How to create a single index when using with filebeats


I'm using filebeats to ship application logs from a server with index name created "iis_logs". I want to create a single index as "iis_logs" in elastic search but its creating new indexes daily adding the date to the index(like iis_logs-15-05-2017). Increase in the shards and indexes reducing the performance of the elastic search. Can you please suggest me is there any way I can do or the latest version filebeats does not have this issues.

(Carlos PĂ©rez Aradros) #2

Hi @dubul,

What version of filebeat are you using? Recent versions support index parameter as a template, allowing you to do what you want:

(Mark Walkom) #3

That is not a good idea. How do you manage retention?


Thanks @exekias


Thanks @warkolm Then I would create indexes monthly basis

(system) #6

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.