# Logstash creating day based indexes

**URL:** <https://discuss.elastic.co/t/logstash-creating-day-based-indexes/49633>\
**Category:** Logstash\
**Created:** [May 10, 2016, 10:04am UTC](https://discuss.elastic.co/t/logstash-creating-day-based-indexes/49633 "2016-05-10T10:04:29Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rajkumar3v](https://avatars.discourse-cdn.com/v4/letter/r/73ab20/32.png) [@rajkumar3v](https://discuss.elastic.co/u/rajkumar3v)\
**Post date:** [May 10, 2016, 10:04am UTC](https://discuss.elastic.co/t/logstash-creating-day-based-indexes/49633/1 "2016-05-10T10:04:29Z")

</div>

Hello guys,

```
           I am new to Logstash, i have configured logstash to process syslog messages and it is creating indexes every day but i need single index for syslog messages. (I have understand logstash will create indexes based on @timestamp) pls help me,,

```

#logstash.conf

input {

```
udp {
   port => 514
   type => syslog
}

```

}

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOG5424SD:time\_stamp} %{WORD:conn\_type} -- %{WORD:action}.\*SRC=%{IP:src\_ip} DST=%{IP:dst\_ip}._PROTO=%{WORD:proto} SPT=%{WORD:src\_port} DPT=%{WORD:dst\_port}._" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
}  
}

output {  
elasticsearch { hosts =\> ["es-1:9200","es-2:9200"] }  
stdout { codec =\> rubydebug }  
}

Thanks,  
Rajkumar

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 10, 2016, 10:11am UTC](https://discuss.elastic.co/t/logstash-creating-day-based-indexes/49633/2 "2016-05-10T10:11:54Z")

</div>

Your post is really badly formatted and hard to read, you may want to edit it.

How do you expect to have a single index that you can delete after 8 months? All your data will be in that single index, irrespective of time.

---

<div class="post-metadata">

**Author:** ![rajkumar3v](https://avatars.discourse-cdn.com/v4/letter/r/73ab20/32.png) [@rajkumar3v](https://discuss.elastic.co/u/rajkumar3v)\
**Post date:** [May 10, 2016, 10:21am UTC](https://discuss.elastic.co/t/logstash-creating-day-based-indexes/49633/3 "2016-05-10T10:21:49Z")

</div>

Hi Mark Walkom,

```
                 sorry for bad format, at least let me know how to create index per month on time based.
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 10, 2016, 10:53am UTC](https://discuss.elastic.co/t/logstash-creating-day-based-indexes/49633/4 "2016-05-10T10:53:05Z")

</div>

Please use the preview pane to the right to see what your messages look like before you post them.

I think using a single index is misguided, but I can't stop you from shooting yourself in the foot. Look at the elasticsearch output's `index` option and keep in mind that the index template that Logstash installs by default only applies to indexes whose names begin with "logstash-".

---

<div class="post-metadata">

**Author:** ![rajkumar3v](https://avatars.discourse-cdn.com/v4/letter/r/73ab20/32.png) [@rajkumar3v](https://discuss.elastic.co/u/rajkumar3v)\
**Post date:** [May 10, 2016, 2:58pm UTC](https://discuss.elastic.co/t/logstash-creating-day-based-indexes/49633/5 "2016-05-10T14:58:16Z")

</div>

Thanks u magnusbaeck, now i am able to create time based index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:58am UTC](https://discuss.elastic.co/t/logstash-creating-day-based-indexes/49633/6 "2017-07-06T04:58:17Z")

</div>


