# How to configure winlogbeat to use existing index in elasticsearch

**URL:** <https://discuss.elastic.co/t/how-to-configure-winlogbeat-to-use-existing-index-in-elasticsearch/147533>\
**Category:** Beats\
**Created:** [September 6, 2018, 9:09am UTC](https://discuss.elastic.co/t/how-to-configure-winlogbeat-to-use-existing-index-in-elasticsearch/147533 "2018-09-06T09:09:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Teja](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teja/32/16324_2.png) [@Teja](https://discuss.elastic.co/u/Teja)\
**Post date:** [September 6, 2018, 9:09am UTC](https://discuss.elastic.co/t/how-to-configure-winlogbeat-to-use-existing-index-in-elasticsearch/147533/1 "2018-09-06T09:09:58Z")

</div>

Hi Team,

I have index in my elastic instance with index pattern "version-1-2018-_". Now, I want my windows logs to be embark under this "version-1-2018-_".

i have did the uploaded the "win beat pattern" in my elasticsearch in the name of "template\_version\_1\_winlogbeat" with index\_pattern as "version-1-\*" as my existing index pattern.

```
name index_patterns order version
kibana_index_template:.kibana [.kibana] 0     
logstash [logstash-*] 0 60001
metricbeat-6.2.4 [metricbeat-6.2.4-*] 1       
template_version_1 [version-1-*] 0     
template_version_1_winlogbeat [version-1-*] 0       
winlogbeat-6.4.0 [winlogbeat-6.4.0-*] 1     

```

now how can i config my winlogbeat to use the template "template\_version\_1\_winlogbeat" and use existing index "version-1-\*".

Believe me, I have tried all configuration(winbeat) unfortunately nothing is working for me.

But i can feel this would be simple configuration. So can you please guide on this.

if there any example config and any KB link would be more grateful.

Gratitude,  
Teja

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [September 6, 2018, 9:30am UTC](https://discuss.elastic.co/t/how-to-configure-winlogbeat-to-use-existing-index-in-elasticsearch/147533/2 "2018-09-06T09:30:06Z")

</div>

Have you tried setting `index`, `setup.template.name` and `setup.template.pattern`?

Example:

```auto
output.elasticsearch:
  enabled: true
  hosts: ["localhost:9200"]

  # Optional index name. The default is "winlogbeat" plus date
  # and generates [winlogbeat-]YYYY.MM.DD keys.
  # In case you modify this pattern you must update setup.template.name and setup.template.pattern accordingly.
  index: "version-1-%{+yyyy}"

# Template name. By default the template name is "winlogbeat-%{[beat.version]}"
# The template name and pattern has to be set in case the elasticsearch index pattern is modified.
setup.template.name: "version-1"

# Template pattern. By default the template pattern is "-%{[beat.version]}-*" to apply to the default index settings.
# The first part is the version of the beat and then -* is used to match all daily indices.
# The template name and pattern has to be set in case the elasticsearch index pattern is modified.
setup.template.pattern: "version-1-*"

```

---

<div class="post-metadata">

**Author:** ![Teja](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teja/32/16324_2.png) [@Teja](https://discuss.elastic.co/u/Teja)\
**Post date:** [September 6, 2018, 10:45am UTC](https://discuss.elastic.co/t/how-to-configure-winlogbeat-to-use-existing-index-in-elasticsearch/147533/3 "2018-09-06T10:45:02Z")

</div>

No its is not working, I am not seeing any results in kibana.

```
winlogbeat.event_logs:
  - name: Application
  - name: Security
  - name: System

output.elasticsearch:
  enabled: true
  hosts:
    - http://xx.xx.xx.xx:9200  
  index: "version-1-%{+YYYY.MM.dd}"

setup.template.name: "template_version_1_winlogbeat"
setup.template.pattern: "version-1-*"
   
  
setup.kibana:
    host: "xx.xx.xx.xx:5601"
  
logging.to_files: true
logging.files:
  path: C:/ProgramData/winlogbeat/Logs
logging.level: debug

```

This is my configuration file.  
Is there any way i can find the error.? (any log files because i cant able find any error in winlogbeat log)

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [September 6, 2018, 5:01pm UTC](https://discuss.elastic.co/t/how-to-configure-winlogbeat-to-use-existing-index-in-elasticsearch/147533/4 "2018-09-06T17:01:10Z")

</div>

What's output of `winlogbeat -e -d "*"`?

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [September 6, 2018, 5:04pm UTC](https://discuss.elastic.co/t/how-to-configure-winlogbeat-to-use-existing-index-in-elasticsearch/147533/5 "2018-09-06T17:04:33Z")

</div>

You set:

```
index: "version-1-%{+YYYY.MM.dd}"

```

While according to your previous messages it should be:

```
index: "version-1-%{+YYYY}"
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2018, 7:04pm UTC](https://discuss.elastic.co/t/how-to-configure-winlogbeat-to-use-existing-index-in-elasticsearch/147533/6 "2018-10-04T19:04:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
