# Manage several data stream(s) in the elasitcsearch output with interpolation

**URL:** <https://discuss.elastic.co/t/manage-several-data-stream-s-in-the-elasitcsearch-output-with-interpolation/332981>\
**Category:** Logstash\
**Tags:** datastreams\
**Created:** [May 9, 2023, 5:39pm UTC](https://discuss.elastic.co/t/manage-several-data-stream-s-in-the-elasitcsearch-output-with-interpolation/332981 "2023-05-09T17:39:58Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Ugo\_Sangiorgi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ugo_sangiorgi/32/146361_2.png) [@Ugo\_Sangiorgi](https://discuss.elastic.co/u/Ugo_Sangiorgi)\
**Post date:** [May 9, 2023, 6:23pm UTC](https://discuss.elastic.co/t/manage-several-data-stream-s-in-the-elasitcsearch-output-with-interpolation/332981/2 "2023-05-09T18:23:51Z")

</div>

> Badly formatted index, after interpolation still contains placeholder

Just to give context, in case you are facing the error above, its likely because Elasticsearch output does not accept field names to compose the data\_stream name like it does for a normal "index" name.

This will not work, for instance:

```auto
data_stream => true
data_stream_type => "logs"
data_stream_dataset => "%{[my_field]}"
data_stream_namespace => "%{[@metadata][version]}"

```

You should instead add the fields in a mutate filter, in the `filter` section, like @Pascal_Nuccio mentioned:

```auto
mutate {
    add_field => {
      "[data_stream][type]" => "logs"
      "[data_stream][dataset]" => "%{[my_field]}"
      "[data_stream][namespace]" => "%{[@metadata][version]}"
    }
  }

```

---

_[View the full topic](https://discuss.elastic.co/t/manage-several-data-stream-s-in-the-elasitcsearch-output-with-interpolation/332981)._
