# Badly formatted index, after interpolation still contains placeholder

**URL:** <https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder/354231>\
**Category:** Logstash\
**Created:** [February 27, 2024, 1:22pm UTC](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder/354231 "2024-02-27T13:22:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jirka\_Liska](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jirka_liska/32/117513_2.png) [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Post date:** [February 27, 2024, 1:22pm UTC](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder/354231/1 "2024-02-27T13:22:22Z")

</div>

Hello, after migration to the 8.12.1 I've started getting error "Badly formatted index, after interpolation still contains placeholder". When I'm trying to process report with Filebeat. More interesting is I get this message on one type of reports and for the other it works..

Output config

```auto
output {
  if [type] == "aws" {
    elasticsearch {
      index => "test-report-%{[PK]}"    
      ecs_compatibility => v8
			hosts => "${ELASTIC_HOST}"
      #ssl => true
      #ssl_certificate_verification => false
      #api_key => "${ELASTIC_ID}:${ELASTIC_KEY}"
    }
  }
}

```

Filter where I create PK field

```auto
    grok {
      match => {
        "[log][file][path]" => ["(?:%{BASE10NUM:PK}-)"]
      }
    }

```

any ideas? Could be done by wrong mapping in Kibana?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 27, 2024, 2:46pm UTC](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder/354231/2 "2024-02-27T14:46:39Z")

</div>

> [@Jirka\_Liska](#):
>
> Badly formatted index, after interpolation still contains placeholder

This means that the field that you are using in your index name does not exist in the event.

For example, you have this as your index name `test-report-%{[PK]}`, so it will get the value of the field `PK` and replace it, but if the field `PK` does not exist in your document, this value will not be replaced and you will get this error.

You need to check your grok if it is really working.

Alternatively you can add this filter to populate the `PK` field in case it does not exist and you can validate what was the issue.

```auto
filter {
    if ![PK] {
        mutate {
            add_field => { "PK" => "no-pk" }
        }
    }
}

```

Then if the field `PK` does not exist in the document, it will be created with the value `no-pk` and your index in this case will be named `test-report-no-pk`.

---

<div class="post-metadata">

**Author:** ![Jirka\_Liska](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jirka_liska/32/117513_2.png) [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Post date:** [February 28, 2024, 12:38pm UTC](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder/354231/3 "2024-02-28T12:38:17Z")

</div>

Thank you for your response! Thanks to your input I was able to find and fix my issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2024, 12:38pm UTC](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder/354231/4 "2024-03-27T12:38:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
