# More than 1 day's log per index?

**URL:** <https://discuss.elastic.co/t/more-than-1-days-log-per-index/62224>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-monitoring\
**Created:** [October 4, 2016, 10:08pm UTC](https://discuss.elastic.co/t/more-than-1-days-log-per-index/62224 "2016-10-04T22:08:29Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![suanmeiguo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suanmeiguo/32/11758_2.png) [@suanmeiguo](https://discuss.elastic.co/u/suanmeiguo)\
**Post date:** [October 4, 2016, 10:08pm UTC](https://discuss.elastic.co/t/more-than-1-days-log-per-index/62224/1 "2016-10-04T22:08:29Z")

</div>

It looks like Marvel create one index per day. Things like `.marvel-es-1-2016.10.04`. Can I configure this to be a bigger date range? for example one index per week or per month?

I want to keep a longer history but don't want to have too many indexes like `.marvel-es-1-2016.10.04`.

Thank you!

---

<div class="post-metadata">

**Author:** ![pickypg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pickypg/32/62409_2.png) [@pickypg](https://discuss.elastic.co/u/pickypg)\
**Post date:** [October 4, 2016, 10:43pm UTC](https://discuss.elastic.co/t/more-than-1-days-log-per-index/62224/2 "2016-10-04T22:43:46Z")

</div>

Yes, within `config/elasticsearch.yml`, you can set the time format of the index for the exporters:

```auto
marvel.agent.exporters:
  id1:
    # ...
    index.name.time_format: YYYY.ww

```

This will change the index pattern that it uses when it creates indices, which the UI-side will pick up automatically. This is better documented in 5.x, but [it's shown in 2.x docs under the large exporter block](https://www.elastic.co/guide/en/marvel/current/configuration.html).

---

<div class="post-metadata">

**Author:** ![bohyun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bohyun/32/10087_2.png) [@bohyun](https://discuss.elastic.co/u/bohyun)\
**Post date:** [October 4, 2016, 10:46pm UTC](https://discuss.elastic.co/t/more-than-1-days-log-per-index/62224/3 "2016-10-04T22:46:20Z")

</div>

Hi Vincent,

Curious to know why you don't want too many indices. Is it because it's hard to maintain?

Thanks,  
Bohyun

---

<div class="post-metadata">

**Author:** ![suanmeiguo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suanmeiguo/32/11758_2.png) [@suanmeiguo](https://discuss.elastic.co/u/suanmeiguo)\
**Post date:** [October 4, 2016, 11:04pm UTC](https://discuss.elastic.co/t/more-than-1-days-log-per-index/62224/4 "2016-10-04T23:04:47Z")

</div>

Too many index means too many segments to maintain, which means too many CPU, Ram for elasticsearch to use on those indexes. I would rather put those resource onto my data.

Cause I learned from elasticsearch: we don't want too many shards/segments.

---

<div class="post-metadata">

**Author:** ![suanmeiguo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suanmeiguo/32/11758_2.png) [@suanmeiguo](https://discuss.elastic.co/u/suanmeiguo)\
**Post date:** [October 4, 2016, 11:05pm UTC](https://discuss.elastic.co/t/more-than-1-days-log-per-index/62224/5 "2016-10-04T23:05:17Z")

</div>

Awesome! Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:41pm UTC](https://discuss.elastic.co/t/more-than-1-days-log-per-index/62224/6 "2017-07-06T13:41:55Z")

</div>


