# Winlogbeat many shards

**URL:** <https://discuss.elastic.co/t/winlogbeat-many-shards/78294>\
**Category:** Elasticsearch\
**Created:** [March 12, 2017, 9:41pm UTC](https://discuss.elastic.co/t/winlogbeat-many-shards/78294 "2017-03-12T21:41:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![brascon01](https://avatars.discourse-cdn.com/v4/letter/b/ac91a4/32.png) [@brascon01](https://discuss.elastic.co/u/brascon01)\
**Post date:** [March 12, 2017, 9:41pm UTC](https://discuss.elastic.co/t/winlogbeat-many-shards/78294/1 "2017-03-12T21:41:47Z")

</div>

Hi All,

i am new with ELK, i have a test cluster with single data node, i have configured one server to use winlogbeat now i am receiving a lots of small shards, i encountered similar issues as the below thread, i am trying to figure out what is best to change from a daily indexing to monthly or yearly index. Can someone please guide me to it.

> [@Testing Elastic Stack and winlogbeat / query exceeds 1000 shards](https://discuss.elastic.co/t/testing-elastic-stack-and-winlogbeat-query-exceeds-1000-shards/77923/22):
>
> @kernelpanic I figured out why: The ignore\_older is only set for the Application log in the config you provided. Use the following if you would like a 72h set for each event log. event\_logs: - name: Application ignore\_older: 72h - name: Security ignore\_older: 72h - name: System ignore\_older: 72h

here is my cluster health:

"cluster\_name" : "Diamond",  
"status" : "yellow",  
"timed\_out" : false,  
"number\_of\_nodes" : 3,  
"number\_of\_data\_nodes" : 1,  
"active\_primary\_shards" : 1682,  
"active\_shards" : 1682,  
"relocating\_shards" : 0,  
"initializing\_shards" : 0,  
"unassigned\_shards" : 1682,  
"delayed\_unassigned\_shards" : 0,  
"number\_of\_pending\_tasks" : 0,  
"number\_of\_in\_flight\_fetch" : 0,  
"task\_max\_waiting\_in\_queue\_millis" : 0,  
"active\_shards\_percent\_as\_number" : 50.0  
Many thanks

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 13, 2017, 9:32pm UTC](https://discuss.elastic.co/t/winlogbeat-many-shards/78294/2 "2017-03-13T21:32:15Z")

</div>

Hey,

you can use the `elasticsearch` output configuration of beats to specify the index name incuding a timespace... see [https://www.elastic.co/guide/en/beats/libbeat/current/config-file-format-namespacing.html](https://www.elastic.co/guide/en/beats/libbeat/current/config-file-format-namespacing.html)

--Alex

---

<div class="post-metadata">

**Author:** ![brascon01](https://avatars.discourse-cdn.com/v4/letter/b/ac91a4/32.png) [@brascon01](https://discuss.elastic.co/u/brascon01)\
**Post date:** [March 14, 2017, 5:32am UTC](https://discuss.elastic.co/t/winlogbeat-many-shards/78294/3 "2017-03-14T05:32:43Z")

</div>

Thank you Alex, appreciate your help, my current logstash beat conf output is:  
output {  
elasticsearch {  
hosts =\> "192.168.1.1.10:9200"  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"

```
document_type => "%{[@metadata][type]}"

```

}

do i have to change it to the below to perform a weekly indexing:

output {  
elasticsearch {  
hosts =\> "192.168.1.1.10:9200"  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.ww}"

```
document_type => "%{[@metadata][type]}"

```

}

---

<div class="post-metadata">

**Author:** ![brascon01](https://avatars.discourse-cdn.com/v4/letter/b/ac91a4/32.png) [@brascon01](https://discuss.elastic.co/u/brascon01)\
**Post date:** [March 18, 2017, 12:57pm UTC](https://discuss.elastic.co/t/winlogbeat-many-shards/78294/4 "2017-03-18T12:57:19Z")

</div>

Maybe this will help someone:

use this

index =\> "%{[@metadata][beat]}-%{+yyyy.ww}"

instead of

index =\> "%{[@metadata][beat]}-%{+YYYY.MM.ww}"

green open winlogbeat-2017.11

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 15, 2017, 12:57pm UTC](https://discuss.elastic.co/t/winlogbeat-many-shards/78294/5 "2017-04-15T12:57:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
