# Logstash Elasticsearch Output into wrong index

**URL:** <https://discuss.elastic.co/t/logstash-elasticsearch-output-into-wrong-index/182417>\
**Category:** Logstash\
**Created:** [May 23, 2019, 11:48am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-into-wrong-index/182417 "2019-05-23T11:48:21Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Spitza\_Spitza](https://avatars.discourse-cdn.com/v4/letter/s/b38774/32.png) [@Spitza\_Spitza](https://discuss.elastic.co/u/Spitza_Spitza)\
**Post date:** [May 23, 2019, 11:48am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-into-wrong-index/182417/1 "2019-05-23T11:48:21Z")

</div>

Hi,  
I upgraded from 6.8 to 7.1 yesterday and it works well, except that I do not write to the default index "logstash-%{+YYYY.MM.dd}" anymore, instead everything goes into an index just called logstash with no date attached.  
After changing the output to "logstash2-%{+YYYY.MM.dd}" it works again as intended, the logs get written to logstash2-2019.05.23.  
I would like for it to be written to just logstash-timestamp again, but for some reason I cannot figure out how, the output just does not seem to work.

This works:

> output {  
> elasticsearch {  
> hosts =\> ["localhost:9200"]  
> index =\> "logstash2-%{+YYYY.MM.dd}"  
> }

This does not:

> output {  
> elasticsearch {  
> hosts =\> ["localhost:9200"]  
> index =\> "logstash-%{+YYYY.MM.dd}"  
> }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 20, 2019, 12:00pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-into-wrong-index/182417/2 "2019-06-20T12:00:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
