# Indexes at work Packetbeat

**URL:** <https://discuss.elastic.co/t/indexes-at-work-packetbeat/79424>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [March 21, 2017, 1:31pm UTC](https://discuss.elastic.co/t/indexes-at-work-packetbeat/79424 "2017-03-21T13:31:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![korsdecaying](https://avatars.discourse-cdn.com/v4/letter/k/dbc845/32.png) [@korsdecaying](https://discuss.elastic.co/u/korsdecaying)\
**Post date:** [March 21, 2017, 1:31pm UTC](https://discuss.elastic.co/t/indexes-at-work-packetbeat/79424/1 "2017-03-21T13:31:05Z")

</div>

How to understand in which the index writes a packetbeat. Why so many indexes were created and how to make everything be written in one. Kibina defines the packetbeat- \* and outputs the information only for 12.03.2017

 ![](https://us1.discourse-cdn.com/elastic/original/3X/a/8/a8b4ed3100c309f79e9c53b7319c6977ebfa77f4.jpg)

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 21, 2017, 3:19pm UTC](https://discuss.elastic.co/t/indexes-at-work-packetbeat/79424/2 "2017-03-21T15:19:33Z")

</div>

By default Packetbeat writes its data to a daily index (an index based on the current UTC day). So you will have packetbeat-2017.03.21 for today and at 00:00 UTC a new index will be created for the next day.

You can customize the index pattern if you like via the `output.elasticsearch.index` config option. You could use a weekly or monthly index pattern to reduce the number of indices. But this decision should be made based on the amount of data being produced and your cluster size and settings.

`index`: [https://www.elastic.co/guide/en/beats/packetbeat/current/elasticsearch-output.html#\_index](https://www.elastic.co/guide/en/beats/packetbeat/current/elasticsearch-output.html#_index)  
Possible formats: [https://godoc.org/github.com/elastic/beats/libbeat/common/dtfmt](https://godoc.org/github.com/elastic/beats/libbeat/common/dtfmt)

---

<div class="post-metadata">

**Author:** ![korsdecaying](https://avatars.discourse-cdn.com/v4/letter/k/dbc845/32.png) [@korsdecaying](https://discuss.elastic.co/u/korsdecaying)\
**Post date:** [March 21, 2017, 3:51pm UTC](https://discuss.elastic.co/t/indexes-at-work-packetbeat/79424/3 "2017-03-21T15:51:08Z")

</div>

Thank you so much.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 18, 2017, 3:51pm UTC](https://discuss.elastic.co/t/indexes-at-work-packetbeat/79424/4 "2017-04-18T15:51:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
