# Loading index patterns to use in Kibana

**URL:** <https://discuss.elastic.co/t/loading-index-patterns-to-use-in-kibana/92356>\
**Category:** Kibana\
**Created:** [July 8, 2017, 9:02am UTC](https://discuss.elastic.co/t/loading-index-patterns-to-use-in-kibana/92356 "2017-07-08T09:02:03Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![BentCoder](https://avatars.discourse-cdn.com/v4/letter/b/c4cdca/32.png) [@BentCoder](https://discuss.elastic.co/u/BentCoder)\
**Post date:** [July 8, 2017, 9:02am UTC](https://discuss.elastic.co/t/loading-index-patterns-to-use-in-kibana/92356/1 "2017-07-08T09:02:03Z")

</div>

Hi,

Is there any point/need/advantage for loading index patterns for filebeat etc. if we use custom index names in elasticsearch output like shown below? For example, If I won't use any of "packetbeat-_", "topbeat-_", "filebeat-_" and "winlogbeat-_" in Kibana, why should I load them?

Thanks

**Logstash config**

```
output {
    elasticsearch {
        hosts => ["localhost:9200"]
        sniffing => true
        manage_template => false
        index => "my-index"
    }
}
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 8, 2017, 9:28am UTC](https://discuss.elastic.co/t/loading-index-patterns-to-use-in-kibana/92356/2 "2017-07-08T09:28:15Z")

</div>

If you use custom patterns then you need to add them in manually.

> [@BentCoder](#):
>
> index =\> "my-index"

That's probably not a good idea if it's time based data.

---

<div class="post-metadata">

**Author:** ![BentCoder](https://avatars.discourse-cdn.com/v4/letter/b/c4cdca/32.png) [@BentCoder](https://discuss.elastic.co/u/BentCoder)\
**Post date:** [July 8, 2017, 9:33am UTC](https://discuss.elastic.co/t/loading-index-patterns-to-use-in-kibana/92356/3 "2017-07-08T09:33:43Z")

</div>

I add them manually but never use them. Instead I use `my-index` in Kibana dashboard. Hence reason I am asking. If I won't use them why should I add them in first place anyway? I want to know if I am missing out some great features when I ignore them.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 8, 2017, 9:21pm UTC](https://discuss.elastic.co/t/loading-index-patterns-to-use-in-kibana/92356/4 "2017-07-08T21:21:56Z")

</div>

If you don't add the index pattern for the data in Elasticsearch then you can't do much with Kibana.

---

<div class="post-metadata">

**Author:** ![BentCoder](https://avatars.discourse-cdn.com/v4/letter/b/c4cdca/32.png) [@BentCoder](https://discuss.elastic.co/u/BentCoder)\
**Post date:** [July 11, 2017, 6:59pm UTC](https://discuss.elastic.co/t/loading-index-patterns-to-use-in-kibana/92356/5 "2017-07-11T18:59:57Z")

</div>

I still don't understand the difference between `index => "my-index"` and `index => "filebeat-my-index"`.

I don't see any difference between selecting `filebeat-*` and `my-index` for "Index name or pattern" field in Kibana GUI. Both logs have exactly the same fields/data in Elasticsearch.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 12, 2017, 1:08am UTC](https://discuss.elastic.co/t/loading-index-patterns-to-use-in-kibana/92356/6 "2017-07-12T01:08:33Z")

</div>

> [@BentCoder](#):
>
> I still don't understand the difference between index =\> "my-index" and index =\> "filebeat-my-index".

It depends on which index you are sending the data to.

> [@BentCoder](#):
>
> index =\> "my-index"

That is what you have in your config, so that is what you should set in Kibana.

---

<div class="post-metadata">

**Author:** ![BentCoder](https://avatars.discourse-cdn.com/v4/letter/b/c4cdca/32.png) [@BentCoder](https://discuss.elastic.co/u/BentCoder)\
**Post date:** [July 12, 2017, 12:41pm UTC](https://discuss.elastic.co/t/loading-index-patterns-to-use-in-kibana/92356/7 "2017-07-12T12:41:49Z")

</div>

I meant;

Whether I sent the data to

- `my-index` and select `my-index`  
OR
- `filebeat-my-index` and select `filebeat-*`

as index pattern in Kibana GUI, there is no difference in logs. Logs in both Elasticsearch indexes have exactly the same fields/data. That's why I don't understand why I cannot do mush with Kibana as you said above.

> If you don't add the index pattern for the data in Elasticsearch then you can't do much with Kibana.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2017, 12:41pm UTC](https://discuss.elastic.co/t/loading-index-patterns-to-use-in-kibana/92356/8 "2017-08-09T12:41:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
