# After configuring the X-PACK log is not coming to logstash

**URL:** <https://discuss.elastic.co/t/after-configuring-the-x-pack-log-is-not-coming-to-logstash/74976>\
**Category:** Logstash\
**Created:** [February 14, 2017, 7:30am UTC](https://discuss.elastic.co/t/after-configuring-the-x-pack-log-is-not-coming-to-logstash/74976 "2017-02-14T07:30:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![shubhrant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubhrant/32/20310_2.png) [@shubhrant](https://discuss.elastic.co/u/shubhrant)\
**Post date:** [February 14, 2017, 7:30am UTC](https://discuss.elastic.co/t/after-configuring-the-x-pack-log-is-not-coming-to-logstash/74976/1 "2017-02-14T07:30:13Z")

</div>

earlier the log was processing normally but after configuring the X-PACK log is not coming ...

my logstash configuration is

input {  
tcp {  
port =\> 5044  
charset =\> "ISO-8859-1"  
}  
}

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

output {  
elasticsearch { hosts =\> ["localhost:9200"] }  
stdout { codec =\> rubydebug }  
}

and the error msg of logstash is

"[2017-02-14T12:51:07,865][ERROR][logstash.inputs.metrics] Failed to create monitoring event {:message=\>"For path: events", :error=\>"LogStash::Instrument::MetricStore::MetricNotFound"}"

some one suggesting me to add "action.auto\_create\_index: .security,.monitoring\*,.watches,.triggered\_watches,.watcher-history\*  
" to the elasticsearch.yml i've added this property but still log is not showing in the kibana dashboard

Kindly help me in this regard ....

thanks...

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [February 24, 2017, 10:30pm UTC](https://discuss.elastic.co/t/after-configuring-the-x-pack-log-is-not-coming-to-logstash/74976/2 "2017-02-24T22:30:22Z")

</div>

Can you run that again with the `--log.level=debug` flag? That will give a full stacktrace allowing us debug further. Thanks!

---

<div class="post-metadata">

**Author:** ![tausif786](https://avatars.discourse-cdn.com/v4/letter/t/bb73d2/32.png) [@tausif786](https://discuss.elastic.co/u/tausif786)\
**Post date:** [March 24, 2017, 11:42am UTC](https://discuss.elastic.co/t/after-configuring-the-x-pack-log-is-not-coming-to-logstash/74976/3 "2017-03-24T11:42:29Z")

</div>

In the output section of elasticsearch in your config mention  
user =\> abc  
password =\> xyz

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 21, 2017, 11:42am UTC](https://discuss.elastic.co/t/after-configuring-the-x-pack-log-is-not-coming-to-logstash/74976/4 "2017-04-21T11:42:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
