# How to bootstrap an index template with a part of the name not defined yet?

**URL:** <https://discuss.elastic.co/t/how-to-bootstrap-an-index-template-with-a-part-of-the-name-not-defined-yet/232332>\
**Category:** Logstash\
**Created:** [May 12, 2020, 11:19pm UTC](https://discuss.elastic.co/t/how-to-bootstrap-an-index-template-with-a-part-of-the-name-not-defined-yet/232332 "2020-05-12T23:19:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [May 12, 2020, 11:19pm UTC](https://discuss.elastic.co/t/how-to-bootstrap-an-index-template-with-a-part-of-the-name-not-defined-yet/232332/1 "2020-05-12T23:19:42Z")

</div>

Hi, depending on the hostgroup field, I want to add certain string to part of the index name:

```auto
filter{
        if [hostgroup] =~ /mass/ {

                mutate { add_field => { "indexname" => "mass" }}
        }
}
output{
    elasticsearch { 
        hosts => ["111.111.111.111"] 
        index => "myprefix-%{indexname}-000001" 
    }
}

```

But how I can bootstrap the index template, if I dont have part of the name yet?

```auto
PUT myprefix-?????-000001 
{
  "aliases": {
    "myprefix-index": {
      "is_write_index": true
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 12, 2020, 11:49pm UTC](https://discuss.elastic.co/t/how-to-bootstrap-an-index-template-with-a-part-of-the-name-not-defined-yet/232332/2 "2020-05-12T23:49:40Z")

</div>

Hello @ElasticLiver

Unfortunately the problem with the Rollover API / ILM index bootstrapping is you need to know in advance the all the possible names of the "data flows" you will be receiving in the cluster, so that a write rollover alias is ready on Elasticsearch side.

This is detailed in this [Github issue](https://github.com/logstash-plugins/logstash-output-elasticsearch/issues/858) and Elasticsearch is evolving to make "unknown" indices auto-bootstrap the indices with 2 concepts:

- [Index Templates v2](https://github.com/elastic/elasticsearch/issues/53101)
- [Data Streams](https://github.com/elastic/elasticsearch/issues/53100)

If you know all the possible values, you can bootstrap the indices in advance using:

```auto
PUT myprefix-mass-000001 
{
  "aliases": {
    "myprefix-mass": {
      "is_write_index": true
    }
  }
}
PUT myprefix-another-000001 
{
  "aliases": {
    "myprefix-another": {
      "is_write_index": true
    }
  }
}

```

As you have a dynamic variable, you have to use the manual bootstrapping of the indices and Logstash must be configured as follows:

```auto
    elasticsearch { 
        hosts => ["111.111.111.111"]
        ilm_enabled => false
        index => "myprefix-%{indexname}" 
    }

```

You will need to put in place an index template to associated the indices `myprefix-mass-*` and `myprefix-another-*` the `rollover_alias` respectively of `myprefix-mass` and `myprefix-another` and a ILM policy.

Those steps are detailed [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/getting-started-index-lifecycle-management.html#getting-started-index-lifecycle-management).

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 13, 2020, 12:34am UTC](https://discuss.elastic.co/t/how-to-bootstrap-an-index-template-with-a-part-of-the-name-not-defined-yet/232332/3 "2020-05-13T00:34:04Z")

</div>

I'm guessing you could use an http filter to do the put of the template, but that strikes me as something that could go very wrong if you have noise in your input.

If your dataset really does only have a few values for indexname then it would be OK, but every additional value adds cost.

---

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [May 13, 2020, 1:06am UTC](https://discuss.elastic.co/t/how-to-bootstrap-an-index-template-with-a-part-of-the-name-not-defined-yet/232332/4 "2020-05-13T01:06:13Z")

</div>

Thanks [Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini) , thanks [Badger](https://discuss.elastic.co/u/Badger) so, the easyest way to solve this will be using myprefix\* index template and then adding a ILM after the index is created?

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 13, 2020, 9:36am UTC](https://discuss.elastic.co/t/how-to-bootstrap-an-index-template-with-a-part-of-the-name-not-defined-yet/232332/5 "2020-05-13T09:36:41Z")

</div>

Each write alias (one per prefix) must have its own index template to set the `rollover_alias`.  
E.g.

```auto
PUT _template/myindex_mass_template
{
  "index_patterns": ["myprefix-mass-*"],                 
  "settings": {
    "index.lifecycle.name": "the_policy",      
    "index.lifecycle.rollover_alias": "myprefix-mass"    
  }
}
PUT _template/myindex_another_template
{
  "index_patterns": ["myprefix-another-*"],                 
  "settings": {
    "index.lifecycle.name": "the_policy",      
    "index.lifecycle.rollover_alias": "myprefix-another"    
  }
}

```

The policy name can be the same or different for both.  
Other common settings across both indices can be set using another template which matches both. E.g.

```auto
PUT _template/myindex_template
{
  "index_patterns": ["myprefix-*"],                 
  "settings": {
    "number_of_shards": 1,
    "number_of_replicas": 1
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 10, 2020, 9:36am UTC](https://discuss.elastic.co/t/how-to-bootstrap-an-index-template-with-a-part-of-the-name-not-defined-yet/232332/6 "2020-06-10T09:36:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
