# Beat not creating index on start

**URL:** <https://discuss.elastic.co/t/beat-not-creating-index-on-start/65696>\
**Category:** Beats\
**Created:** [November 10, 2016, 4:04pm UTC](https://discuss.elastic.co/t/beat-not-creating-index-on-start/65696 "2016-11-10T16:04:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![tostasqb](https://avatars.discourse-cdn.com/v4/letter/t/7feea3/32.png) [@tostasqb](https://discuss.elastic.co/u/tostasqb)\
**Post date:** [November 10, 2016, 4:04pm UTC](https://discuss.elastic.co/t/beat-not-creating-index-on-start/65696/1 "2016-11-10T16:04:02Z")

</div>

Just started using Beats and Version 5.

After installing filebeat and metricbeat on my mac, when starting either one I'm getting the following systematic error:

```
2016/11/10 15:50:37.490503 client.go:420: WARN Can not index event (status=404): {"type":"index_not_found_exception","reason":"no such index","resource.type":"index_expression","resource.id":"filebeat-2016.11.10","index_uuid":"_na_","index":"filebeat-2016.11.10"}

```

So, from this I'm getting that indexes are created daily and in this case `filebeat-2016.11.10` was not yet created. The workaround I've found was straightforward, I created the index in ES and the tried again. That was a success but I guess there's something missing here since this is clearly not the expected use...

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [November 11, 2016, 11:33am UTC](https://discuss.elastic.co/t/beat-not-creating-index-on-start/65696/2 "2016-11-11T11:33:39Z")

</div>

What is your setup? Do you use Shield? Normally beats create the indices automatically. After creating the index manually, adding data from the beats side just worked?

---

<div class="post-metadata">

**Author:** ![tostasqb](https://avatars.discourse-cdn.com/v4/letter/t/7feea3/32.png) [@tostasqb](https://discuss.elastic.co/u/tostasqb)\
**Post date:** [November 11, 2016, 11:50am UTC](https://discuss.elastic.co/t/beat-not-creating-index-on-start/65696/3 "2016-11-11T11:50:15Z")

</div>

I used a fresh new installation of version 5 on a folder of my Mac (`/opt/elastic/`).  
I installed Elasticsearch, kibana and X-Pack and finally beats and yes, after creating the indexes manually and running Metricbeat or Filebeat they run fine...the data is on elasticsearch and I'm able to search it on Kibana as well.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [November 11, 2016, 12:04pm UTC](https://discuss.elastic.co/t/beat-not-creating-index-on-start/65696/4 "2016-11-11T12:04:42Z")

</div>

As you have Shield installed, is it possible that the filebeat user does not have the rights to create indices?

---

<div class="post-metadata">

**Author:** ![tostasqb](https://avatars.discourse-cdn.com/v4/letter/t/7feea3/32.png) [@tostasqb](https://discuss.elastic.co/u/tostasqb)\
**Post date:** [November 11, 2016, 12:34pm UTC](https://discuss.elastic.co/t/beat-not-creating-index-on-start/65696/5 "2016-11-11T12:34:26Z")

</div>

Got it!

I began by changing my folder to have all rights (777) but it didn't work so it got me thinking about X-Pack, so I got another look into the [installation guides](https://www.elastic.co/guide/en/x-pack/current/installing-xpack.html) and found my mistake... I introduced the `auto_create_index` in the elasticsearch configs. Seems pretty obvious now...

After commenting that all is good again.

Thanks for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 1, 2016, 4:04pm UTC](https://discuss.elastic.co/t/beat-not-creating-index-on-start/65696/6 "2016-12-01T16:04:13Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
