# Index name based on tags

**URL:** <https://discuss.elastic.co/t/index-name-based-on-tags/137065>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 22, 2018, 6:25pm UTC](https://discuss.elastic.co/t/index-name-based-on-tags/137065 "2018-06-22T18:25:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hobapolis](https://avatars.discourse-cdn.com/v4/letter/h/ea666f/32.png) [@hobapolis](https://discuss.elastic.co/u/hobapolis)\
**Post date:** [June 22, 2018, 6:25pm UTC](https://discuss.elastic.co/t/index-name-based-on-tags/137065/1 "2018-06-22T18:25:33Z")

</div>

trying to accomplish:

```
index: "filebeat-%{[beat.version]}-%{[tags]}-%{+yyyy.MM.dd}"

```

my prospector looks similar to this:

```
- type: log
  enabled: true
  paths:
     - /var/log/auth.log
  tags: auth
  exclude_files: ['\.gz$']
  fields_under_root: true

```

However i'm getting this when trying to start up filebeat:

```
2018-06-22T18:20:34.797Z	WARN	fmtstr/formatevents.go:398	Can not convert key '[auth]' value to string

```

On filebeat 6.2.2

Any thoughts? I'm truly stuck.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [June 26, 2018, 8:57am UTC](https://discuss.elastic.co/t/index-name-based-on-tags/137065/2 "2018-06-26T08:57:02Z")

</div>

Hi @hobapolis,

`tags` is an array, and it cannot be used in variable substitution for the index name. You can add a custom field and use this field, something like this:

```auto
- type: log
  enabled: true
  paths:
     - /var/log/auth.log
  fields:
    index: auth
  exclude_files: ['\.gz$']

```

And then:

```auto
index: "filebeat-%{[beat.version]}-%{[fields.index]}-%{+yyyy.MM.dd}"

```

Another option is to use `indices` instead of index, that allows to define more advanced rules for index selection, you'd have to replace your index with something like:

```auto
  indices:
  - index: "filebeat-%{[beat.version]}-auth-%{+yyyy.MM.dd}"
    when.contains:
      tags: "auth"

```

---

<div class="post-metadata">

**Author:** ![hobapolis](https://avatars.discourse-cdn.com/v4/letter/h/ea666f/32.png) [@hobapolis](https://discuss.elastic.co/u/hobapolis)\
**Post date:** [June 26, 2018, 12:51pm UTC](https://discuss.elastic.co/t/index-name-based-on-tags/137065/3 "2018-06-26T12:51:19Z")

</div>

Thanks @jsoriano. I came to the realization that `tags` wasn't going to be a thing for me not long after I posted this question.

I did something very similar to your first suggestion. I ended up just creating a custom field called `index_name`.

Take care.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2018, 12:51pm UTC](https://discuss.elastic.co/t/index-name-based-on-tags/137065/4 "2018-07-24T12:51:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
