# Metricbeat new index creation

**URL:** <https://discuss.elastic.co/t/metricbeat-new-index-creation/80204>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [March 27, 2017, 8:21pm UTC](https://discuss.elastic.co/t/metricbeat-new-index-creation/80204 "2017-03-27T20:21:25Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [March 27, 2017, 8:21pm UTC](https://discuss.elastic.co/t/metricbeat-new-index-creation/80204/1 "2017-03-27T20:21:26Z")

</div>

Hello if i have multiple systems using metricbeat and all sending to the same Elasticsearch cluster is there a way to use the already made graphs for each different index of metricbeat. Each cluster i am shipping with a different index name.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 28, 2017, 2:38pm UTC](https://discuss.elastic.co/t/metricbeat-new-index-creation/80204/2 "2017-03-28T14:38:20Z")

</div>

Are you referring to the Kibana dashboards? You could define a different index-pattern with `-i`: [https://www.elastic.co/guide/en/beats/libbeat/master/import-dashboards.html](https://www.elastic.co/guide/en/beats/libbeat/master/import-dashboards.html) BTH I'm not 100% sure what will happen if you will load the same visualisations multiple times for different patterns. Never tried it. I worry that some parts will overwrite each other. @monica WDYT?

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [March 28, 2017, 2:54pm UTC](https://discuss.elastic.co/t/metricbeat-new-index-creation/80204/3 "2017-03-28T14:54:06Z")

</div>

How do i go about creating the same dashboard but for a different cluster?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 30, 2017, 8:00am UTC](https://discuss.elastic.co/t/metricbeat-new-index-creation/80204/4 "2017-03-30T08:00:12Z")

</div>

Different cluster = different Kibana instance? Then you can just import it there too and use a different elasticsearch target in import\_dashboards.

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [March 30, 2017, 6:58pm UTC](https://discuss.elastic.co/t/metricbeat-new-index-creation/80204/5 "2017-03-30T18:58:02Z")

</div>

hmm i think i am confused. we have the same ELK cluster but different hosts we want to monitor. I can change that in the imports?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 31, 2017, 2:03pm UTC](https://discuss.elastic.co/t/metricbeat-new-index-creation/80204/6 "2017-03-31T14:03:57Z")

</div>

So you have multiple metricbeat instances sending data into one Elasticsearch cluster. You can filter by hosts in Kibana and don't need to import dashboards multiple times.

You mentioned before `different cluster` so I assume you meant elasticsearch cluster. Is my above assumption now correct?

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [March 31, 2017, 4:07pm UTC](https://discuss.elastic.co/t/metricbeat-new-index-creation/80204/7 "2017-03-31T16:07:57Z")

</div>

correct, I was wondering if there is a way to sort by index? I have each set of clusters sending data with a different Index. It seems when creating dashboards it defaults to the Metricbeat Index but there is no way to change that Index.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [April 3, 2017, 7:03am UTC](https://discuss.elastic.co/t/metricbeat-new-index-creation/80204/8 "2017-04-03T07:03:24Z")

</div>

You can create your own index pattern in Kibana. For example if your indicies are `metricbeat-cluster1-*` etc. you could create index pattern for each cluster.

What is your end goal? Having dashboards for each cluster? Or being able to view on data for each cluster? Because the second one you could solve with applying filters based on same fields for example. So you still have the overall view but can dig into each (or multiple clusters).

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [April 3, 2017, 1:18pm UTC](https://discuss.elastic.co/t/metricbeat-new-index-creation/80204/9 "2017-04-03T13:18:12Z")

</div>

Having dashboards for each cluster based off the index that is passed with metricbeat.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [April 4, 2017, 2:46pm UTC](https://discuss.elastic.co/t/metricbeat-new-index-creation/80204/10 "2017-04-04T14:46:58Z")

</div>

If each "group of machines" (cluster) will have the same dashboards, why do you want to import it multiple times? I think I'm missing something. Is this about different access rights to the data?

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [April 4, 2017, 3:02pm UTC](https://discuss.elastic.co/t/metricbeat-new-index-creation/80204/11 "2017-04-04T15:02:18Z")

</div>

the dashboards need to reflect each different cluster. Instead of filtering the data host by host, i wanted to see if there is a way to do it by Index? It seems it just defaults to the metricbeat index everytime.

---

<div class="post-metadata">

**Author:** ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)\
**Post date:** [April 5, 2017, 2:59pm UTC](https://discuss.elastic.co/t/metricbeat-new-index-creation/80204/12 "2017-04-05T14:59:06Z")

</div>

I am afraid that you are not able to have the same dashboard for multiple indexes in one Kibana instance, as all the dashboard dependecies (searches, visualizations) will be overwritten.  
There is not a simple solution that I can think of now. One option would be to import first the dashboards for one index (there is an option to change the default index name in the import script) and then export the dashboards using the [python script](https://github.com/elastic/beats/blob/master/dev-tools/export_dashboards.py), and then change manually the name of all the visualizations, searches and dashboards.

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [April 5, 2017, 3:44pm UTC](https://discuss.elastic.co/t/metricbeat-new-index-creation/80204/13 "2017-04-05T15:44:48Z")

</div>

Should I set up more than one kibana instance? I'm trying to figure out best solution for this.

---

<div class="post-metadata">

**Author:** ![tsullivan93](https://avatars.discourse-cdn.com/v4/letter/t/58956e/32.png) [@tsullivan93](https://discuss.elastic.co/u/tsullivan93)\
**Post date:** [April 5, 2017, 4:10pm UTC](https://discuss.elastic.co/t/metricbeat-new-index-creation/80204/14 "2017-04-05T16:10:07Z")

</div>

Hi all,

I am currently facing a similar issue as kmroz and I thought I would lend my current plan of action which seems promising thus far. Essentially I have different hosts that I all want to use the metricbeat index template, but I do not want them all to be on the same dashboard. I understand there are ways to filter out certain hosts, but I wasn't crazy about the idea of creating a inventive regex every time I added a new host to the metricbeat index. What I decided to do was download the metricbeat template from your github Monica ([Here for kmroz](https://github.com/monicasarbu/metricbeat-dashboards)) and alter the titles on each visualization and dashboard json as well as altering the title in the index pattern json. I then used the import script to point to my instance of Kibana where I already have metricbeat dashboards running. I ran the script with -i (renaming the index to match the title specified in the pattern json), the -dir (to point to my saved version of the metricbeat template), and the -es (to point to my kibana instance) parameters. This allowed me to use the metricbeat template for my new index without overwriting the original metricbeat index's dashboards and visualizations. Now this took some effort to manually changed the json, but this was only a POC. I plan to programmatically have it alter the titles in the json for any future indicies I may want to add.

---

<div class="post-metadata">

**Author:** ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)\
**Post date:** [April 5, 2017, 8:00pm UTC](https://discuss.elastic.co/t/metricbeat-new-index-creation/80204/15 "2017-04-05T20:00:33Z")

</div>

If you are using indexes of format `metricbeat-cluster1-*`, `metricbeat-cluster2-*`, etc, an option (didn't test this) would be to use the default generated index pattern (`metricbeat-*` in Kibana) to match all the above. Instead of defining an index pattern in Kibana for each index template, you could define a single index pattern (`metricbeat-*`) and use it into all visualizations. This way, having a dashboard for all indexes is possible and you can use the filtering capabilities in Kibana to select the data coming from a cluser or another.

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [April 5, 2017, 8:20pm UTC](https://discuss.elastic.co/t/metricbeat-new-index-creation/80204/16 "2017-04-05T20:20:33Z")

</div>

Ok thanks @tsullivan93 @monica I will take both of your guys comments into consideration and see which one works out for me. I appreciate the quick responses!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2017, 8:20pm UTC](https://discuss.elastic.co/t/metricbeat-new-index-creation/80204/17 "2017-05-03T20:20:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
