# Non timeseries beat indexes

**URL:** <https://discuss.elastic.co/t/non-timeseries-beat-indexes/209725>\
**Category:** Beats\
**Created:** [November 27, 2019, 4:26pm UTC](https://discuss.elastic.co/t/non-timeseries-beat-indexes/209725 "2019-11-27T16:26:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Blake\_Wills](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blake_wills/32/45778_2.png) [@Blake\_Wills](https://discuss.elastic.co/u/Blake_Wills)\
**Post date:** [November 27, 2019, 4:26pm UTC](https://discuss.elastic.co/t/non-timeseries-beat-indexes/209725/1 "2019-11-27T16:26:22Z")

</div>

Is it possible to setup beats (auditbeat / metricbeat / winlogbeat) to not use timeseries indexes?

I've orderridden the index name in the respective config files but the template (via [beat].exe setup - manual loading) creates and applies the template to a new timeseries index, using the name I specified as the base.

I've tried setting the index name as part of the setup command but as said, this just uses that name as a base and appends the beat version and date.

The reason we want non timeseries indexes is because we don't want hundreds of very small shards, we would rather rollover once the index gets to an appropriate size. This is especially true for auditbeat, which we are only using for file change alerts; daily indexes would have little to no documents.

The only way I can think of getting around this is to export the template, change the values causing the daily indexes and then call the template api myself.

Is there any other way?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [November 28, 2019, 4:04pm UTC](https://discuss.elastic.co/t/non-timeseries-beat-indexes/209725/2 "2019-11-28T16:04:04Z")

</div>

Have you tried using the ILM manager of ES with Filebeat: [https://www.elastic.co/guide/en/beats/filebeat/current/ilm.html](https://www.elastic.co/guide/en/beats/filebeat/current/ilm.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2019, 6:04pm UTC](https://discuss.elastic.co/t/non-timeseries-beat-indexes/209725/3 "2019-12-26T18:04:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
