# Which indexes does the new Infrastructure / Logs feature use?

**URL:** <https://discuss.elastic.co/t/which-indexes-does-the-new-infrastructure-logs-feature-use/157920>\
**Category:** Logs\
**Created:** [November 22, 2018, 4:56pm UTC](https://discuss.elastic.co/t/which-indexes-does-the-new-infrastructure-logs-feature-use/157920 "2018-11-22T16:56:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matin\_Nayob](https://avatars.discourse-cdn.com/v4/letter/m/e8c25b/32.png) [@Matin\_Nayob](https://discuss.elastic.co/u/Matin_Nayob)\
**Post date:** [November 22, 2018, 4:56pm UTC](https://discuss.elastic.co/t/which-indexes-does-the-new-infrastructure-logs-feature-use/157920/1 "2018-11-22T16:56:35Z")

</div>

The new logs feature in Kibana 6.5.0 only seems to display live logs from a subset of my indexes.  
Is there a way to configure this yet? I've tried adding specific indexes to the filter, but it doesnt display any data.

Thanks!

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [November 23, 2018, 12:59pm UTC](https://discuss.elastic.co/t/which-indexes-does-the-new-infrastructure-logs-feature-use/157920/2 "2018-11-23T12:59:45Z")

</div>

Hi @Matin_Nayob

thank you for trying out version 6.5 of the Elastic Stack! :elasticheart:

It is currently designed to work with filebeat out-of-the box. That said, there is some flexibility if you're willing to change the Kibana configuration file (there will be a UI for that soon as well). The index pattern used to read log events can be changed via the `xpack.infra.sources.default.logAlias` setting, which can contain any [index pattern supported by Elasticsearch](https://www.elastic.co/guide/en/elasticsearch/reference/current/multi-index.html), e.g.

```auto
xpack.infra:
  sources:
    default:
      logAlias: 'filebeat-*,different-filebeat-*'

```

---

<div class="post-metadata">

**Author:** ![Matin\_Nayob](https://avatars.discourse-cdn.com/v4/letter/m/e8c25b/32.png) [@Matin\_Nayob](https://discuss.elastic.co/u/Matin_Nayob)\
**Post date:** [November 28, 2018, 10:00am UTC](https://discuss.elastic.co/t/which-indexes-does-the-new-infrastructure-logs-feature-use/157920/3 "2018-11-28T10:00:19Z")

</div>

Excellent, that worked perfectly!

If its of any interest to you, we capture and manually (via logstash) parse a lot of the different log types that filebeat has modules for (like apache and nginx), rather than using the filebeat modules themselves. We do this because we have our own custom log formats for those systems.

Being able to select non-filebeat indexes from the UI would be perfect for our use case.

Either way, thank you very much for your help, really appreciate the amazing work you guys do!

Matin

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [November 28, 2018, 6:26pm UTC](https://discuss.elastic.co/t/which-indexes-does-the-new-infrastructure-logs-feature-use/157920/4 "2018-11-28T18:26:21Z")

</div>

Thank you, that feedback is very valuable indeed. A UI to change those settings more conveniently is being worked on.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2018, 6:26pm UTC](https://discuss.elastic.co/t/which-indexes-does-the-new-infrastructure-logs-feature-use/157920/5 "2018-12-26T18:26:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
