# Question Regarding \`index\` in logstash elasticsearch output plugin

**URL:** <https://discuss.elastic.co/t/question-regarding-index-in-logstash-elasticsearch-output-plugin/116954>\
**Category:** Logstash\
**Created:** [January 25, 2018, 2:25am UTC](https://discuss.elastic.co/t/question-regarding-index-in-logstash-elasticsearch-output-plugin/116954 "2018-01-25T02:25:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![shreyask](https://avatars.discourse-cdn.com/v4/letter/s/ecc23a/32.png) [@shreyask](https://discuss.elastic.co/u/shreyask)\
**Post date:** [January 25, 2018, 2:25am UTC](https://discuss.elastic.co/t/question-regarding-index-in-logstash-elasticsearch-output-plugin/116954/1 "2018-01-25T02:25:35Z")

</div>

I am using logstash elasticsearch output plugin to create time based indices.  
I create index patterns in the following way currently:

```
output {
# other settings
index => "server-netlogs-%{+YYYY.MM.dd}" 
}

```

The events which I want to index have `@timestamp` field on them which represents the source of truth. But the `%{+YYYY.MM.dd}` used in creating the index pattern uses the current timestamp of the instance logstash is running on.

I wanted to know if it is possible to use `@timestamp` for the index as in my case real timestamp != timestamp on the event and I want the timestamp in the event to be used to index the data in ES.

Any pointers would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 25, 2018, 7:12am UTC](https://discuss.elastic.co/t/question-regarding-index-in-logstash-elasticsearch-output-plugin/116954/2 "2018-01-25T07:12:54Z")

</div>

> The events which I want to index have @timestamp field on them which represents the source of truth. But the %{+YYYY.MM.dd} used in creating the index pattern uses the current timestamp of the instance logstash is running on.

No, `%{+YYYY.MM.dd}` uses the `@timestamp` value of each event.

---

<div class="post-metadata">

**Author:** ![shreyask](https://avatars.discourse-cdn.com/v4/letter/s/ecc23a/32.png) [@shreyask](https://discuss.elastic.co/u/shreyask)\
**Post date:** [January 25, 2018, 8:21pm UTC](https://discuss.elastic.co/t/question-regarding-index-in-logstash-elasticsearch-output-plugin/116954/3 "2018-01-25T20:21:01Z")

</div>

Thanks for the clarification. @magnusbaeck I have a mutation filter which mutated `@timestamp` so I had to change the ordering of a couple of filters to make sure `@timestamp` is primed and it does create indices based on that. Really appreciate the swift reply.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 22, 2018, 8:21pm UTC](https://discuss.elastic.co/t/question-regarding-index-in-logstash-elasticsearch-output-plugin/116954/4 "2018-02-22T20:21:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
