# Weekly indices with name as starting day of the week

**URL:** <https://discuss.elastic.co/t/weekly-indices-with-name-as-starting-day-of-the-week/104307>\
**Category:** Logstash\
**Created:** [October 17, 2017, 10:01pm UTC](https://discuss.elastic.co/t/weekly-indices-with-name-as-starting-day-of-the-week/104307 "2017-10-17T22:01:19Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Manikanth\_Reddy](https://avatars.discourse-cdn.com/v4/letter/m/5fc32e/32.png) [@Manikanth\_Reddy](https://discuss.elastic.co/u/Manikanth_Reddy)\
**Post date:** [October 17, 2017, 10:01pm UTC](https://discuss.elastic.co/t/weekly-indices-with-name-as-starting-day-of-the-week/104307/1 "2017-10-17T22:01:19Z")

</div>

Hi,

As of now, we are using daily indices and are trying to create weekly indices going forward. I have tried configuring indexprefix-%{+xxxx.ww} but it is giving indices by week number out of year. I have been trying to find any solution available but couldn't find any. Could you please help me in this. Thanks.

index name should be: indexprefix\_2017.10.16  
Considering 2017.10.16 as first day in the week.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 18, 2017, 5:17am UTC](https://discuss.elastic.co/t/weekly-indices-with-name-as-starting-day-of-the-week/104307/2 "2017-10-18T05:17:57Z")

</div>

This isn't supported out of the box, but you could certainly write a short piece of Ruby code in a ruby filter that inspects `@timestamp`, figures out the date of closest preceding Monday, and stores that in a field that you reference in the elasticsearch output configuration.

---

<div class="post-metadata">

**Author:** ![Manikanth\_Reddy](https://avatars.discourse-cdn.com/v4/letter/m/5fc32e/32.png) [@Manikanth\_Reddy](https://discuss.elastic.co/u/Manikanth_Reddy)\
**Post date:** [October 18, 2017, 5:16pm UTC](https://discuss.elastic.co/t/weekly-indices-with-name-as-starting-day-of-the-week/104307/3 "2017-10-18T17:16:15Z")

</div>

@magnusbaeck Thanks. I will try to do that but I have one more doubt. We are also using metricbeat for some of our logs. How can I achieve the same when using metricbeat as we don't use logstash for parsing here. Please let me know your thoughts. Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 18, 2017, 6:50pm UTC](https://discuss.elastic.co/t/weekly-indices-with-name-as-starting-day-of-the-week/104307/4 "2017-10-18T18:50:26Z")

</div>

I'm pretty sure you can't do that with Metricbeat.

---

<div class="post-metadata">

**Author:** ![Manikanth\_Reddy](https://avatars.discourse-cdn.com/v4/letter/m/5fc32e/32.png) [@Manikanth\_Reddy](https://discuss.elastic.co/u/Manikanth_Reddy)\
**Post date:** [October 18, 2017, 8:16pm UTC](https://discuss.elastic.co/t/weekly-indices-with-name-as-starting-day-of-the-week/104307/5 "2017-10-18T20:16:36Z")

</div>

@magnusbaeck hmm..is there any way, we can achieve weekly indices in logstash as well as in metricbeat apart from ndexprefix-%{+xxxx.ww}. Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 18, 2017, 8:25pm UTC](https://discuss.elastic.co/t/weekly-indices-with-name-as-starting-day-of-the-week/104307/6 "2017-10-18T20:25:28Z")

</div>

Not that I know of. I don't understand why you care so much about the index names. Why is that relevant?

---

<div class="post-metadata">

**Author:** ![Manikanth\_Reddy](https://avatars.discourse-cdn.com/v4/letter/m/5fc32e/32.png) [@Manikanth\_Reddy](https://discuss.elastic.co/u/Manikanth_Reddy)\
**Post date:** [October 18, 2017, 8:34pm UTC](https://discuss.elastic.co/t/weekly-indices-with-name-as-starting-day-of-the-week/104307/7 "2017-10-18T20:34:54Z")

</div>

Currently we have daily indices. If we move to weekly indices, it is confusing to analyze the historical data as indices will be like indexprefix\_2017.43 because clients need to remember the week number out of year. But If we have weekly indices with name as starting day of the week, then it will be easy to find out, data to which week or date it belongs.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 18, 2017, 8:48pm UTC](https://discuss.elastic.co/t/weekly-indices-with-name-as-starting-day-of-the-week/104307/8 "2017-10-18T20:48:40Z")

</div>

But surely humans aren't choosing index names by hand?

---

<div class="post-metadata">

**Author:** ![Manikanth\_Reddy](https://avatars.discourse-cdn.com/v4/letter/m/5fc32e/32.png) [@Manikanth\_Reddy](https://discuss.elastic.co/u/Manikanth_Reddy)\
**Post date:** [October 18, 2017, 8:57pm UTC](https://discuss.elastic.co/t/weekly-indices-with-name-as-starting-day-of-the-week/104307/9 "2017-10-18T20:57:05Z")

</div>

Yes. Some times we might need that. When we ingest historical logs which are older than couple of weeks, it will be easy to find whether everything looks good or not if we have date's in the index name. But if we have week numbers, then people will be confused and not sure which week their data belongs? Accept my apologies if I didn't understand your question properly.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 19, 2017, 3:53am UTC](https://discuss.elastic.co/t/weekly-indices-with-name-as-starting-day-of-the-week/104307/10 "2017-10-19T03:53:06Z")

</div>

I think you're solving the wrong problem. If index names are confusing to people, don't expose them to the index names. Over and out.

---

<div class="post-metadata">

**Author:** ![Manikanth\_Reddy](https://avatars.discourse-cdn.com/v4/letter/m/5fc32e/32.png) [@Manikanth\_Reddy](https://discuss.elastic.co/u/Manikanth_Reddy)\
**Post date:** [October 19, 2017, 6:34pm UTC](https://discuss.elastic.co/t/weekly-indices-with-name-as-starting-day-of-the-week/104307/11 "2017-10-19T18:34:33Z")

</div>

@magnusbaeck thanks for the help. We are going with week numbers instead of dates 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 16, 2017, 6:34pm UTC](https://discuss.elastic.co/t/weekly-indices-with-name-as-starting-day-of-the-week/104307/12 "2017-11-16T18:34:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
