When you use Wazuh’s default configuration for the Elastic Stack (by following the installation guide) alerts are indexed in elasticsearch with the following naming convention:
This means you are not only specifying an index name, but also defining daily indices for your alerts.
This behaviour is laid out in the Logstash configuration file:
The pipeline’s output specifies the index name the alert will end up belonging to.
Logstash takes care of creating the index in case it is not present in elasticsearch.