# How to set Index name in conf.d .conf File to adjust to ILM

**URL:** <https://discuss.elastic.co/t/how-to-set-index-name-in-conf-d-conf-file-to-adjust-to-ilm/207544>\
**Category:** Logstash\
**Created:** [November 12, 2019, 3:04pm UTC](https://discuss.elastic.co/t/how-to-set-index-name-in-conf-d-conf-file-to-adjust-to-ilm/207544 "2019-11-12T15:04:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Moritz\_Kiesewetter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moritz_kiesewetter/32/51243_2.png) [@Moritz\_Kiesewetter](https://discuss.elastic.co/u/Moritz_Kiesewetter)\
**Post date:** [November 12, 2019, 3:04pm UTC](https://discuss.elastic.co/t/how-to-set-index-name-in-conf-d-conf-file-to-adjust-to-ilm/207544/1 "2019-11-12T15:04:02Z")

</div>

Hello Guys, i've got the following set in my /logstash/conf.d/10-syslog-XXXXX.conf file:

```
output {
if [type] == "syslog" {
  elasticsearch {
    hosts => ["000.000.000.000"]
    index => "logstash-vmw-000002"

```

I've also setup a Index Lifecycle Management for this index. It works somehow, in kibana i can see the new Index "logstash-vmw-000003" as a write Index and the aliases have been passed to it aswell. The Problem is, my Logstash Nodes still sent the Logs to the Index logstash-vmw-000002, so there are Logs in the new index. How do i have to setup the Index-Name in the conf.yml to let it adjust automatically?

Kind regards,  
Moritz Kiesewetter

---

<div class="post-metadata">

**Author:** ![philippkahr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippkahr/32/100137_2.png) [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Post date:** [November 12, 2019, 6:23pm UTC](https://discuss.elastic.co/t/how-to-set-index-name-in-conf-d-conf-file-to-adjust-to-ilm/207544/2 "2019-11-12T18:23:37Z")

</div>

Hi!

```auto
output {
if [type] == "syslog" {
  elasticsearch {
    hosts => ["000.000.000.000"]
    index => "logstash-vmw"

```

You can reference the index with the alias you created. When you use the alias elasticsearch takes care of writing to the correct index.

---

<div class="post-metadata">

**Author:** ![Moritz\_Kiesewetter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moritz_kiesewetter/32/51243_2.png) [@Moritz\_Kiesewetter](https://discuss.elastic.co/u/Moritz_Kiesewetter)\
**Post date:** [November 13, 2019, 7:42am UTC](https://discuss.elastic.co/t/how-to-set-index-name-in-conf-d-conf-file-to-adjust-to-ilm/207544/3 "2019-11-13T07:42:43Z")

</div>

Hi, thanks for your reply!  
I've set the Alias in the Index-Template logstash-\*

```
{
  "logstash": {}
}

```

I changed the config file following your recommendations, the logs still get the deliver, if i open them up they tell me :

> @timestamp Nov 13, 2019 @ 08:40:23.141  
> **t** @version 1  
> **t** \_id aIy0Y24Bk3krkYz-y0R0  
> **t** \_index logstash-vmw

Should i be bothered because it say "index: logstash-vmw" or is this ok cause the docs will still get sorted in the "logstash-vmw-00003" Index?

Thanks anyway, you helped me a lot!

EDIT:  
Ok so now i have the problem, that the Doc count of my newest Index doesn't rise.  
I can see the Logs in the Discovery Section, but the index is not changing in size or Doc Count...  
Can i somehow tell my Logstash to send in to an Alias? Instead of static Index Name? Also if i now check my Indicies under "Index Management" i can see a logstash-vmw Index, which i never created...

---

<div class="post-metadata">

**Author:** ![philippkahr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippkahr/32/100137_2.png) [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Post date:** [November 13, 2019, 8:06am UTC](https://discuss.elastic.co/t/how-to-set-index-name-in-conf-d-conf-file-to-adjust-to-ilm/207544/5 "2019-11-13T08:06:23Z")

</div>

You have to send it to the index alias name.

Let's say you have `logstash-vmw-00003` and your index alias is `logstash-vmw` then it works. If your alias is `logstash-` then you would have to use `logstash-`

---

<div class="post-metadata">

**Author:** ![Moritz\_Kiesewetter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moritz_kiesewetter/32/51243_2.png) [@Moritz\_Kiesewetter](https://discuss.elastic.co/u/Moritz_Kiesewetter)\
**Post date:** [November 13, 2019, 12:17pm UTC](https://discuss.elastic.co/t/how-to-set-index-name-in-conf-d-conf-file-to-adjust-to-ilm/207544/6 "2019-11-13T12:17:10Z")

</div>

Now it works!  
Thanks a lot man 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 11, 2019, 12:17pm UTC](https://discuss.elastic.co/t/how-to-set-index-name-in-conf-d-conf-file-to-adjust-to-ilm/207544/7 "2019-12-11T12:17:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
