# Logstash always creates elasticsearch indexes if they dont exist

**URL:** <https://discuss.elastic.co/t/logstash-always-creates-elasticsearch-indexes-if-they-dont-exist/248444>\
**Category:** Logstash\
**Created:** [September 13, 2020, 5:16pm UTC](https://discuss.elastic.co/t/logstash-always-creates-elasticsearch-indexes-if-they-dont-exist/248444 "2020-09-13T17:16:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ejhayes](https://avatars.discourse-cdn.com/v4/letter/e/b782af/32.png) [@ejhayes](https://discuss.elastic.co/u/ejhayes)\
**Post date:** [September 13, 2020, 5:16pm UTC](https://discuss.elastic.co/t/logstash-always-creates-elasticsearch-indexes-if-they-dont-exist/248444/1 "2020-09-13T17:16:27Z")

</div>

I precreated Elasticsearch indexes with alias "logstash-beats" and "logstash-postgres" and that works fine with Logstash output.

However I would also like to completely disable logstash from creating new indexes at all (for when they have not yet been creaed) and for the life of me cannot find a combination of settings below to do that.

No matter which way I include these settings logstash still creates the indexes if they dont exist. Shouldnt having "manage\_template =\> false" do the trick?

I also tried manage\_template =\> "false" with no luck

```auto
  if [docker][container][labels][com_docker_compose_service] == "beats" {
      elasticsearch {
        hosts => ["elasticsearch7:9200"]
        manage_template => false
        template_overwrite => false
        template_name => "logstash-beats"
        ilm_enabled => false
        index => "logstash-beats"
      }
  }
  else if [docker][container][labels][com_docker_compose_service] == "postgres" {
        hosts => ["elasticsearch7:9200"]
        manage_template => false
        template_overwrite => false
        template_name => "logstash-postgres"
        ilm_enabled => false
        index => "logstash-postgres"
      }
  }
  else {
        null{}
  }

```

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [September 13, 2020, 6:01pm UTC](https://discuss.elastic.co/t/logstash-always-creates-elasticsearch-indexes-if-they-dont-exist/248444/2 "2020-09-13T18:01:02Z")

</div>

In your `else if` you don't have `elasticsearch {` which I don't know if it's your issue, but it is an issue.

```auto
  else if [docker][container][labels][com_docker_compose_service] == "postgres" {
     elasticsearch { <---------- THIS
        hosts => ["elasticsearch7:9200"]
        manage_template => false
        template_overwrite => false
        template_name => "logstash-postgres"
        ilm_enabled => false
        index => "logstash-postgres"
      }
  }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 13, 2020, 10:02pm UTC](https://discuss.elastic.co/t/logstash-always-creates-elasticsearch-indexes-if-they-dont-exist/248444/3 "2020-09-13T22:02:01Z")

</div>

I would have thought the simplest solution would be to only write to the two indexes you want to have. Just do not set the index option to anything else.

You can turn off the automatic creation of indexes when written to in elasticsearch. See the Index API [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-index_.html) and search for auto\_create\_index. Not sure what elasticsearch does if you set that. If it returns an error to logstash that may not help much.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 13, 2020, 11:16pm UTC](https://discuss.elastic.co/t/logstash-always-creates-elasticsearch-indexes-if-they-dont-exist/248444/4 "2020-09-13T23:16:30Z")

</div>

If you are indexing Beats data, you really don't want to be putting everything into one big index without using ILM.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 11, 2020, 11:16pm UTC](https://discuss.elastic.co/t/logstash-always-creates-elasticsearch-indexes-if-they-dont-exist/248444/5 "2020-10-11T23:16:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
