# Time Based Indices

**URL:** <https://discuss.elastic.co/t/time-based-indices/131510>\
**Category:** Elasticsearch\
**Created:** [May 11, 2018, 3:58pm UTC](https://discuss.elastic.co/t/time-based-indices/131510 "2018-05-11T15:58:14Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jose\_Campos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jose_campos/32/11259_2.png) [@Jose\_Campos](https://discuss.elastic.co/u/Jose_Campos)\
**Post date:** [May 11, 2018, 3:58pm UTC](https://discuss.elastic.co/t/time-based-indices/131510/1 "2018-05-11T15:58:14Z")

</div>

Hi, I was trying to create an index based on time, but with a different name. For example if I want to create an index called "nginx- \*", at the time of consulting will be nginx-2018.11.05, but I need to geolocate, and reading articles, can only be "logstash" the name of the index to create the geoip.

So in what way could I create an index based on time with geolocation ?, and how do I call it in logstash ?.

This is my current .conf.

```
input {

    file {
            path => "/var/log/nginx"
            start_position => "beginning"
            stat_interval => 1
            discover_interval => 15
            sincedb_path => "/dev/null"
            sincedb_write_interval => 15
         }

  }

filter {

grok {
   patterns_dir => "/etc/logstash/patterns/"
   match => { "message" => "%{NGINXDATE:logtimestamp}" }
}

date { match => ["logtimestamp", "MMM dd HH:mm:ss", "MMM d HH:mm:ss"] }

grok {

    patterns_dir => "/etc/logstash/patterns"
    match => { "message" => "%{NGINX_ACCESS}" }
    remove_tag => ["_grokparsefailure"]
    add_tag => ["nginx_access"]
}

grok {
    match => { "agent" => "[(]%{DATA:OS}; %{DATA:version}; %{DATA:device}[)]" }
    match => { "agent" => "[(]%{DATA:OS}[)]" }
}

geoip {
           source => "clientip"
}

mutate {
remove_field => ["type", "path", "host"]
}
}

output {

elasticsearch {
            hosts => ["192.168.1.105:9200"]
            index => "logstash-nginx"
               }
    }

```

I'm new to this, sorry.

Regards,

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 14, 2018, 5:04am UTC](https://discuss.elastic.co/t/time-based-indices/131510/2 "2018-05-14T05:04:39Z")

</div>

> [@Jose\_Campos](#):
>
> but I need to geolocate, and reading articles, can only be "logstash" the name of the index to create the geoip.

This can be set up for any index, but Logstash comes with a default index template for the `logstash-*` index pattern. You can retrieve this [index template](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/indices-templates.html), update it to match your index pattern and then store it back in Elasticsearch under an appropriate name.

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [May 14, 2018, 6:49am UTC](https://discuss.elastic.co/t/time-based-indices/131510/3 "2018-05-14T06:49:19Z")

</div>

> [@Jose\_Campos](#):
>
> index =\> "logstash-nginx"

your index is pre with logstash not nginx  
can with \*nginx \* in kibana create parrten.

---

<div class="post-metadata">

**Author:** ![Jose\_Campos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jose_campos/32/11259_2.png) [@Jose\_Campos](https://discuss.elastic.co/u/Jose_Campos)\
**Post date:** [May 14, 2018, 12:55pm UTC](https://discuss.elastic.co/t/time-based-indices/131510/5 "2018-05-14T12:55:02Z")

</div>

Thanks for support.

But creating \* nginx \*, will create a time based Index?, for e.g. nginx-2018.05.14?.

Regards,

---

<div class="post-metadata">

**Author:** ![Jose\_Campos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jose_campos/32/11259_2.png) [@Jose\_Campos](https://discuss.elastic.co/u/Jose_Campos)\
**Post date:** [May 14, 2018, 2:15pm UTC](https://discuss.elastic.co/t/time-based-indices/131510/6 "2018-05-14T14:15:11Z")

</div>

Hi, I think I can give an alternative solution to this, thinking that creating a new template is a bit difficult, and solving my doubt to create time-based indexes, configure this.

Logstash

```
output {

elasticsearch {
    hosts => ["192.168.1.105:9200"]
    index => "logstash-nginx-%{+ YYYY.MM.dd}"
}
}

```

Kibana

logstash-nginx-\*

Now, when I run "get \_cat / shards", I get the following.

logstash-2018.05.14  
logstash-nginx-2018.05.14

Can you tell me why you create two indexes, if I only define logstash-nginx?

regards,

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [May 15, 2018, 12:45am UTC](https://discuss.elastic.co/t/time-based-indices/131510/7 "2018-05-15T00:45:37Z")

</div>

delete the indices and try again? see which create.  
logstash maybe other create.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 12, 2018, 12:45am UTC](https://discuss.elastic.co/t/time-based-indices/131510/8 "2018-06-12T00:45:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
