# Logstash logs to "logstash" index instead of "logstash-\<date\>" after update

**URL:** <https://discuss.elastic.co/t/logstash-logs-to-logstash-index-instead-of-logstash-date-after-update/197717>\
**Category:** Elasticsearch\
**Created:** [September 2, 2019, 4:20pm UTC](https://discuss.elastic.co/t/logstash-logs-to-logstash-index-instead-of-logstash-date-after-update/197717 "2019-09-02T16:20:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![holobolo0815](https://avatars.discourse-cdn.com/v4/letter/h/ecc23a/32.png) [@holobolo0815](https://discuss.elastic.co/u/holobolo0815)\
**Post date:** [September 2, 2019, 4:20pm UTC](https://discuss.elastic.co/t/logstash-logs-to-logstash-index-instead-of-logstash-date-after-update/197717/1 "2019-09-02T16:20:25Z")

</div>

Hello,  
I've upgraded without too much hassle from ELK 5.5 across 6.8 to 7.3.

Arriving at 7.3 I notice that the index in ES that LS seems to use is "logstash". Why? Why won't it continue writing to the existing logstash- (in this case logstash-2019.09.02)  
AFAICS the default "index" directive of LS output module "elasticsearch" has not changed and apart for which ES host it should log to, nothing is configured.

Why is it doing this?

**UPDATE** Oh well I guess it's not a problem with ES since I've captured the HTTP stream and the POST request to "/\_bulk" says:  
`{"index":{"_id":null,"_index":"logstash","_type":"_doc","routing":null}}`  
But why?

---

<div class="post-metadata">

**Author:** ![holobolo0815](https://avatars.discourse-cdn.com/v4/letter/h/ecc23a/32.png) [@holobolo0815](https://discuss.elastic.co/u/holobolo0815)\
**Post date:** [September 2, 2019, 4:48pm UTC](https://discuss.elastic.co/t/logstash-logs-to-logstash-index-instead-of-logstash-date-after-update/197717/2 "2019-09-02T16:48:55Z")

</div>

Yeah ok, Logstash 7.0 breaking changes:

> Elasticsearch [Index lifecycle management (ILM)](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/index-lifecycle-management.html) is auto-detected and enabled by default if your Elasticsearch cluster supports it.

RTFM, I guess.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 30, 2019, 4:48pm UTC](https://discuss.elastic.co/t/logstash-logs-to-logstash-index-instead-of-logstash-date-after-update/197717/3 "2019-09-30T16:48:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
