# Packet beat - index created monthly

**URL:** <https://discuss.elastic.co/t/packet-beat-index-created-monthly/170203>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [February 27, 2019, 4:17pm UTC](https://discuss.elastic.co/t/packet-beat-index-created-monthly/170203 "2019-02-27T16:17:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![derekmizak](https://avatars.discourse-cdn.com/v4/letter/d/b2d939/32.png) [@derekmizak](https://discuss.elastic.co/u/derekmizak)\
**Post date:** [February 27, 2019, 4:17pm UTC](https://discuss.elastic.co/t/packet-beat-index-created-monthly/170203/1 "2019-02-27T16:17:04Z")

</div>

I want to have packetbeat index created monthly.  
In pcketbeat.yml I have chnaged configuration option as follow:

```auto
#-------------------------- Elasticsearch output ------------------------------
output.elasticsearch:
 
  hosts: ["localhost:9200"]
  output.elasticsearch.index: "packetbeat-%{+yyyy.MM}"
  setup.template.name: "packetbeat"
  setup.template.pattern: "packetbeat-*"

```

However, when I am starting packetbeat - it creates index daily as follow:  
green open packetbeat-6.6.1-2019.02.27

Any idea what am I doing wrong?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 27, 2019, 6:49pm UTC](https://discuss.elastic.co/t/packet-beat-index-created-monthly/170203/2 "2019-02-27T18:49:21Z")

</div>

It looks like your `setup.template.*` options are in the wrong place. Here's an example:

```auto
  setup.template:
    name: 'packetbeat-%{[beat.version]}'
    pattern: 'packetbeat-%{[beat.version]}-*'
    settings:
      index.number_of_shards: 3
      index.number_of_replicas: 1
      index.codec: best_compression

  output.elasticsearch:
    hosts:
      - '{{ es_url }}'
    username: '{{ beat_username }}'
    password: '{{ beat_password }}'
    index: 'packetbeat-%{[beat.version]}-%{+yyyy.MM}'

```

---

<div class="post-metadata">

**Author:** ![derekmizak](https://avatars.discourse-cdn.com/v4/letter/d/b2d939/32.png) [@derekmizak](https://discuss.elastic.co/u/derekmizak)\
**Post date:** [February 27, 2019, 6:52pm UTC](https://discuss.elastic.co/t/packet-beat-index-created-monthly/170203/3 "2019-02-27T18:52:44Z")

</div>

Andrew,

Thanks, it works.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2019, 6:52pm UTC](https://discuss.elastic.co/t/packet-beat-index-created-monthly/170203/4 "2019-03-27T18:52:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
