# How to change inbuilt modules index name with the same fields?

**URL:** <https://discuss.elastic.co/t/how-to-change-inbuilt-modules-index-name-with-the-same-fields/237444>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 17, 2020, 10:01am UTC](https://discuss.elastic.co/t/how-to-change-inbuilt-modules-index-name-with-the-same-fields/237444 "2020-06-17T10:01:06Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![sana1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sana1/32/46439_2.png) [@sana1](https://discuss.elastic.co/u/sana1)\
**Post date:** [June 17, 2020, 10:01am UTC](https://discuss.elastic.co/t/how-to-change-inbuilt-modules-index-name-with-the-same-fields/237444/1 "2020-06-17T10:01:06Z")

</div>

I want to change default filebeat-\* index name to zeek-\* with the same fields as configured in the zeek.yml, Until now I have changed  
'''  
hosts: ["localhost:9200"]  
protocol: "http"  
index: "zeek-%{+yyyy.MM.dd}"

setup.template:  
name: 'zeek- _'  
pattern: 'zeek-_ '  
enabled: true

setup.template:  
name: 'zeek- _'  
pattern: 'zeek-_ '  
enabled: true  
setup.ilm.enabled: false  
'''  
but still getting all the fields in filebeat-\* index instead of zeek-\* index, any help is appreciable.

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [June 17, 2020, 11:01am UTC](https://discuss.elastic.co/t/how-to-change-inbuilt-modules-index-name-with-the-same-fields/237444/2 "2020-06-17T11:01:12Z")

</div>

Hi @sana1 🙂

Can you paste the **entire config** file with proper markdown formatting, please? It's often an error in the YAML indentation  
[https://www.elastic.co/guide/en/beats/filebeat/7.7/elasticsearch-output.html](https://www.elastic.co/guide/en/beats/filebeat/7.7/elasticsearch-output.html)

---

<div class="post-metadata">

**Author:** ![sana1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sana1/32/46439_2.png) [@sana1](https://discuss.elastic.co/u/sana1)\
**Post date:** [June 17, 2020, 11:37am UTC](https://discuss.elastic.co/t/how-to-change-inbuilt-modules-index-name-with-the-same-fields/237444/3 "2020-06-17T11:37:25Z")

</div>

```auto

```

```auto
filebeat.inputs:
  - type: log
  enabled: false

filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: true
  reload.period: 10s

setup.template.name: "zeek-*"
setup.template.fields: "fields.yml"
setup.template.overwrite: false
setup.template.settings:
  index.number_of_shards: 1
  index.number_of_replicas: 1

setup.dashboards:
  index: "zeek-*"

setup.kibana:
  # Kibana Host
setup.ilm.enabled: false
#-------------------------- Elasticsearch output ------------------------------

output.elasticsearch:
  hosts: ["localhost:9200"]
  indices:
    - index: "zeek-%{+yyyy.MM.dd}"

```

```auto

```

---

<div class="post-metadata">

**Author:** ![sana1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sana1/32/46439_2.png) [@sana1](https://discuss.elastic.co/u/sana1)\
**Post date:** [June 17, 2020, 11:37am UTC](https://discuss.elastic.co/t/how-to-change-inbuilt-modules-index-name-with-the-same-fields/237444/4 "2020-06-17T11:37:59Z")

</div>

This is my code with zeek module enabled, still get no fields in zeek-\* index

---

<div class="post-metadata">

**Author:** ![sovello](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sovello/32/70101_2.png) [@sovello](https://discuss.elastic.co/u/sovello)\
**Post date:** [June 18, 2020, 4:51am UTC](https://discuss.elastic.co/t/how-to-change-inbuilt-modules-index-name-with-the-same-fields/237444/5 "2020-06-18T04:51:08Z")

</div>

It is a bit confusing here since you are configuring `zeek.yml`, but I would think you need to have those inside of filebeat.yml.  
Alternatively if you have set filebeat to communicate with elasticsearch through `logstash` then you may want to put that in the `output.elasticsearch.index` field of `logstash/conf.d/{config-file-name}.conf`  
like this

```auto
    output {
      elasticsearch {
        hosts => ["localhost:9200"]
        manage_template => false
        # index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
        index => "zeek-%{+YYYY.MM.dd}"
      }
    }

```

The commented line is actually the one that created the `filebeat-*` pattern.

Remember restarting logstash if you set this in logstash or restart filebeat service if you set this inside filebeat.  
You will also need to add the index pattern to logstash.

However above all, providing details about your setup will be more helpful to those who may want to provide a hand  
You can also look at the logs to check if anything is being logged there.

Goodluck

---

<div class="post-metadata">

**Author:** ![sana1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sana1/32/46439_2.png) [@sana1](https://discuss.elastic.co/u/sana1)\
**Post date:** [June 18, 2020, 5:02am UTC](https://discuss.elastic.co/t/how-to-change-inbuilt-modules-index-name-with-the-same-fields/237444/6 "2020-06-18T05:02:22Z")

</div>

I am using filebeat and elasticsearch , no logstash is being use. Using default setting of zeek module of Elasticsearch siem, i am able to get all 2550 fields of zeek with filebeat-\* index, but I want all the json fields in zeek-\* index. with the above mentioned settings I am able to get zeek-\* index but with 69 system fields only. This is the problem.

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [June 18, 2020, 2:02pm UTC](https://discuss.elastic.co/t/how-to-change-inbuilt-modules-index-name-with-the-same-fields/237444/7 "2020-06-18T14:02:19Z")

</div>

> [@sana1](#):
>
> ```auto
> output.elasticsearch:
> hosts: ["localhost:9200"]
> indices:
> - index: "zeek-%{+yyyy.MM.dd}"
> 
> ```

Can you try removing the `indices` key here?

```yaml
output.elasticsearch:
  hosts: ["localhost:9200"]
  index: "zeek-%{+yyyy.MM.dd}"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 16, 2020, 4:02pm UTC](https://discuss.elastic.co/t/how-to-change-inbuilt-modules-index-name-with-the-same-fields/237444/8 "2020-07-16T16:02:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
