# Can't create indices

**URL:** <https://discuss.elastic.co/t/cant-create-indices/254204>\
**Category:** Logstash\
**Created:** [November 4, 2020, 5:30am UTC](https://discuss.elastic.co/t/cant-create-indices/254204 "2020-11-04T05:30:34Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [November 4, 2020, 5:30am UTC](https://discuss.elastic.co/t/cant-create-indices/254204/1 "2020-11-04T05:30:35Z")

</div>

setup elk version 7.9.3 cannot create index logstash show me warning

```auto
[logstash.outputs.elasticsearch][main][27fb9d77028509eff9b3e4ec584ce0c8528c70f76c962e4e94e144a725a5b964] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"logs-packetbeat-flow-2020.11.04", :routing=>nil, :_type=>"_doc"}, #<LogStash::Event:0x35a2514c>], :response=>{"index"=>{"_index"=>"logs-packetbeat-flow-2020.11.04", "_type"=>"_doc", "_id"=>nil, "status"=>400, "error"=>{"type"=>"illegal_argument_exception", "reason"=>"only write ops with an op_type of create are allowed in data streams"}}}}

```

my pipleline file is

```auto
output {
 if[agent][type]=="packetbeat"
 {
if[type]=="flow"
   {
    elasticsearch {
    hosts => ["coordinate2:9200"]
    manage_template => false
    index => "logs-packetbeat-flow-%{+YYYY.MM.dd}"
  }
  }

```

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [November 4, 2020, 6:03am UTC](https://discuss.elastic.co/t/cant-create-indices/254204/2 "2020-11-04T06:03:03Z")

</div>

Hi,

It seems you are using data streams instead of indexes in your installation:

> [@Aniket\_Pant](#):
>
> `only write ops with an op_type of create are allowed in data streams`

Although I have not used data streams myself I know that datastreams cannot be updated - they only allow inserts of new documents. Therefore, I think setting the [action](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-action) setting to `create` (defaults to `index`) on your Elasticsearch output should help you.

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [November 4, 2020, 6:43am UTC](https://discuss.elastic.co/t/cant-create-indices/254204/3 "2020-11-04T06:43:20Z")

</div>

i actually don't know what is the data stream in elasticsearch.In elk 7.8 version i didn't see this error and when i upgraded to 7.9 version it can't show me indices although it is showing but it is hidden.  
now it is working  
i changed my pipeline file

```auto
output {
 if[agent][type]=="packetbeat"
 {
if[type]=="flow"
   {
    elasticsearch {
    hosts => ["coordinate2:9200"]
    manage_template => false
    index => "logs-packetbeat-flow-%{+YYYY.MM.dd}"
    action => "create"
  }
  }
}
}

```

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [November 4, 2020, 6:45am UTC](https://discuss.elastic.co/t/cant-create-indices/254204/4 "2020-11-04T06:45:29Z")

</div>

Great to hear that is working!

For more information about datastreams have a look here: [https://www.elastic.co/guide/en/elasticsearch/reference/master/data-streams.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/data-streams.html)

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [November 4, 2020, 9:07am UTC](https://discuss.elastic.co/t/cant-create-indices/254204/5 "2020-11-04T09:07:04Z")

</div>

The data streams seems to be confusing and i dont want to use it is there any want to not using of data stream.

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [November 4, 2020, 9:30am UTC](https://discuss.elastic.co/t/cant-create-indices/254204/6 "2020-11-04T09:30:25Z")

</div>

I guess this is caused by the [new index templates](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-templates.html): The Elastic Stack creates a new index template with pattern logs-_-_ which defines a data stream. See [here](https://www.elastic.co/guide/en/elasticsearch/reference/7.9/breaking-changes-7.9.html) for the relevant breaking change in 7.9.

To solve that, you would have to create your own template with a higher priority to store the data in indizes instead of datastreams. Unfortunately, I don't know if it is possible to convert the datastream back to "raw" indizes...

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [November 4, 2020, 10:08am UTC](https://discuss.elastic.co/t/cant-create-indices/254204/7 "2020-11-04T10:08:37Z")

</div>

yes you are saying right and my logstash index is also start with logs- prefix thats why it automatically uses the data streams

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 2, 2020, 10:08am UTC](https://discuss.elastic.co/t/cant-create-indices/254204/8 "2020-12-02T10:08:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
