# Set Index pattern name in Kibana by auditbeat setup

**URL:** <https://discuss.elastic.co/t/set-index-pattern-name-in-kibana-by-auditbeat-setup/184242>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [June 4, 2019, 6:53pm UTC](https://discuss.elastic.co/t/set-index-pattern-name-in-kibana-by-auditbeat-setup/184242 "2019-06-04T18:53:29Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![thekm1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thekm1/32/35926_2.png) [@thekm1](https://discuss.elastic.co/u/thekm1)\
**Post date:** [June 4, 2019, 6:53pm UTC](https://discuss.elastic.co/t/set-index-pattern-name-in-kibana-by-auditbeat-setup/184242/1 "2019-06-04T18:53:29Z")

</div>

For kibana setup from audit beat:  
(In the both verision I am discribing below, I am using the parameter setup.dashboard.index from "./auditbeat setup" command to set the index-pattern title )

in Version 6.7, I was able to set the index-pattern title by setting the parameter "setup.dashboards.index" and the value of that attribute was used as the title of the index-pattern in Kibana.

But this is not working anymore in version 7.1.1 Elastic Stack. You can set the auditbeat setup parameter "setup.dashboards.index" to whatever you want, but it takes the default value "auditbeat-\*" as index pattern.

Is this maybe a bug? or am I just missing something.

Thank for helping.  
Mathew

---

<div class="post-metadata">

**Author:** ![MarianaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marianad/32/42687_2.png) [@MarianaD](https://discuss.elastic.co/u/MarianaD)\
**Post date:** [June 5, 2019, 8:05am UTC](https://discuss.elastic.co/t/set-index-pattern-name-in-kibana-by-auditbeat-setup/184242/2 "2019-06-05T08:05:14Z")

</div>

hi @thekm1, starting with 7.0, auditbeat will use index lifecycle management by default when it connects to a cluster that supports lifecycle management and will load the default policy automatically which will apply to any indices created by auditbeat ([https://www.elastic.co/guide/en/beats/auditbeat/current/ilm.html](https://www.elastic.co/guide/en/beats/auditbeat/current/ilm.html)).  
If you set setup.ilm.enabled to false and retry your current setup do you see any results? If not, can you provide us with the content of the auditbeat.yml file?

---

<div class="post-metadata">

**Author:** ![thekm1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thekm1/32/35926_2.png) [@thekm1](https://discuss.elastic.co/u/thekm1)\
**Post date:** [June 5, 2019, 8:27am UTC](https://discuss.elastic.co/t/set-index-pattern-name-in-kibana-by-auditbeat-setup/184242/3 "2019-06-05T08:27:34Z")

</div>

Hi @MarianaD  
Thank you for your response.

I tried this as well  
My command looks like this:

> ./auditbeat setup -E 'setup.dashboards.index="myname-\*"' -E 'setup.dashboards.enabled=true' -E 'setup.ilm.enabled=false'

But this also results in the same indexpattern name, which is `auditbeat-*`  
This is my auditbeat.yml file does not contain any big changes:

> auditbeat.modules:
> 
> - module: file\_integrity  
> paths:
> 
> - module: system  
> datasets:
> 
> setup.template.settings:  
> index.number\_of\_shards: 1
> 
> setup.kibana:  
> host: "localhost:5601"
> 
> output.elasticsearch:  
> hosts: ["localhost:9200"]
> 
> processors:
> 
> - add\_host\_metadata: ~
> - add\_cloud\_metadata: ~

Even if I enabled the ilm, I don't see a possibility to set the index-pattern name from the auditbeat config.

Thank you a lot for your effort.

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [June 6, 2019, 1:55am UTC](https://discuss.elastic.co/t/set-index-pattern-name-in-kibana-by-auditbeat-setup/184242/4 "2019-06-06T01:55:40Z")

</div>

Hi @thekm1 - I was able to reproduce the problem. It's indeed a bug and I put up a [fix](https://github.com/elastic/beats/pull/12457) for it. Should work again soon. Thanks for reporting it!

In the meantime, I'm afraid there might not be much else you can do except replace the index pattern name manually. ☹

---

<div class="post-metadata">

**Author:** ![thekm1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thekm1/32/35926_2.png) [@thekm1](https://discuss.elastic.co/u/thekm1)\
**Post date:** [June 6, 2019, 5:02am UTC](https://discuss.elastic.co/t/set-index-pattern-name-in-kibana-by-auditbeat-setup/184242/5 "2019-06-06T05:02:48Z")

</div>

Hi @cwurm  
Thank you for the fix.

Yes, we think as well, that the workaround is [creating](https://www.elastic.co/guide/en/kibana/7.1/saved-objects-api-create.html#_examples_5) or [renaming](https://www.elastic.co/guide/en/kibana/7.1/saved-objects-api-update.html#_examples_7) it.

Thank you for the quick reaction of this issue. 😁

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2019, 5:02am UTC](https://discuss.elastic.co/t/set-index-pattern-name-in-kibana-by-auditbeat-setup/184242/6 "2019-06-27T05:02:53Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
