# Winlogbeat creates indexes based on dates from the past

**URL:** <https://discuss.elastic.co/t/winlogbeat-creates-indexes-based-on-dates-from-the-past/62403>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [October 6, 2016, 3:17pm UTC](https://discuss.elastic.co/t/winlogbeat-creates-indexes-based-on-dates-from-the-past/62403 "2016-10-06T15:17:01Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gmourani](https://avatars.discourse-cdn.com/v4/letter/g/a6a055/32.png) [@gmourani](https://discuss.elastic.co/u/gmourani)\
**Post date:** [October 6, 2016, 3:17pm UTC](https://discuss.elastic.co/t/winlogbeat-creates-indexes-based-on-dates-from-the-past/62403/1 "2016-10-06T15:17:01Z")

</div>

Hello,

I've a strange problem with winlogbeat. I've installed winlogbeat 1.3 on servers and receive directly on elastic port 9200 corrupted log that create indexes starting from December 2015 through now! Event if I delete all winlogbeat indexes, they recreate automatically! I've only one elasticsearch db, no cluster.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 6, 2016, 3:34pm UTC](https://discuss.elastic.co/t/winlogbeat-creates-indexes-based-on-dates-from-the-past/62403/2 "2016-10-06T15:34:16Z")

</div>

Daily indexes are automatically created based on the event `@timestamp`. Winlogbeat uses the event log record's `TimeCreated` field as the `@timestamp` in its events [1]. If you wish to have Winlogbeat only report events that were created within the last N hours/minutes/seconds then you can use the `ignore_older` settings [2]. Note that in Winlogbeat 5.x the ignore\_older filter implementation has been improved and is much faster since it uses a time based query when asking Windows for event log records.

- [1] [https://www.elastic.co/guide/en/beats/winlogbeat/current/exported-fields-common.html#\_timestamp](https://www.elastic.co/guide/en/beats/winlogbeat/current/exported-fields-common.html#_timestamp)
- [2] [https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#\_event\_logs\_ignore\_older](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#_event_logs_ignore_older)

---

<div class="post-metadata">

**Author:** ![gmourani](https://avatars.discourse-cdn.com/v4/letter/g/a6a055/32.png) [@gmourani](https://discuss.elastic.co/u/gmourani)\
**Post date:** [October 6, 2016, 5:09pm UTC](https://discuss.elastic.co/t/winlogbeat-creates-indexes-based-on-dates-from-the-past/62403/3 "2016-10-06T17:09:00Z")

</div>

Thanks Andrew for your quick reply, very appreciated. Here is what am using in the config and it's the default when installing winlogbeat 1.3.

```auto
  event_logs:
    - name: Application
      ignore_older: 72h 
    - name: Security
    - name: System

```

ignore\_older is already set! or maybe the order is important here and having the parameter after -name: Application make it only apply for Application logs ?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 6, 2016, 5:34pm UTC](https://discuss.elastic.co/t/winlogbeat-creates-indexes-based-on-dates-from-the-past/62403/4 "2016-10-06T17:34:11Z")

</div>

> [@gmourani](#):
>
> ignore\_older is already set!

It's only set for the `Application` log in the config you provided. Use the following if you would like a 72h set for each event log.

```auto
  event_logs:
    - name: Application
      ignore_older: 72h 
    - name: Security
      ignore_older: 72h
    - name: System
      ignore_older: 72h

```

> [@gmourani](#):
>
> maybe the order is important here

Order doesn't matter. [`event_logs`](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#_event_logs) is a list of dictionaries (key/value pairs). Each `-` indicates a new entry in the list. Each dictionary configures an individual event log reader. In 1.3 the only options are name (required) and ignore\_older (optional). In 5.x there are few more.

---

<div class="post-metadata">

**Author:** ![gmourani](https://avatars.discourse-cdn.com/v4/letter/g/a6a055/32.png) [@gmourani](https://discuss.elastic.co/u/gmourani)\
**Post date:** [October 7, 2016, 3:38pm UTC](https://discuss.elastic.co/t/winlogbeat-creates-indexes-based-on-dates-from-the-past/62403/5 "2016-10-07T15:38:44Z")

</div>

Thanks Andrew,

It works now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 28, 2016, 3:39pm UTC](https://discuss.elastic.co/t/winlogbeat-creates-indexes-based-on-dates-from-the-past/62403/6 "2016-10-28T15:39:11Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
