# Index pattern matching all non-system indices

**URL:** https://discuss.elastic.co/t/index-pattern-matching-all-non-system-indices/110413
**Category:** Elasticsearch
**Created:** [December 5, 2017, 7:51pm UTC](https://discuss.elastic.co/t/index-pattern-matching-all-non-system-indices/110413 "2017-12-05T19:51:48Z")
**Posts on this page:** 12
**Page:** 1

<div class="post-metadata">

### Author: ![Supermathie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/supermathie/32/44936_2.png) [@Supermathie](https://discuss.elastic.co/u/Supermathie)
#### Post date: [December 5, 2017, 7:51pm UTC](https://discuss.elastic.co/t/index-pattern-matching-all-non-system-indices/110413/1 "2017-12-05T19:51:48Z")

</div>

We are running ES6 and have a number of indices:

- other-%{+YYYY.MM.dd}
- nginx-%{+YYYY.MM.dd}
- haproxy-%{+YYYY.MM.dd}

We would like to have an index pattern matching all of these, but discovered that `*` also matches the system indices.

How can I write a pattern to match only what I want? Are there any other options available beyond a globbing wildcard?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [December 6, 2017, 1:20am UTC](https://discuss.elastic.co/t/index-pattern-matching-all-non-system-indices/110413/2 "2017-12-06T01:20:22Z")

</div>

You might be better off adding an alias, I don't think there is anything else what would allow this 🙂

---

<div class="post-metadata">

### Author: ![Supermathie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/supermathie/32/44936_2.png) [@Supermathie](https://discuss.elastic.co/u/Supermathie)
#### Post date: [December 6, 2017, 4:31am UTC](https://discuss.elastic.co/t/index-pattern-matching-all-non-system-indices/110413/3 "2017-12-06T04:31:00Z")

</div>

I see the aliases in the documentation, but I don't see of a way to have them created dynamically; it seems the aliases need to be created for each index.

The wildcard aliases are point-in-time, so they would also have to be updated daily (or as the index are created...)

It's kind of painful, but it seems the best option is to rename all user indices so they have a common prefix 😢

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [December 6, 2017, 4:34am UTC](https://discuss.elastic.co/t/index-pattern-matching-all-non-system-indices/110413/4 "2017-12-06T04:34:51Z")

</div>

You can add aliases via templates, ie on creation.  
You could also use the `_rollover` API.

---

<div class="post-metadata">

### Author: ![Supermathie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/supermathie/32/44936_2.png) [@Supermathie](https://discuss.elastic.co/u/Supermathie)
#### Post date: [December 6, 2017, 4:44am UTC](https://discuss.elastic.co/t/index-pattern-matching-all-non-system-indices/110413/5 "2017-12-06T04:44:31Z")

</div>

We're already using templates so using [aliases in the templates](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html) looks perfect for our use, thanks!

EDIT: we've modified our templates to accomodate the idea of "types" of logs as follows:

```auto
{
  "index_patterns": ["haproxy-access", "haproxy-access-*"],
  "aliases": {
    "alllogs-{index}": {},
    "weblogs-{index}": {}
  },
...
}

```

```auto
{
  "index_patterns": ["postfix", "postfix-*"],
  "aliases": {
    "alllogs-{index}": {}
  },
...
}

```

---

<div class="post-metadata">

### Author: ![venkat545](https://avatars.discourse-cdn.com/v4/letter/v/f1d935/32.png) [@venkat545](https://discuss.elastic.co/u/venkat545)
#### Post date: [December 6, 2017, 5:39am UTC](https://discuss.elastic.co/t/index-pattern-matching-all-non-system-indices/110413/6 "2017-12-06T05:39:56Z")

</div>

hi .. hope this is the place to ask questions about Kibana.

I am new to Kibana and so far I have enjoyed playing around with it.

Could su help me out with the following..

If I have a numeric value in a doc eg.. the age of a person.  
Is there some way in Kibana that I could show the average age for the  
results of my query?

---

<div class="post-metadata">

### Author: ![Supermathie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/supermathie/32/44936_2.png) [@Supermathie](https://discuss.elastic.co/u/Supermathie)
#### Post date: [December 6, 2017, 5:42am UTC](https://discuss.elastic.co/t/index-pattern-matching-all-non-system-indices/110413/7 "2017-12-06T05:42:45Z")

</div>

This would be appropriate as a new topic, not a reply to an existing topic.

But, if you're looking to experiment with visualization in Kibana I just wrote a blog post on some examples of how to get started with that:

> **[An Instrumentation Story (How I Learned to Love the Elastic Stack)](https://blog.discourse.org/2017/11/an-instrumentation-story-how-i-learned-to-love-elk/)**
>
> in which we discover a better way to meet our customer’s needs while showing us where we can improve our code When you’re operating a hosting service it’s essential to know what’s going on. Visibility into your environment is required, both on a...

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [December 6, 2017, 5:43am UTC](https://discuss.elastic.co/t/index-pattern-matching-all-non-system-indices/110413/8 "2017-12-06T05:43:03Z")

</div>

Awesome, think you could rename it to Elastic Stack? 😉

---

<div class="post-metadata">

### Author: ![Supermathie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/supermathie/32/44936_2.png) [@Supermathie](https://discuss.elastic.co/u/Supermathie)
#### Post date: [December 6, 2017, 5:44am UTC](https://discuss.elastic.co/t/index-pattern-matching-all-non-system-indices/110413/9 "2017-12-06T05:44:05Z")

</div>

Ah, I see you're rebranding it! OK.

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [December 6, 2017, 7:11am UTC](https://discuss.elastic.co/t/index-pattern-matching-all-non-system-indices/110413/11 "2017-12-06T07:11:30Z")

</div>

Please start your own thread.

---

<div class="post-metadata">

### Author: ![venkat545](https://avatars.discourse-cdn.com/v4/letter/v/f1d935/32.png) [@venkat545](https://discuss.elastic.co/u/venkat545)
#### Post date: [December 6, 2017, 7:38am UTC](https://discuss.elastic.co/t/index-pattern-matching-all-non-system-indices/110413/12 "2017-12-06T07:38:08Z")

</div>

ok thank u:slightly\_smiling\_face:

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 3, 2018, 7:38am UTC](https://discuss.elastic.co/t/index-pattern-matching-all-non-system-indices/110413/13 "2018-01-03T07:38:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
