# Filebeat setup error

**URL:** <https://discuss.elastic.co/t/filebeat-setup-error/286147>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 7, 2021, 2:44pm UTC](https://discuss.elastic.co/t/filebeat-setup-error/286147 "2021-10-07T14:44:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![nunex\_17](https://avatars.discourse-cdn.com/v4/letter/n/f17d59/32.png) [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Post date:** [October 7, 2021, 2:44pm UTC](https://discuss.elastic.co/t/filebeat-setup-error/286147/1 "2021-10-07T14:44:09Z")

</div>

Hi there.

After upgrading to Filebeat 7.15 i get this error on filebeat setup

```auto
root@suricata:~# sudo filebeat setup
Overwriting ILM policy is disabled. Set `setup.ilm.overwrite: true` for enabling.

Index setup finished.
Loading dashboards (Kibana must be running and reachable)
Exiting: 1 error: error setting index 'suricata-ids-*' in index pattern: empty index pattern

```

I dont want to use the default filebeat index and my config is like this (which was perfect on the previous version)

```auto
setup.ilm.enabled: auto
setup.ilm.rollover_alias: "suricata-ids" #Write your alias
setup.ilm.pattern: "{now/d}-000001"
setup.template.name: "suricata-ids"
setup.template.pattern: "suricata-ids-*"
setup.dashboards.index: "suricata-ids-*"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2021, 4:44pm UTC](https://discuss.elastic.co/t/filebeat-setup-error/286147/2 "2021-11-04T16:44:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
