# Could not index event to Elasticsearch error creating index

**URL:** <https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error-creating-index/146141>\
**Category:** Logstash\
**Created:** [August 27, 2018, 9:30am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error-creating-index/146141 "2018-08-27T09:30:24Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 27, 2018, 9:30am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error-creating-index/146141/1 "2018-08-27T09:30:24Z")

</div>

I am trying to parse my logs and trying to create a dynamic index. But somehow logstash is itself creating the index with a `,` in the pattern hence its failing. Can you please help me remove the comma.

```
filter{

grok{
match => [
				"message",'^%{TIMESTAMP_ISO8601:betimestamp} %{DATA:tenantId} % {EMAILADDRESS:userId} (\[%{DATA:threadName}\])']

}

  mutate {
    lowercase => ["tenantId"]
      }

  }

    output {
if [tenantId] {		
		if [type] =~ /UI$/ {
		  elasticsearch {
			 hosts => ["localhost:9200"]
			 index => "atest-%{tenantId}-%{+YYYY.MM.dd}"
		  }
		} else {
			elasticsearch {
			 hosts => ["localhost:9200"]
			 index => "atest-%{tenantId}-%{+YYYY.MM.dd}"
		  }
		}
	}
}

```

`[WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"atest-Wipro,Wipro-be-log-2018.08.27", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x57f204da>], :response=>{"index"=>{"_index"=>"atest-Wipro,Wipro-be-log-2018.08.27", "_type"=>"doc", "_id"=>nil, "status"=>400, "error"=>{"type"=>"invalid_index_name_exception", "reason"=>"Invalid index name [atest-Wipro,Wipro-be-log-2018.08.27], must not contain the following characters [, \", *, \\, <, |, ,, >, /, ?]", "index_uuid"=>"_na_", "index"=>"atest-Wipro,Wipro-be-log-2018.08.27"}}}}`

The problem was with uppercase letter, I have updated my configuration but `tenantId` is not changing.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 27, 2018, 9:33am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error-creating-index/146141/2 "2018-08-27T09:33:18Z")

</div>

The `tenantId` field is probably an array. If you temporarily replace the elasticsearch output with a `stdout { codec => rubydebug }` output you'll see what your events actually look like.

---

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 27, 2018, 9:48am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error-creating-index/146141/3 "2018-08-27T09:48:14Z")

</div>

I have updated my config please check...

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 27, 2018, 10:15am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error-creating-index/146141/4 "2018-08-27T10:15:48Z")

</div>

My answer is the same.

---

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 27, 2018, 10:16am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error-creating-index/146141/5 "2018-08-27T10:16:44Z")

</div>

But its not an array, the log file is generated by me.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 27, 2018, 10:19am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error-creating-index/146141/6 "2018-08-27T10:19:20Z")

</div>

If you want help with your problem then follow my suggestions.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 24, 2018, 10:19am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error-creating-index/146141/7 "2018-09-24T10:19:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
