Hello
riccait,Yes, it is possible to create different indexes for each label configured in the agents.
What you have to do is to modify the filebeat pipeline so that it generates different indexes according to the label. To do this, you must modify the file:
/usr/share/filebeat/module/wazuh/alerts/ingest/pipeline.jsonAdd a block for each label that you want to generate a different index, for example:
{
"date_index_name": {
"if": "ctx?.agent?.labels?.customers != 'riccait'",
"field": "timestamp",
"date_rounding": "d",
"index_name_prefix":"{{fields.index_prefix}}riccait-",
"index_name_format": "yyyy.MM.dd",
"ignore_failure": true
}In this way and for this case we will generate an index with name:
wazuh-alerts-4.4-riccait-yyyy.MM.ddIt is also necessary to apply the changes in the filebeat pipeline:
filebeat setup --pipelines --modules wazuhFinally, you must add these index pattern names in the template:
https://documentation.wazuh.com/current/user-manual/elasticsearch/configure-indices.html#indices-configurationIf you have any doubt or problem, do not hesitate to tell me about it. Thanks for using Wazuh!
Best regards,
Jose.