# Is it ok to leave all my metricbeats with the default index name?

**URL:** https://discuss.elastic.co/t/is-it-ok-to-leave-all-my-metricbeats-with-the-default-index-name/182113
**Category:** Beats
**Tags:** metricbeat
**Created:** [May 22, 2019, 2:06am UTC](https://discuss.elastic.co/t/is-it-ok-to-leave-all-my-metricbeats-with-the-default-index-name/182113 "2019-05-22T02:06:30Z")
**Posts on this page:** 1
**Showing post:** 3

<div class="post-metadata">

### Author: ![TsuWeiQuan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsuweiquan/32/46252_2.png) [@TsuWeiQuan](https://discuss.elastic.co/u/TsuWeiQuan)
#### Post date: [May 23, 2019, 8:59am UTC](https://discuss.elastic.co/t/is-it-ok-to-leave-all-my-metricbeats-with-the-default-index-name/182113/3 "2019-05-23T08:59:59Z")

</div>

Thank you for the clarification for the default index name question!

Previously i was trying to change the index name by following the [template loading documentation](https://www.elastic.co/guide/en/beats/metricbeat/7.1/metricbeat-template.html). I am using the 7.0.1 version and did not change much of the setting. I think ILM was controlling my indexes and i did not cover this part of the documentation yet hence rendering my manual template loading to be useless.

> "Starting with version 7.0, Metricbeat uses index lifecycle management by default when it connects to a cluster that supports lifecycle management. Metricbeat loads the default policy automatically and applies it to any indices created by Metricbeat."

Thank you i did not know about this!

> How are you changing the index names?

Currently i am changing my index name by editing the output filter.

```
# Sample Logstash configuration for creating a simple
# Beats -> Logstash -> Elasticsearch pipeline.

input {
  beats {
    port => 5044
  }
}

# The filter part of this file is commented out to indicate that it is
# optional.
filter {
    grok {
        match => { "message" => "%{COMBINEDAPACHELOG}"}
    }
    geoip {
        source => "clientip"
    }
}

output {
    stdout { codec => rubydebug }
    elasticsearch {
     hosts => ["http://esnode1:9200", "http://esnode2:9200", "http://esnode3:9200"]
     index => "itsys2-filebeat-%{+YYYY.MM.dd}"
    }
}

```

I am now learning/trying to receive multiple filebeats logs from windows or linux machines.

May i ask you a question on multiple pipelines?

In a scenario where my logstash instance would like to collect logs from 2 client, a windows machine and linux machine where both have filebeat installed.

Is it correct/recommended to setup 2 pipelines with 2 different port numbers (5044, 5045) and i would configure the windows client to send to 5044 and linux client to send to 5045 pipe?

Or would it be better to just have 1 pipeline on logstash with port 5044 and all clients are send to that pipeline, then i should use conditional filters to seperate the logs?  
i got [this idea](https://discuss.elastic.co/t/multiple-filebeats/153114/5) from a thread that was posted last year.

This is my current setup 🙂

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/3/4356af24867d02622927e3bff40674514fac7323.png)

Thank you @jsoriano

---

_[View the full topic](https://discuss.elastic.co/t/is-it-ok-to-leave-all-my-metricbeats-with-the-default-index-name/182113)._
