Elasticsearch generates a few indices like filebeat-7.10.2-2022.01.30, filebeat-7.10.2-2022.01.31, filebeat-7.10.2-2022.02.01 at the same time. How does it happen?

---

<div class="post-metadata">

**Author:** ![linuxxin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/linuxxin/32/100602_2.png) [@linuxxin](https://discuss.elastic.co/u/linuxxin)\
**Post date:** [February 25, 2022, 7:59am UTC](https://discuss.elastic.co/t/filebeat-index-name-pattern-timestamp/296255/6 "2022-02-25T07:59:36Z")

</div>

output.Elasticsearch:

hosts: ["192.168.0.12:9200"]

enabled: true

index: "test-1-%{[agent.version]}-%{+yyyy.MM.dd}"

setup.template.name: "test-1"

setup.template.pattern: "test-1-\*"

setup.template.overwrit: true

setup.template.enabled: true

setup.ilm.enabled: false

---

<div class="post-metadata">

**Author:** ![danielc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielc/32/78486_2.png) [@danielc](https://discuss.elastic.co/u/danielc)\
**Post date:** [February 25, 2022, 9:59pm UTC](https://discuss.elastic.co/t/filebeat-index-name-pattern-timestamp/296255/7 "2022-02-25T21:59:30Z")

</div>

I've got:  
setup.template.enabled: false

---

<div class="post-metadata">

**Author:** ![danielc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielc/32/78486_2.png) [@danielc](https://discuss.elastic.co/u/danielc)\
**Post date:** [March 2, 2022, 12:11am UTC](https://discuss.elastic.co/t/filebeat-index-name-pattern-timestamp/296255/8 "2022-03-02T00:11:29Z")

</div>

I suspected that the old registry was the culprit so I've removed the old registry and restarted Filebeat. All of logs goes to the current index now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2022, 2:12am UTC](https://discuss.elastic.co/t/filebeat-index-name-pattern-timestamp/296255/9 "2022-03-30T02:12:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
