# How to change elasticsearch output index with default template

**URL:** <https://discuss.elastic.co/t/how-to-change-elasticsearch-output-index-with-default-template/177518>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 18, 2019, 5:22pm UTC](https://discuss.elastic.co/t/how-to-change-elasticsearch-output-index-with-default-template/177518 "2019-04-18T17:22:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![geforcesong](https://avatars.discourse-cdn.com/v4/letter/g/ce7236/32.png) [@geforcesong](https://discuss.elastic.co/u/geforcesong)\
**Post date:** [April 18, 2019, 5:22pm UTC](https://discuss.elastic.co/t/how-to-change-elasticsearch-output-index-with-default-template/177518/1 "2019-04-18T17:22:13Z")

</div>

Hello, checked the documents, i am still not able to update elasticsearch output index. i want to add a log type on it. But it keeps giving me the default one.  
Here is my conf,

```
    filebeat.inputs:

- type: log

  # change to true to enable this input configuration.
  enabled: true

  # paths that should be crawled and fetched. glob based paths.
  paths:
    - /users/george/downloads/jslog1.log

  json.keys_under_root: true
  json.add_error_key: true
  json.message_key: log
    #- c:\programdata\elasticsearch\logs\*

  fields:
   level: debug
   review: 1
   log_type: nodeerror

  

filebeat.config.modules:
  # glob pattern for configuration loading
  path: ${path.config}/modules.d/*.yml

  # set to true to enable config reloading
  reload.enabled: false

#==================== elasticsearch template setting ==========================
setup.template.name: "filebeat"
setup.template.pattern: "filebeat-*"
setup.template.settings:
  index.number_of_shards: 1

output.elasticsearch:
  # array of hosts to connect to.
  hosts: ["localhost:9200"]
  index: "%{[fields.log_type]}-%{[agent.version]}-%{+yyyy.mm.dd}"

processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~

```

In the filebeat output log i noticed that it says "Set setup.template.name to '{filebeat-7.0.0 {now/d}-000001}' as ILM is enabled." This is default one. why???  
Do I have to create a new customized templates to change the index?

Thanks!

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 18, 2019, 5:49pm UTC](https://discuss.elastic.co/t/how-to-change-elasticsearch-output-index-with-default-template/177518/2 "2019-04-18T17:49:22Z")

</div>

Unfortunately its not possible right now to change the index name with ILM enabled. If you want to change the index name, you'll want to disable ILM. You can do this by setting `setup.ilm.enabled: false` in your `filebeat.yml`.

I've created an issue on GitHub to document this limitation in Beats documentation: [https://github.com/elastic/beats/issues/11866](https://github.com/elastic/beats/issues/11866).

---

<div class="post-metadata">

**Author:** ![geforcesong](https://avatars.discourse-cdn.com/v4/letter/g/ce7236/32.png) [@geforcesong](https://discuss.elastic.co/u/geforcesong)\
**Post date:** [April 18, 2019, 8:57pm UTC](https://discuss.elastic.co/t/how-to-change-elasticsearch-output-index-with-default-template/177518/4 "2019-04-18T20:57:19Z")

</div>

ok, after set this, everything works  
setup.ilm.enabled: false

How can i use ILM in this case? Is there an example?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 16, 2019, 8:57pm UTC](https://discuss.elastic.co/t/how-to-change-elasticsearch-output-index-with-default-template/177518/5 "2019-05-16T20:57:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
