# How to set the index name to the value of tags set by filebeat

**URL:** <https://discuss.elastic.co/t/how-to-set-the-index-name-to-the-value-of-tags-set-by-filebeat/279820>\
**Category:** Logstash\
**Created:** [July 28, 2021, 7:49am UTC](https://discuss.elastic.co/t/how-to-set-the-index-name-to-the-value-of-tags-set-by-filebeat/279820 "2021-07-28T07:49:26Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![its-ogawa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its-ogawa/32/120829_2.png) [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Post date:** [July 28, 2021, 7:49am UTC](https://discuss.elastic.co/t/how-to-set-the-index-name-to-the-value-of-tags-set-by-filebeat/279820/1 "2021-07-28T07:49:26Z")

</div>

I am using filebeat to collect some logs.  
I have set the value of tags for each log, and I want to use that value as the name of the index.  
Is that possible?

```auto
vi /etc/filebeat/filebeat.yml
... snip ...
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /path/to/A.log
  tags: ["A", "foo", "bar"]
- type: log
  enabled: true
  paths:
    - /path/to/B.log
  tags: ["B", "hoge"]
... snip ...

```

With the following method, it will be "[tags][0]-2021.07.28" instead of the value of tags.  
(Actually, we want it to be "A-2021.07.28", "B-2021.07.28", etc.)

```auto
vi /etc/logstash/logstash-sample.config
... snip ...
output {
  elasticsearch {
    hosts => ["localhost"]
    index => "%{[tags][0]}-%{+YYYY.MM.dd}"
}
... snip ...

```

As a workaround for now, I'm using if-else statements, but I'm having trouble with the increasing number of log types.

```auto
vi /etc/logstash/logstash-sample.config
... snip ...
if ( "A" in [tags][0] ) [
  output {
    elasticsearch {
      hosts => ["localhost"]
      index => "A-%{+YYYY.MM.dd}"
  }
}
else if ( "B" in [tags][0] ) [
  output {
    elasticsearch {
      hosts => ["localhost"]
      index => "B-%{+YYYY.MM.dd}"
  }
}
... snip ...

```

Do you have any good ideas?

Also, I'd really like to concatenate the values I set for tags (different lengths for different logs) into the name of the index.  
(For example, I want to use "A-foo-bar-2021.07.28" or "B-hoge-2021.07.28.")

Do you have any good ideas about this as well?

---

<div class="post-metadata">

**Author:** ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)\
**Post date:** [July 28, 2021, 7:16pm UTC](https://discuss.elastic.co/t/how-to-set-the-index-name-to-the-value-of-tags-set-by-filebeat/279820/2 "2021-07-28T19:16:46Z")

</div>

Don't use tags, have filebeat create a new field instead.

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /path/to/A.log
  tags: ["foo", "bar"]
  fields:
       index_name: A

- type: log
  enabled: true
  paths:
    - /path/to/B.log
  tags: ["hoge"]
  fields:
       index_name: B

```

> **[Log input | Filebeat Reference \[7.13\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-log.html#filebeat-input-log-fields)**

Then with the output you don't have to use all those if statements:

```auto
    output {
      elasticsearch {
        index => "%{[fields][index_name]}-%{+YYYY.MM.dd}"
      }
    }

```

---

<div class="post-metadata">

**Author:** ![its-ogawa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its-ogawa/32/120829_2.png) [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Post date:** [July 29, 2021, 1:18am UTC](https://discuss.elastic.co/t/how-to-set-the-index-name-to-the-value-of-tags-set-by-filebeat/279820/3 "2021-07-29T01:18:57Z")

</div>

Very good idea!!!  
That's exactly what I needed to know!!!  
Thanks for letting me know!

---

<div class="post-metadata">

**Author:** ![its-ogawa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its-ogawa/32/120829_2.png) [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Post date:** [July 29, 2021, 7:33am UTC](https://discuss.elastic.co/t/how-to-set-the-index-name-to-the-value-of-tags-set-by-filebeat/279820/4 "2021-07-29T07:33:15Z")

</div>

Basically, the log is being output with the name I specified, but  
For some reason, it also creates an index with the following name.

%{[fields][index\_name]}-2021.07.29

The size of the document is not large, but I can't look inside it with elasticsearch-head.  
(The search is in progress and no results are returned)

Can you tell me why?

---

<div class="post-metadata">

**Author:** ![its-ogawa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its-ogawa/32/120829_2.png) [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Post date:** [July 29, 2021, 8:17am UTC](https://discuss.elastic.co/t/how-to-set-the-index-name-to-the-value-of-tags-set-by-filebeat/279820/5 "2021-07-29T08:17:50Z")

</div>

I can't seem to get the ElasticSearchAPI to display properly.  
Is there any way to fix this?

```auto
curl -XGET 'localhost:9200/%{[fields][index_name]}-2021.07.29/_settings?pretty'
curl: (3) [globbing] nested braces not supported at pos 18

```

---

<div class="post-metadata">

**Author:** ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)\
**Post date:** [July 31, 2021, 5:41pm UTC](https://discuss.elastic.co/t/how-to-set-the-index-name-to-the-value-of-tags-set-by-filebeat/279820/6 "2021-07-31T17:41:42Z")

</div>

If that happens then the field `[fields][index_name]` does not exist. Double check your input by outputting to `stdout` and make sure that you define a field name. If you want you can also include an `if` statement before the output to set a default index name  
Check out this example:

> **[Elasticsearch output plugin | Logstash Reference \[7.13\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#_writing_to_different_indices_best_practices)**

```auto
    output {
    if [fields][index_name] {
       elasticsearch {
         index => "%{[fields][index_name]}-%{+YYYY.MM.dd}"
       }
     } else {
       elasticsearch {
         index => "defaultindex-%{+YYYY.MM.dd}"
       }
     }
       
    }

```

---

<div class="post-metadata">

**Author:** ![its-ogawa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its-ogawa/32/120829_2.png) [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Post date:** [August 2, 2021, 1:22am UTC](https://discuss.elastic.co/t/how-to-set-the-index-name-to-the-value-of-tags-set-by-filebeat/279820/7 "2021-08-02T01:22:08Z")

</div>

Thank you for your answer.

That's a very good idea to set the default index name in the if-else!  
I had already done that support as well.

However, I had written the following to determine if the field name exists

```auto
if([fields][index_name] ! = "") {
... snip ...

```

Following your idea, I would write something like this

```auto
if([fields][index_name]) {
... snip ...

```

Since the index is not created immediately, we don't know the result yet.  
I will report the results when they are available.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 30, 2021, 1:22am UTC](https://discuss.elastic.co/t/how-to-set-the-index-name-to-the-value-of-tags-set-by-filebeat/279820/8 "2021-08-30T01:22:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
