# Unable to change the default index in Winlogbeat.yaml

**URL:** <https://discuss.elastic.co/t/unable-to-change-the-default-index-in-winlogbeat-yaml/109528>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [November 29, 2017, 7:46am UTC](https://discuss.elastic.co/t/unable-to-change-the-default-index-in-winlogbeat-yaml/109528 "2017-11-29T07:46:34Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![AnithaLingam](https://avatars.discourse-cdn.com/v4/letter/a/e5b9ba/32.png) [@AnithaLingam](https://discuss.elastic.co/u/AnithaLingam)\
**Post date:** [November 29, 2017, 7:46am UTC](https://discuss.elastic.co/t/unable-to-change-the-default-index-in-winlogbeat-yaml/109528/1 "2017-11-29T07:46:34Z")

</div>

I need to push the event logs to the existing index that we already has, but the logs are flowing to new index WInlogbeat. I tried to modify the WInlogbeat.yaml file by entering the index name but it is not working and always saying "[Setup.template.name](http://Setup.template.name) and setup.template.pattern have to be set if index name is modified'. Please provide the solution for this.

#-------------------------- Elasticsearch output ------------------------------  
output.elasticsearch:

# Array of hosts to connect to.

hosts: hostname  
index: "mi-services"

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [November 29, 2017, 7:16pm UTC](https://discuss.elastic.co/t/unable-to-change-the-default-index-in-winlogbeat-yaml/109528/2 "2017-11-29T19:16:00Z")

</div>

As the notes above the configuration shows, you should set `setup.template.name` and `setup.template.pattern`.

```auto
# Optional index name. The default is "winlogbeat" plus date
# and generates [winlogbeat-]YYYY.MM.DD keys.
# In case you modify this pattern you must update setup.template.name and setup.template.pattern accordingly.
index: "winlogbeat-%{[beat.version]}-%{+yyyy.MM.dd}"

```

So you need to set these two options:

```auto
# Template name. By default the template name is "winlogbeat-%{[beat.version]}"
# The template name and pattern has to be set in case the elasticsearch index pattern is modified.
setup.template.name: "winlogbeat-%{[beat.version]}"

# Template pattern. By default the template pattern is "-%{[beat.version]}-*" to apply to the default index settings.
# The first part is the version of the beat and then -* is used to match all daily indices.
# The template name and pattern has to be set in case the elasticsearch index pattern is modified.
setup.template.pattern: "winlogbeat-%{[beat.version]}-*"

```

If you want to send only to index named `mi-services` you can use the following settings:

```auto
setup.template.name: "mi-services"
setup.template.pattern: ""

```

If the end of the name can have suffixes, you could put `setup.template.pattern: "*"` into your config.

---

<div class="post-metadata">

**Author:** ![AnithaLingam](https://avatars.discourse-cdn.com/v4/letter/a/e5b9ba/32.png) [@AnithaLingam](https://discuss.elastic.co/u/AnithaLingam)\
**Post date:** [November 30, 2017, 9:08am UTC](https://discuss.elastic.co/t/unable-to-change-the-default-index-in-winlogbeat-yaml/109528/3 "2017-11-30T09:08:14Z")

</div>

> [@kvch](#):
>
> %{[beat.version]}

Thank you .  
I have updated .yml file as below  
#-------------------------- Elasticsearch output ------------------------------  
output.elasticsearch:

# Array of hosts to connect to.

```
hosts: hostname
template.overwrite: true
setup.template.name: "mi-services"
setup.templa.pattern: "*"	

```

But still the logs are flowing to the Winlogbeat index only unable to push to the existing index. Please provide the solution

---

<div class="post-metadata">

**Author:** ![AnithaLingam](https://avatars.discourse-cdn.com/v4/letter/a/e5b9ba/32.png) [@AnithaLingam](https://discuss.elastic.co/u/AnithaLingam)\
**Post date:** [November 30, 2017, 9:25am UTC](https://discuss.elastic.co/t/unable-to-change-the-default-index-in-winlogbeat-yaml/109528/4 "2017-11-30T09:25:01Z")

</div>

output.elasticsearch:

# Array of hosts to connect to.

```
enabled: true
hosts: hostname  
index: "mi-services"
setup.template.name: "mi-services"
setup.templa.pattern: "*"	

```

This is my .yml file still is saying [Setp.template.name](http://Setp.template.name) and setup.template.pattern needs to be speicfied.Please provide solution for this.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [November 30, 2017, 10:26am UTC](https://discuss.elastic.co/t/unable-to-change-the-default-index-in-winlogbeat-yaml/109528/5 "2017-11-30T10:26:49Z")

</div>

You have a typo in your config. You wrote `setup.templa.pattern` instead of `setup.template.pattern`.

The correct form of your config is the following:

```auto
enabled: true
hosts: hostname  
index: "mi-services"
setup.template.name: "mi-services"
setup.template.pattern: "*"	

```

---

<div class="post-metadata">

**Author:** ![AnithaLingam](https://avatars.discourse-cdn.com/v4/letter/a/e5b9ba/32.png) [@AnithaLingam](https://discuss.elastic.co/u/AnithaLingam)\
**Post date:** [December 4, 2017, 7:16am UTC](https://discuss.elastic.co/t/unable-to-change-the-default-index-in-winlogbeat-yaml/109528/6 "2017-12-04T07:16:45Z")

</div>

> [@kvch](#):
>
> enabled: true  
> hosts: hostname  
> index: "mi-services"  
> setup.template.name: "mi-services"  
> setup.template.pattern: "\*"

I have modified my yml file with your input still it is saying "setup.template.name and setup.template.pattern have to be set if index name is modified'.Please provide resolution for this.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [December 4, 2017, 4:34pm UTC](https://discuss.elastic.co/t/unable-to-change-the-default-index-in-winlogbeat-yaml/109528/8 "2017-12-04T16:34:14Z")

</div>

One solution could be to turn off template handling done by Winlogbeat. So you can omit `setup.template.name` and `setup.template.pattern`.

```auto
setup.template.enabled: true

```

Please note that in this case Winlogbeat would not manage templates at all.

---

<div class="post-metadata">

**Author:** ![AnithaLingam](https://avatars.discourse-cdn.com/v4/letter/a/e5b9ba/32.png) [@AnithaLingam](https://discuss.elastic.co/u/AnithaLingam)\
**Post date:** [December 5, 2017, 9:34am UTC](https://discuss.elastic.co/t/unable-to-change-the-default-index-in-winlogbeat-yaml/109528/9 "2017-12-05T09:34:44Z")

</div>

I have modified the .yml file and included this setting still facing the same issue.

setup.template.enabled: true

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [December 5, 2017, 9:51am UTC](https://discuss.elastic.co/t/unable-to-change-the-default-index-in-winlogbeat-yaml/109528/10 "2017-12-05T09:51:03Z")

</div>

By turning off I meant setting `setup.template.enabled` to `false`.

---

<div class="post-metadata">

**Author:** ![AnithaLingam](https://avatars.discourse-cdn.com/v4/letter/a/e5b9ba/32.png) [@AnithaLingam](https://discuss.elastic.co/u/AnithaLingam)\
**Post date:** [December 5, 2017, 10:06am UTC](https://discuss.elastic.co/t/unable-to-change-the-default-index-in-winlogbeat-yaml/109528/11 "2017-12-05T10:06:27Z")

</div>

output.elasticsearch:

# Array of hosts to connect to.

```
 enabled: true
 hosts: hotname  	
 index: "mi-services"  
 setup.template.enabled: false

```

I tried with false also same issue.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [December 5, 2017, 11:46am UTC](https://discuss.elastic.co/t/unable-to-change-the-default-index-in-winlogbeat-yaml/109528/12 "2017-12-05T11:46:07Z")

</div>

Could you share your whole config?

---

<div class="post-metadata">

**Author:** ![AnithaLingam](https://avatars.discourse-cdn.com/v4/letter/a/e5b9ba/32.png) [@AnithaLingam](https://discuss.elastic.co/u/AnithaLingam)\
**Post date:** [December 5, 2017, 12:20pm UTC](https://discuss.elastic.co/t/unable-to-change-the-default-index-in-winlogbeat-yaml/109528/13 "2017-12-05T12:20:04Z")

</div>

I attached my yml file here, please check once.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [December 5, 2017, 2:28pm UTC](https://discuss.elastic.co/t/unable-to-change-the-default-index-in-winlogbeat-yaml/109528/14 "2017-12-05T14:28:44Z")

</div>

Sorry, I cannot find your full config. Where did you attach it?

---

<div class="post-metadata">

**Author:** ![AnithaLingam](https://avatars.discourse-cdn.com/v4/letter/a/e5b9ba/32.png) [@AnithaLingam](https://discuss.elastic.co/u/AnithaLingam)\
**Post date:** [December 5, 2017, 2:51pm UTC](https://discuss.elastic.co/t/unable-to-change-the-default-index-in-winlogbeat-yaml/109528/15 "2017-12-05T14:51:11Z")

</div>

I attached the file here..

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [December 5, 2017, 2:54pm UTC](https://discuss.elastic.co/t/unable-to-change-the-default-index-in-winlogbeat-yaml/109528/16 "2017-12-05T14:54:42Z")

</div>

I still can't see it. Could you copy it into the textarea?

Also, could you try the template names and patterns like this:

```auto
setup.template.name: mi-services
setup.template.pattern: mi-services
output.elasticsearch.index: mi-services

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 2, 2018, 2:55pm UTC](https://discuss.elastic.co/t/unable-to-change-the-default-index-in-winlogbeat-yaml/109528/17 "2018-01-02T14:55:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
