# Can't send logs to data view

**URL:** <https://discuss.elastic.co/t/cant-send-logs-to-data-view/298176>\
**Category:** Logstash\
**Created:** [February 24, 2022, 1:54pm UTC](https://discuss.elastic.co/t/cant-send-logs-to-data-view/298176 "2022-02-24T13:54:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![martiros\_martiros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martiros_martiros/32/102280_2.png) [@martiros\_martiros](https://discuss.elastic.co/u/martiros_martiros)\
**Post date:** [February 24, 2022, 1:54pm UTC](https://discuss.elastic.co/t/cant-send-logs-to-data-view/298176/1 "2022-02-24T13:54:07Z")

</div>

I got this in my spring boot

this is my conf. file

```
input {
    file {
        type => "java"
         path => "/UUUU ******** /IdeaProjects/elk-stack-logging-example/elk-example.log"

        codec => multiline {
                     pattern => "^%{YEAR}-%{MONTHNUM}-%{MONTHDAY} %{TIME}.*"
                     negate => "true"
                     what => "previous"
                 }
    }
}

filter {
#If log line contains tab character followed by 'at' then we will tag that entry as stacktrace
    if [message] =~ "\tat" {
        grok {
            match => ["message", "^(\tat)"]
            add_tag => ["stacktrace"]
        }
    }

    grok {
        match => [ "message",
            "(?<timestamp>%{YEAR}-%{MONTHNUM}-%{MONTHDAY} %{TIME}) %{LOGLEVEL:level} %{NUMBER:pid} --- \[(?<thread>[A-Za-z0-9-]+)\] [A-Za-z0-9.]*\.(?<class>[A-Za-z0-9#_]+)\s*:\s+(?<logmessage>.*)",
            "message",
            "(?<timestamp>%{YEAR}-%{MONTHNUM}-%{MONTHDAY} %{TIME}) %{LOGLEVEL:level} %{NUMBER:pid} --- .+? :\s+(?<logmessage>.*)"
        ]
    }

    date {
        match => ["timestamp" , "yyyy-MM-dd HH:mm:ss.SSS"]
    }
}

output {

# Sending properly parsed log events to elasticsearch
    elasticsearch {
        hosts => ['https:// ********************** :9243/']
        user => 'elastic'
        password => ' *********************'
        index => "logstash_%{+YYYYMMdd}"
    }
    stdout { codec => rubydebug }

}

```

after running the code I go to Elasticsearch then I want to create a data view inserting the name log stash it says not data stream or index found for a given name.  
How to make this conf file work and create that index so I can create the view

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 24, 2022, 8:49pm UTC](https://discuss.elastic.co/t/cant-send-logs-to-data-view/298176/2 "2022-02-24T20:49:47Z")

</div>

If [ILM](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ilm) is enabled (and it is on by default if your Elasticsearch version supports it) then the index option is ignored. You will have an alias called logstash and indexes called {now/d}-00001 etc.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2022, 8:49pm UTC](https://discuss.elastic.co/t/cant-send-logs-to-data-view/298176/3 "2022-03-24T20:49:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
