# Multiple metricbeat index for each host

**URL:** https://discuss.elastic.co/t/multiple-metricbeat-index-for-each-host/117674
**Category:** Beats
**Tags:** metricbeat
**Created:** [January 30, 2018, 5:14pm UTC](https://discuss.elastic.co/t/multiple-metricbeat-index-for-each-host/117674 "2018-01-30T17:14:21Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![arun\_prasath1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arun_prasath1/32/49539_2.png) [@arun\_prasath1](https://discuss.elastic.co/u/arun_prasath1)
#### Post date: [January 30, 2018, 5:14pm UTC](https://discuss.elastic.co/t/multiple-metricbeat-index-for-each-host/117674/1 "2018-01-30T17:14:21Z")

</div>

Currently i am sending metricbeat data from all the server directly to elastichost:9200. This way metricbeat data from all the server sends data to single metricbeat-dataIs it possible to create separate index for metricbeat data from each server. Current metricbeat configuration is like below.

metricbeat.yml:  
metricbeat.modules:

#------------------------------- System Module -------------------------------

- module: system  
metricsets:
  - cpu
  - load
  - filesystem
  - fsstat
  - memory
  - network
  - process  
enabled: true  
period: 10s  
processes: ['.\*']

output.elasticsearch:  
hosts: ["elastichost:9200"]

For example, I looking for separate metricbeat index for each host.  
metricbeat-host1-dd-mm-yy  
metricbeat-host2-dd-mm-yy

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [January 30, 2018, 5:30pm UTC](https://discuss.elastic.co/t/multiple-metricbeat-index-for-each-host/117674/2 "2018-01-30T17:30:15Z")

</div>

You can change the [index` setting](https://www.elastic.co/guide/en/beats/metricbeat/current/elasticsearch-output.html#index-option-es).

E.g.

```auto
output.elasticsearch:
  index: 'metricbeat-%{[beat.version]}-%{[beat.name]}-%{+yyyy.MM.dd}'

```

This way the index-name is still versioned by the beat version (required to the template mapping still to be applied). I'm using `beat.name` here. The hostname is stored in `beat.hostname`. The `beat.name` is the hostname by default, but can be reconfigured using the global `name` setting in beats.

---

<div class="post-metadata">

### Author: ![arun\_prasath1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arun_prasath1/32/49539_2.png) [@arun\_prasath1](https://discuss.elastic.co/u/arun_prasath1)
#### Post date: [January 30, 2018, 5:35pm UTC](https://discuss.elastic.co/t/multiple-metricbeat-index-for-each-host/117674/3 "2018-01-30T17:35:08Z")

</div>

Nice and simple. I will try this and let you know. Thanks Steffens.

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [January 30, 2018, 5:53pm UTC](https://discuss.elastic.co/t/multiple-metricbeat-index-for-each-host/117674/4 "2018-01-30T17:53:09Z")

</div>

Before making this change, be aware that having a large number of small indices can be very inefficient.

---

<div class="post-metadata">

### Author: ![arun\_prasath1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arun_prasath1/32/49539_2.png) [@arun\_prasath1](https://discuss.elastic.co/u/arun_prasath1)
#### Post date: [January 31, 2018, 12:42pm UTC](https://discuss.elastic.co/t/multiple-metricbeat-index-for-each-host/117674/5 "2018-01-31T12:42:03Z")

</div>

This is what i was looking for. Initially i thought to send to logstash and create separate index using logstash output. But this creates directly in ES.  
@Christian_Dahlqvist - I am using this option for one or two servers to monitor and retain the index for a month.  
Thanks team for your help.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 28, 2018, 12:42pm UTC](https://discuss.elastic.co/t/multiple-metricbeat-index-for-each-host/117674/6 "2018-02-28T12:42:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
