# Index name for modules

**URL:** <https://discuss.elastic.co/t/index-name-for-modules/194893>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 12, 2019, 5:21pm UTC](https://discuss.elastic.co/t/index-name-for-modules/194893 "2019-08-12T17:21:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tenney](https://avatars.discourse-cdn.com/v4/letter/t/35a633/32.png) [@tenney](https://discuss.elastic.co/u/tenney)\
**Post date:** [August 12, 2019, 5:21pm UTC](https://discuss.elastic.co/t/index-name-for-modules/194893/1 "2019-08-12T17:21:19Z")

</div>

Using filebeat 7.3.0 on ubuntu and can't seem to change the index name for any modules that get enabled.

All I want to do is make the indexes that get created be done so monthly names instead of daily.

I would expect this to work, but has no change:

output.elasticsearch:  
index: "filebeat-%{[agent.version]}-%{+yyyy.MM}"

Tried a lot a different things and it just seems to ignore them. Any ideas? Thanks.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 13, 2019, 9:47am UTC](https://discuss.elastic.co/t/index-name-for-modules/194893/2 "2019-08-13T09:47:49Z")

</div>

Please properly format logs and configs using the `</>` button. Filebeat configuration is sensitive to indentation. Without proper formatting it is difficult to see if there might be an error.

Do you have ILM enabled? Which exact index names are generated in Elasticsearch?

---

<div class="post-metadata">

**Author:** ![tenney](https://avatars.discourse-cdn.com/v4/letter/t/35a633/32.png) [@tenney](https://discuss.elastic.co/u/tenney)\
**Post date:** [August 13, 2019, 3:50pm UTC](https://discuss.elastic.co/t/index-name-for-modules/194893/3 "2019-08-13T15:50:22Z")

</div>

ILM is not enabled. Here is an example index name that gets generated:

filebeat-7.3.0-2019.08.13-000001

I can change the index name for non-module log consumption. I am using for example the nginx module by doing "filebeat modules enable nginx". I can't seem to change the index name for the nginx logs that now get consumed by filebeat.

It's default creates way to many indexes that is causing me performance issues with elasticsearch. I simply want to create a monthly index for it and would expect this to work:

```
output.elasticsearch:
  index: "filebeat-%{[agent.version]}-%{+yyyy.MM}"
```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 14, 2019, 9:37am UTC](https://discuss.elastic.co/t/index-name-for-modules/194893/4 "2019-08-14T09:37:56Z")

</div>

The default ILM mode is 'auto'. If beats detect the Elasticsearch cluster you send to has ILM support, then it will be enabled. The Index name `filebeat-7.3.0-2019.08.13-000001` is created by ILM, not by beats. In fact beats uses a write alias named `filebeat-%{[agent.version]}` here.

With ILM enabled, the `output.elasticsearch.index` setting will be overwritten with the write alias.

In order to disable ILM stop beats, remove the `filebeat-*` templates, add `setup.ilm.enabled: false` to your config file and restart.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 11, 2019, 9:37am UTC](https://discuss.elastic.co/t/index-name-for-modules/194893/5 "2019-09-11T09:37:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
