# How to define index name for kibana index pattern

**URL:** <https://discuss.elastic.co/t/how-to-define-index-name-for-kibana-index-pattern/66614>\
**Category:** Logstash\
**Created:** [November 19, 2016, 8:49am UTC](https://discuss.elastic.co/t/how-to-define-index-name-for-kibana-index-pattern/66614 "2016-11-19T08:49:00Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![student975](https://avatars.discourse-cdn.com/v4/letter/s/aeb1de/32.png) [@student975](https://discuss.elastic.co/u/student975)\
**Post date:** [November 19, 2016, 8:49am UTC](https://discuss.elastic.co/t/how-to-define-index-name-for-kibana-index-pattern/66614/1 "2016-11-19T08:49:00Z")

</div>

Hi!

How to define index name in `multi-ls-on-hosts -> rabbit -> ls -> kibana` chain to be further used in kibana index pattern?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 19, 2016, 8:54am UTC](https://discuss.elastic.co/t/how-to-define-index-name-for-kibana-index-pattern/66614/2 "2016-11-19T08:54:17Z")

</div>

It's not really clear what you are after here, can you try asking it a different way?

---

<div class="post-metadata">

**Author:** ![student975](https://avatars.discourse-cdn.com/v4/letter/s/aeb1de/32.png) [@student975](https://discuss.elastic.co/u/student975)\
**Post date:** [November 19, 2016, 9:07am UTC](https://discuss.elastic.co/t/how-to-define-index-name-for-kibana-index-pattern/66614/3 "2016-11-19T09:07:00Z")

</div>

I have a service logging in local ls. This ls pushes messages to rabbitmq, and the last one gathers messages from multiple similar services. Then rmq pushes messages to another ls, and the last one forwards them to elasticsearch used by kibana. Kibana has got settings "indices" to configure index patterns.

Say, for two given services i'd want to push their messages to indexes `jazz@yyyy.mm.dd` to be then able to separate them in kibana from other indexes using `jazz@*` index pattern.

Which configuration(s) must deal with `jazz` name?

---

<div class="post-metadata">

**Author:** ![student975](https://avatars.discourse-cdn.com/v4/letter/s/aeb1de/32.png) [@student975](https://discuss.elastic.co/u/student975)\
**Post date:** [November 19, 2016, 4:58pm UTC](https://discuss.elastic.co/t/how-to-define-index-name-for-kibana-index-pattern/66614/4 "2016-11-19T16:58:14Z")

</div>

Is my attempt to elaborate the question is still ugly to be understood? 🙂

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 20, 2016, 12:58am UTC](https://discuss.elastic.co/t/how-to-define-index-name-for-kibana-index-pattern/66614/5 "2016-11-20T00:58:25Z")

</div>

Have a look at my answer here - [Can I create different index patterns for different logs types in logstash?](https://discuss.elastic.co/t/can-i-create-different-index-patterns-for-different-logs-types-in-logstash/66588) - it's basically the same thing.

[https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html) will also be helpful.

---

<div class="post-metadata">

**Author:** ![student975](https://avatars.discourse-cdn.com/v4/letter/s/aeb1de/32.png) [@student975](https://discuss.elastic.co/u/student975)\
**Post date:** [November 20, 2016, 4:07am UTC](https://discuss.elastic.co/t/how-to-define-index-name-for-kibana-index-pattern/66614/6 "2016-11-20T04:07:06Z")

</div>

I guess we still say about different use cases. Hope, this scheme will clarify my intention. ![](https://us1.discourse-cdn.com/elastic/original/2X/c/c2499577a3b8de26bf64d5e16d31f159b600a837.jpg)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 20, 2016, 6:35am UTC](https://discuss.elastic.co/t/how-to-define-index-name-for-kibana-index-pattern/66614/7 "2016-11-20T06:35:24Z")

</div>

Assuming you have something in your data that can be used to determine which index it should go to, you can achieve this by using 2 elasticsearch output blocks (one for each index) covered by [conditionals](https://www.elastic.co/guide/en/logstash/5.0/event-dependent-configuration.html#conditionals). If you current do not have this, you can simply add a tag or a field at the Logstash instances that collects the data and use this.

---

<div class="post-metadata">

**Author:** ![student975](https://avatars.discourse-cdn.com/v4/letter/s/aeb1de/32.png) [@student975](https://discuss.elastic.co/u/student975)\
**Post date:** [November 20, 2016, 6:45am UTC](https://discuss.elastic.co/t/how-to-define-index-name-for-kibana-index-pattern/66614/8 "2016-11-20T06:45:33Z")

</div>

> [@Christian\_Dahlqvist](#):
>
> Assuming you have something in your data that can be used to determine which index it should go to

No, I haven't. The information must be some way provided in the local (on the left side) LSs configurations. And there can be potentially infinite amount of `foos` and `bars` on the left side.

[quote="Christian\_Dahlqvist, post:7, topic:66614, full:true"]If you current do not have this, you can simply add a tag or a field at the Logstash instances that collects the data and use this.  
[/quote]Aha, this way seems to be appropriate, thanks, will try to dig in this direction.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 20, 2016, 8:15am UTC](https://discuss.elastic.co/t/how-to-define-index-name-for-kibana-index-pattern/66614/9 "2016-11-20T08:15:37Z")

</div>

> [@student975](#):
>
> And there can be potentially infinite amount of foos and bars on the left side.

Group events into a few indices based on how similar the event structures are. Be careful to not create a large amount of small, time-based indices and shards as this is very inefficient and is very likely cause problems down the road. You should easily be able to find examples of the issues around having too many indices and shards in these forums as it is a relatively common mistake.

---

<div class="post-metadata">

**Author:** ![student975](https://avatars.discourse-cdn.com/v4/letter/s/aeb1de/32.png) [@student975](https://discuss.elastic.co/u/student975)\
**Post date:** [November 20, 2016, 10:07am UTC](https://discuss.elastic.co/t/how-to-define-index-name-for-kibana-index-pattern/66614/10 "2016-11-20T10:07:58Z")

</div>

Thanks, there isn't any reason at my case to get really many indexes, and I'm aware of the road to the hell - that is to use shards with partitioning. So the next step is to understand how to map a field (which was set with `add_field`) to ES index name.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2016, 10:07am UTC](https://discuss.elastic.co/t/how-to-define-index-name-for-kibana-index-pattern/66614/11 "2016-12-18T10:07:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
