# Lost .raw fields after creating custom index

**URL:** <https://discuss.elastic.co/t/lost-raw-fields-after-creating-custom-index/44395>\
**Category:** Kibana\
**Created:** [March 15, 2016, 6:56am UTC](https://discuss.elastic.co/t/lost-raw-fields-after-creating-custom-index/44395 "2016-03-15T06:56:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sameer\_Dharur](https://avatars.discourse-cdn.com/v4/letter/s/58956e/32.png) [@Sameer\_Dharur](https://discuss.elastic.co/u/Sameer_Dharur)\
**Post date:** [March 15, 2016, 6:56am UTC](https://discuss.elastic.co/t/lost-raw-fields-after-creating-custom-index/44395/1 "2016-03-15T06:56:44Z")

</div>

I just created a custom index using the following config but I don't see the .raw fields anymore - which I need to carry out the desired visualizations. Could somebody please explain exactly what I need to do and how I should go about doing it? Thanks!

Here's my config -

I have modified my config to the following but still getting the same default date-based name for the index. Any suggestions?

input {  
file {  
path =\> "C:/ELK/logstash-2.2.2/sample.log"  
type =\> "sample"  
start\_position =\> "beginning"  
sincedb\_path =\> "C:/ELK/logstash-2.2.2/dbfiles"

}  
}

filter {  
grok { match =\> { "message" =\> "%{DAY:day}\s%{MONTH:month}\s%{MONTHDAY:monthday}\s%{YEAR:year}\s%{TIME:time}\sGMT(?[+-]\d\d\d\d)\s([^)]+)\s%{NUMBER:temp}\s%{NUMBER:light}\s%{GREEDYDATA:room}"} }

}

output {

elasticsearch {

index =\> "templightlogs"

}

stdout{}

}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2016, 7:18am UTC](https://discuss.elastic.co/t/lost-raw-fields-after-creating-custom-index/44395/2 "2016-03-15T07:18:15Z")

</div>

This is really a Logstash question that you might want to move to the Logstash category.

This is because the index template that ships with Logstash and is installed on the ES cluster by default only covers indexes whose names match logstash-\*. You should make a copy of that template, adjust the index name pattern, and have your elasticsearch output use your template file instead.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:59pm UTC](https://discuss.elastic.co/t/lost-raw-fields-after-creating-custom-index/44395/3 "2017-07-06T13:59:06Z")

</div>


