# Filebeat writing to its own index

**URL:** <https://discuss.elastic.co/t/filebeat-writing-to-its-own-index/310842>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 28, 2022, 9:09am UTC](https://discuss.elastic.co/t/filebeat-writing-to-its-own-index/310842 "2022-07-28T09:09:54Z")\
**Posts on this page:** 1\
**Showing post:** 24

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 3, 2022, 12:09am UTC](https://discuss.elastic.co/t/filebeat-writing-to-its-own-index/310842/24 "2022-08-03T00:09:56Z")

</div>

When you use modules like ngnix the index names is set in the module and overwrites the output ...

See a sample here / read this pay a special attention to the nginx input settings and explanation

> [@How to get the sum in time of values in Lens](https://discuss.elastic.co/t/how-to-get-the-sum-in-time-of-values-in-lens/310735/21):
>
> You can just copy the existing filebeat template and start from there it is pretty complete... or just use it as is... and change a few items like the index pattern matching ... and the write alias / ILM if you want to use them. Also this is the first time you mentioned logstash, which is fine but can add complications... not done correct it can affect the index name / results etc... (usually I suggest getting filebeat -\> elasticsearch first before adding logstash) Not sure what you mean T…

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-writing-to-its-own-index/310842)._
