# Indices folder names are random

**URL:** <https://discuss.elastic.co/t/indices-folder-names-are-random/66690>\
**Category:** Logstash\
**Created:** [November 21, 2016, 9:00am UTC](https://discuss.elastic.co/t/indices-folder-names-are-random/66690 "2016-11-21T09:00:23Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![bopa](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bopa](https://discuss.elastic.co/u/bopa)\
**Post date:** [November 21, 2016, 9:00am UTC](https://discuss.elastic.co/t/indices-folder-names-are-random/66690/1 "2016-11-21T09:00:24Z")

</div>

I upgrade my ELK stack from 2.4 to 5.0. after the upgrade all my event log indices are saved as random words. like  
**UcA4wqnpQs2D4AUdBpuRwg**  
**U6a2PE9mTduqAGfbDLT22g**  
**ZzOUMMSRRPukjy6muHRS2w**

Before the upgrade it was **winlogbeat- (date of the event received)**  
my logstash config file as follows,

input {  
beats {  
port =\> 5000  
type =\> "filebeat"  
}  
beats {  
port =\> 5001  
type =\> "winlogbeat"  
}  
}

# Filebeat filter

filter {  
#ignore log comments  
if [message] =~ "^#" {  
drop {}  
}  
grok {  
#patterns\_dir =\> "./patterns"

match =\> {"message" =\> "%{TIMESTAMP\_ISO8601:timestamp} %{IPORHOST:servername1} %{IPORHOST:serverip} %{WORD:verb} %{NOTSPACE:request1} %{GREEDYDATA:request2} %{NUMBER:port} %{IPORHOST:clientip} %{NOTSPACE:protocol} %{NOTSPACE:querystring} %{IPORHOST:servername} %{NOTSPACE:agent} %{NOTSPACE:referrer} %{NUMBER:response} %{NUMBER:sub\_response} %{NUMBER:sc\_status} %{NUMBER:responsetime}"}  
}  
date {  
match =\> ["timestamp", "yyyy-MM-dd HH:mm:ss"]  
locale =\> "en"  
}  
}

# Second filter

#filter {

# if "\_grokparsefailure" in [tags] {

# } else {

# # on success remove the message field to save space

# mutate {

```
# remove_field => ["message", "timestamp", "servername", "servername1"]
#}

```

# }

#}

**output {**  
**elasticsearch {**  
**hosts =\> ["172..........:9200"]**  
**manage\_template =\> false**  
**index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"**  
**document\_type =\> "%{[@metadata][type]}"**  
}  
}  
Now I can't even use curator to clean up old indices. Because their is no detectable patterns in the indices folders.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 21, 2016, 9:12am UTC](https://discuss.elastic.co/t/indices-folder-names-are-random/66690/2 "2016-11-21T09:12:41Z")

</div>

Curator doesn't use directory names, it uses the APIs.

---

<div class="post-metadata">

**Author:** ![bopa](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bopa](https://discuss.elastic.co/u/bopa)\
**Post date:** [November 21, 2016, 9:19am UTC](https://discuss.elastic.co/t/indices-folder-names-are-random/66690/3 "2016-11-21T09:19:09Z")

</div>

then how can I use curator to clean up my old indices for logstash 5.0

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 21, 2016, 9:29am UTC](https://discuss.elastic.co/t/indices-folder-names-are-random/66690/4 "2016-11-21T09:29:01Z")

</div>

It's the same as it ever was - [https://www.elastic.co/guide/en/elasticsearch/client/curator/current/index.html](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/index.html)

---

<div class="post-metadata">

**Author:** ![bopa](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bopa](https://discuss.elastic.co/u/bopa)\
**Post date:** [November 21, 2016, 9:32am UTC](https://discuss.elastic.co/t/indices-folder-names-are-random/66690/5 "2016-11-21T09:32:59Z")

</div>

But why folder names are in gibberish.previously it was recognizable. 😕

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 21, 2016, 9:34am UTC](https://discuss.elastic.co/t/indices-folder-names-are-random/66690/6 "2016-11-21T09:34:12Z")

</div>

It doesn't matter, you shouldn't be looking at the file system to remove things. Use the APIs, like curator 🙂

---

<div class="post-metadata">

**Author:** ![bopa](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bopa](https://discuss.elastic.co/u/bopa)\
**Post date:** [November 21, 2016, 9:36am UTC](https://discuss.elastic.co/t/indices-folder-names-are-random/66690/7 "2016-11-21T09:36:12Z")

</div>

Thanx warkolm. I will try with curator API then 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 19, 2016, 9:36am UTC](https://discuss.elastic.co/t/indices-folder-names-are-random/66690/8 "2016-12-19T09:36:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
