# Filebeat Index

**URL:** <https://discuss.elastic.co/t/filebeat-index/340008>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 3, 2023, 7:33am UTC](https://discuss.elastic.co/t/filebeat-index/340008 "2023-08-03T07:33:03Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vog93](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vog93/32/123838_2.png) [@Vog93](https://discuss.elastic.co/u/Vog93)\
**Post date:** [August 3, 2023, 7:33am UTC](https://discuss.elastic.co/t/filebeat-index/340008/1 "2023-08-03T07:33:03Z")

</div>

Hello, I have installed filebeat and uploaded a CSV to obtain the filebeat configuration for the installation, creating a new index and pipeline. the yml file looks like this:

```auto
filebeat.inputs:
- type: log
  paths:
  - C:\Users\victo\Downloads\archive\*.csv
  exclude_lines: ['^"?General_Health"?,"?Checkup"?,"?Exercise"?,"?Heart_Disease"?,"?Skin_Cancer"?,"?Other_Cancer"?,"?Depression"?,"?Diabetes"?,"?Arthritis"?,"?Sex"?,"?Age_Category"?,"?Height_\(cm\)"?,"?Weight_\(kg\)"?,"?BMI"?,"?Smoking_History"?,"?Alcohol_Consumption"?,"?Fruit_Consumption"?,"?Green_Vegetables_Consumption"?,"?FriedPotato_Consumption"?']

cloud.id: "MyID: ****"
cloud.auth: "elastic: ****"
 
index: "prueba3"
pipeline: "prueba3-pipeline"

setup:
  template.enabled: false
  ilm.enabled: false

```

After that I go to powershell and execute ` ./filebeat -c filebeat.yml setup` when finished `./filebeat -e -c filebeat.yml`

I can see that the data is going to the filebeat-\* index but not to the created one "prueba3"

I want to have the data in my index prueba3, what is the problem what am i doing wrong?

---

<div class="post-metadata">

**Author:** ![Vog93](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vog93/32/123838_2.png) [@Vog93](https://discuss.elastic.co/u/Vog93)\
**Post date:** [August 3, 2023, 7:44am UTC](https://discuss.elastic.co/t/filebeat-index/340008/2 "2023-08-03T07:44:00Z")

</div>

Here is the filebeat-\* index  
and the prueba3 index that has the data that i uploaded manually, I think that the number of hits of the prueba3 should increase because I have 2 files on the directory

 ![imagen](https://us1.discourse-cdn.com/elastic/original/3X/8/a/8a7322722374bbd30edf2e3acc0f5c85ec929f3a.png)

This is just a test, because I have to upload a bunch of files with the same structure to elastic and that is why i am using filebeat and obtaining the structure of the fiiles by just uploading one and copying the yml.

---

<div class="post-metadata">

**Author:** ![Vog93](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vog93/32/123838_2.png) [@Vog93](https://discuss.elastic.co/u/Vog93)\
**Post date:** [August 3, 2023, 8:18am UTC](https://discuss.elastic.co/t/filebeat-index/340008/3 "2023-08-03T08:18:52Z")

</div>

I see that the data is in the message part how can I have it on my index?

 ![imagen](https://us1.discourse-cdn.com/elastic/original/3X/d/c/dc426e295dce69899a0f0d2d5a75328eec94273d.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 3, 2023, 2:18pm UTC](https://discuss.elastic.co/t/filebeat-index/340008/4 "2023-08-03T14:18:20Z")

</div>

Think you need this to be

> [@Vog93](#):
>
> ```auto
> output.elasticsearch:
> index: "prueba3"
> pipeline: "prueba3-pipeline"
> 
> ```

What version as what you need to do is bit different in 7.x and 8.x.

Did you set up a template for the mappings? Otherwise you are going to get a default mapping which is not what you want... let me know the version and I think there are some post here with the correct steps / syntax

---

<div class="post-metadata">

**Author:** ![Vog93](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vog93/32/123838_2.png) [@Vog93](https://discuss.elastic.co/u/Vog93)\
**Post date:** [August 3, 2023, 2:33pm UTC](https://discuss.elastic.co/t/filebeat-index/340008/5 "2023-08-03T14:33:38Z")

</div>

That solved it thank you!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2023, 4:34pm UTC](https://discuss.elastic.co/t/filebeat-index/340008/6 "2023-08-31T16:34:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
