# How to create a new filebeat index with a custom name?

**URL:** <https://discuss.elastic.co/t/how-to-create-a-new-filebeat-index-with-a-custom-name/61689>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 28, 2016, 11:36am UTC](https://discuss.elastic.co/t/how-to-create-a-new-filebeat-index-with-a-custom-name/61689 "2016-09-28T11:36:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jinal.shah](https://avatars.discourse-cdn.com/v4/letter/j/3da27b/32.png) [@jinal.shah](https://discuss.elastic.co/u/jinal.shah)\
**Post date:** [September 28, 2016, 11:36am UTC](https://discuss.elastic.co/t/how-to-create-a-new-filebeat-index-with-a-custom-name/61689/1 "2016-09-28T11:36:42Z")

</div>

Hello

What is the best way to create a new index for filebeat and output it to elastic elasticsearch/kibana?

The filebeat logs will still be parsed through logstash.

So far, I have enabled this on the filebeat client:

```
#
# # Optional index name. The default is "filebeat" and generates
# # [filebeat-]YYYY.MM.DD keys.
    index: "appstash-dev-%{+YYYY.MM.dd}"
#
# # A template is used to set the mapping in Elasticsearch
# # By default template loading is disabled and no template is loaded.
# # These settings can be adjusted to load your own template or overwrite existing ones
    template:
#
# # Template name. By default the template name is filebeat.
      name: "appstash"
#
# # Path to template file
      path: "appstash.template.json"

```

And I have uploaded the new template on the ELK server after modifying the last line to :

```
},
  "template": "appstash-*"

curl -XPUT 'http://localhost:9200/_template/appstash?pretty' -d@appstash-index-template.json

```

Thanks

---

<div class="post-metadata">

**Author:** ![jinal.shah](https://avatars.discourse-cdn.com/v4/letter/j/3da27b/32.png) [@jinal.shah](https://discuss.elastic.co/u/jinal.shah)\
**Post date:** [September 28, 2016, 1:09pm UTC](https://discuss.elastic.co/t/how-to-create-a-new-filebeat-index-with-a-custom-name/61689/2 "2016-09-28T13:09:32Z")

</div>

Figured out that you only need to make changes in the output section of the configuration file:

```
output {
      stdout { }
      elasticsearch {
        hosts => ["localhost:9200"]
        sniffing => true
        manage_template => false
        index => "appstash-%{environment}-%{+YYYY.MM.dd}"
        document_type => "appstash"
      }
```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 3, 2016, 1:49pm UTC](https://discuss.elastic.co/t/how-to-create-a-new-filebeat-index-with-a-custom-name/61689/3 "2016-10-03T13:49:52Z")

</div>

If you use the LS output configuration from the documentation, then when you customize the `output.logstash.index` value in your Filebeat config it should work as expected (it causes the `[@metadata][beat]` value to change to the configured index value). This also allows the [`document_type`](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#_document_type) config option to work correctly from the Filebeat prospector config.

Source: [https://www.elastic.co/guide/en/beats/libbeat/current/logstash-installation.html](https://www.elastic.co/guide/en/beats/libbeat/current/logstash-installation.html)

```auto
output {
  elasticsearch {
    hosts => "localhost:9200"
    manage_template => false
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
  }
}

```

---

<div class="post-metadata">

**Author:** ![jinal.shah](https://avatars.discourse-cdn.com/v4/letter/j/3da27b/32.png) [@jinal.shah](https://discuss.elastic.co/u/jinal.shah)\
**Post date:** [October 3, 2016, 2:04pm UTC](https://discuss.elastic.co/t/how-to-create-a-new-filebeat-index-with-a-custom-name/61689/4 "2016-10-03T14:04:12Z")

</div>

Perfect, thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 19, 2016, 11:37am UTC](https://discuss.elastic.co/t/how-to-create-a-new-filebeat-index-with-a-custom-name/61689/5 "2016-10-19T11:37:05Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
