# How do I create my own Index name?

**URL:** <https://discuss.elastic.co/t/how-do-i-create-my-own-index-name/172890>\
**Category:** Logstash\
**Created:** [March 19, 2019, 3:42am UTC](https://discuss.elastic.co/t/how-do-i-create-my-own-index-name/172890 "2019-03-19T03:42:11Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [March 19, 2019, 3:42am UTC](https://discuss.elastic.co/t/how-do-i-create-my-own-index-name/172890/1 "2019-03-19T03:42:11Z")

</div>

Hi Guys,

Can someone please help me on creating new Index name isntead of logstash-\* or filebeat-\*

Something like hashes-\*.

I think I need to create my new mapping and then post it on elasticsearch? The thing happening here is since I already have logstash-\* indices running creating new index name by creating fields in existing logstash indices.

Please help!!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 19, 2019, 3:44am UTC](https://discuss.elastic.co/t/how-do-i-create-my-own-index-name/172890/2 "2019-03-19T03:44:50Z")

</div>

What are you using to send the data to Elasticsearch?

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [March 19, 2019, 3:52am UTC](https://discuss.elastic.co/t/how-do-i-create-my-own-index-name/172890/3 "2019-03-19T03:52:22Z")

</div>

Its logstash.

May be I am wrong but I tried copying existing template from APImodifying it and trying to put using CURL but that is not happening. I am not so versed with MAPPING templates hence wanted to know what method I can follow to create my in index name so that fields won't get entangled in other indices.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 19, 2019, 4:26am UTC](https://discuss.elastic.co/t/how-do-i-create-my-own-index-name/172890/4 "2019-03-19T04:26:24Z")

</div>

You need to have it defined in your output section to Elasticsearch. Can you show us what you have there?

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [March 19, 2019, 4:32am UTC](https://discuss.elastic.co/t/how-do-i-create-my-own-index-name/172890/5 "2019-03-19T04:32:19Z")

</div>

its simple

```
input {

```

file {  
path =\> "/opt/HASH/finalHash"  
start\_position =\> "beginning"  
sincedb\_path =\> "/dev/null"  
}  
}  
filter {  
csv {  
separator =\> ","  
columns =\> ["hash","sev","stat","attack","type"]  
}

}  
output {  
elasticsearch {  
hosts =\> "[http://xx.xx.xx.xx:9200](http://xx.xx.xx.xx:9200)"  
index =\> "hashes-%{+YYYY.MM.dd}"  
}  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 19, 2019, 4:34am UTC](https://discuss.elastic.co/t/how-do-i-create-my-own-index-name/172890/6 "2019-03-19T04:34:06Z")

</div>

That will work. It will only apply the default-dynamic mapping though.  
If you want to use the same type of mapping that the `logstash-*` indices use, then you will need to copy the existing template and change it to match the new index pattern.

Also, please format your code/logs/config using the `</>` button, or markdown style back ticks. It helps to make things easy to read which helps us help you 🙂

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [March 19, 2019, 4:43am UTC](https://discuss.elastic.co/t/how-do-i-create-my-own-index-name/172890/7 "2019-03-19T04:43:30Z")

</div>

Yep but I do have other indices running which is logstash-isnti-_; now when I run logstash the fields from hashes-_ indices getting mingled in logstash-isnti-\* indices.

I need to keep those completely separate and this is not happening.

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [March 27, 2019, 11:17am UTC](https://discuss.elastic.co/t/how-do-i-create-my-own-index-name/172890/8 "2019-03-27T11:17:46Z")

</div>

Hi Team,

Unfortunately this is not happening; since my data is being ingested by logstash the fields created by either of the indices are gettign appeared in both of the Indices.

Here is what I did -

Logstash is creating indices by name  
isnti- [has fields "IOC","attack","Severity"]  
and hash-\* [has fields "hash","attack","Severity"]

Now Hash field is appearing in isnti indices as well and vice-versa. How to make them completely isolated?

```
more 01.conf

```

```auto
  file {
    path => "/opt/output/*.out"
    start_position => "beginning"
   sincedb_path => "/dev/null"
  }
}
filter {
  csv {
      separator => ","
     columns => ["IOC","attack","Severity"]
  }
grok {
    match => { "IOC" => "%{IP:IPaddr}" }
}

geoip {
    source => "IPaddr"
    remove_field => "IPaddr"
        }

}
output {
   elasticsearch {
     hosts => "http://localhost:9200"
     index => "isnti-%{+YYYY.MM.dd}"
  }
}
`
    `input {
  file {
    path => "/opt/output/*.hashes"
    start_position => "beginning"
   sincedb_path => "/dev/null"
  }
}
filter {
  csv {
      separator => ","
     columns => ["hash","attack","Severity"]
  }
}
output {
   elasticsearch {
     hosts => "http://localhost:9200"
     index => "hash-%{+YYYY.MM.dd}"
  }
}
`
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 24, 2019, 11:17am UTC](https://discuss.elastic.co/t/how-do-i-create-my-own-index-name/172890/9 "2019-04-24T11:17:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
