# Filebeats Sending Data to the Wrong index (ignoring .yml config and using default index)

**URL:** <https://discuss.elastic.co/t/filebeats-sending-data-to-the-wrong-index-ignoring-yml-config-and-using-default-index/216708>\
**Category:** Beats\
**Created:** [January 27, 2020, 5:24pm UTC](https://discuss.elastic.co/t/filebeats-sending-data-to-the-wrong-index-ignoring-yml-config-and-using-default-index/216708 "2020-01-27T17:24:46Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![guibarati](https://avatars.discourse-cdn.com/v4/letter/g/848f3c/32.png) [@guibarati](https://discuss.elastic.co/u/guibarati)\
**Post date:** [January 27, 2020, 5:24pm UTC](https://discuss.elastic.co/t/filebeats-sending-data-to-the-wrong-index-ignoring-yml-config-and-using-default-index/216708/1 "2020-01-27T17:24:46Z")

</div>

Hi,

I'm testing a filebeats indexing of JSON content created with wireshark.  
I have the filebeat.yml configured as below, but the logs keep going to the default filebeats index, (filebeat-7.5.2-2020.01.27-000001).

Can someone point me on the right direction?

Thank you!

* * *

filebeat.inputs:

- type: log  
paths:
  - "c:/sample/packets6.json"  
document\_type: "pcap\_file"  
json.keys\_under\_root: true

processors:

- drop\_event:  
when:  
equals:  
index.\_type: "pcap\_file"

output.elasticsearch:  
index: "packets-%{+yyyy-MM-dd}"  
hosts: ["10.1.30.104:9200"]  
path: "packets-test"

setup.template.name: "packets-_"  
setup.template.pattern: "packets-_"  
setup.template.enabled: false

# Debug logging config.

logging.level: debug  
logging.selectors: ['\*']

* * *

---

<div class="post-metadata">

**Author:** ![guibarati](https://avatars.discourse-cdn.com/v4/letter/g/848f3c/32.png) [@guibarati](https://discuss.elastic.co/u/guibarati)\
**Post date:** [January 29, 2020, 2:31pm UTC](https://discuss.elastic.co/t/filebeats-sending-data-to-the-wrong-index-ignoring-yml-config-and-using-default-index/216708/2 "2020-01-29T14:31:26Z")

</div>

Bringing the thread up to try to get some help

---

<div class="post-metadata">

**Author:** ![inhinyera16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inhinyera16/32/61625_2.png) [@inhinyera16](https://discuss.elastic.co/u/inhinyera16)\
**Post date:** [January 29, 2020, 2:59pm UTC](https://discuss.elastic.co/t/filebeats-sending-data-to-the-wrong-index-ignoring-yml-config-and-using-default-index/216708/3 "2020-01-29T14:59:54Z")

</div>

Can you validate your yaml here =\> [http://www.yamllint.com/](http://www.yamllint.com/)

---

<div class="post-metadata">

**Author:** ![guibarati](https://avatars.discourse-cdn.com/v4/letter/g/848f3c/32.png) [@guibarati](https://discuss.elastic.co/u/guibarati)\
**Post date:** [January 29, 2020, 3:04pm UTC](https://discuss.elastic.co/t/filebeats-sending-data-to-the-wrong-index-ignoring-yml-config-and-using-default-index/216708/4 "2020-01-29T15:04:45Z")

</div>

I pasted it over and it said it was "valid"

---

<div class="post-metadata">

**Author:** ![inhinyera16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inhinyera16/32/61625_2.png) [@inhinyera16](https://discuss.elastic.co/u/inhinyera16)\
**Post date:** [January 29, 2020, 3:21pm UTC](https://discuss.elastic.co/t/filebeats-sending-data-to-the-wrong-index-ignoring-yml-config-and-using-default-index/216708/5 "2020-01-29T15:21:10Z")

</div>

Did you manually load the template named "packets-"? coz if its not there, by default, filebeat template will be used.

---

<div class="post-metadata">

**Author:** ![guibarati](https://avatars.discourse-cdn.com/v4/letter/g/848f3c/32.png) [@guibarati](https://discuss.elastic.co/u/guibarati)\
**Post date:** [January 29, 2020, 4:57pm UTC](https://discuss.elastic.co/t/filebeats-sending-data-to-the-wrong-index-ignoring-yml-config-and-using-default-index/216708/6 "2020-01-29T16:57:08Z")

</div>

Yes, I manually created a template that applies to the pattern packets-\*.  
But in any case the data should be getting to the right index right? just using the wrong template even if I had not crated the template?

---

<div class="post-metadata">

**Author:** ![inhinyera16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inhinyera16/32/61625_2.png) [@inhinyera16](https://discuss.elastic.co/u/inhinyera16)\
**Post date:** [January 29, 2020, 6:51pm UTC](https://discuss.elastic.co/t/filebeats-sending-data-to-the-wrong-index-ignoring-yml-config-and-using-default-index/216708/7 "2020-01-29T18:51:38Z")

</div>

Could u please include ur template? Bcoz I can see u put “packet-“ as template name in filebeat config

---

<div class="post-metadata">

**Author:** ![guibarati](https://avatars.discourse-cdn.com/v4/letter/g/848f3c/32.png) [@guibarati](https://discuss.elastic.co/u/guibarati)\
**Post date:** [January 29, 2020, 8:34pm UTC](https://discuss.elastic.co/t/filebeats-sending-data-to-the-wrong-index-ignoring-yml-config-and-using-default-index/216708/8 "2020-01-29T20:34:29Z")

</div>

{  
"packets" : {  
"order" : 0,  
"index\_patterns" : [  
"packets-\*"  
],  
"settings" : { },  
"mappings" : {  
"dynamic" : "false",  
"properties" : {  
"layers" : {  
"properties" : {  
"udp" : {  
"properties" : {  
"udp\_udp\_srcport" : {  
"type" : "integer"  
},  
"udp\_udp\_dstport" : {  
"type" : "integer"  
}  
}  
},  
"ip" : {  
"properties" : {  
"ip\_ip\_src" : {  
"type" : "ip"  
},  
"ip\_ip\_dst" : {  
"type" : "ip"  
}  
}  
},  
"frame" : {  
"properties" : {  
"frame\_frame\_len" : {  
"type" : "long"  
},  
"frame\_frame\_protocols" : {  
"type" : "keyword"  
}  
}  
}  
}  
},  
"timestamp" : {  
"type" : "date"  
}  
}  
},  
"aliases" : { }  
}  
}

---

<div class="post-metadata">

**Author:** ![inhinyera16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inhinyera16/32/61625_2.png) [@inhinyera16](https://discuss.elastic.co/u/inhinyera16)\
**Post date:** [January 30, 2020, 1:34pm UTC](https://discuss.elastic.co/t/filebeats-sending-data-to-the-wrong-index-ignoring-yml-config-and-using-default-index/216708/9 "2020-01-30T13:34:14Z")

</div>

hi @guibarati,

in your filebeat config, you have this line:

```
setup.template.name: "packets-"

```

but your template is named "packets" 😃

---

<div class="post-metadata">

**Author:** ![guibarati](https://avatars.discourse-cdn.com/v4/letter/g/848f3c/32.png) [@guibarati](https://discuss.elastic.co/u/guibarati)\
**Post date:** [January 30, 2020, 2:17pm UTC](https://discuss.elastic.co/t/filebeats-sending-data-to-the-wrong-index-ignoring-yml-config-and-using-default-index/216708/10 "2020-01-30T14:17:39Z")

</div>

Hi @inhinyera16, I've changed the setup.template.name to "packets" but it didn't have an effect.  
I changed my index output to "packets-test" on my yml file and started receiving the following message:

Failed to connect to backoff(elasticsearch([http://10.1.30.104:9200/packets-test](http://10.1.30.104:9200/packets-test))): 404 Not Found: {"error":{"root\_cause":[{"type":"index\_not\_found\_exception"

Then I manually created the index, but got another error and the index is not being populated with data:

elasticsearch/client.go:771 GET [http://10.1.30.104:9200/packets-test/\_xpack?human=false](http://10.1.30.104:9200/packets-test/_xpack?human=false)  
licenser/elastic\_fetcher.go:105 Received 'Method Not allowed' (405) response from server, fallback to OSS license

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 27, 2020, 4:17pm UTC](https://discuss.elastic.co/t/filebeats-sending-data-to-the-wrong-index-ignoring-yml-config-and-using-default-index/216708/11 "2020-02-27T16:17:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
