# Could Not Index Event to Elasticsearch Error?

**URL:** <https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188>\
**Category:** Elasticsearch\
**Created:** [September 12, 2022, 11:27am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188 "2022-09-12T11:27:10Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![Priyanka4](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@Priyanka4](https://discuss.elastic.co/u/Priyanka4)\
**Post date:** [September 12, 2022, 11:27am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188/1 "2022-09-12T11:27:10Z")

</div>

message:  
[2022-09-12T11:02:46,381][WARN][logstash.outputs.elasticsearch][main][2a206be8e9b0598adfe625bef432d5a7f49b90230ff74f12fb3baf9c5024173f] Could not index event to Elasticsearch. {:status=\>400, :action=

---

<div class="post-metadata">

**Author:** ![Priyanka4](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@Priyanka4](https://discuss.elastic.co/u/Priyanka4)\
**Post date:** [September 12, 2022, 11:28am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188/2 "2022-09-12T11:28:52Z")

</div>

cat 02-beats-input.conf  
input {  
beats {  
port =\> 5044  
}  
}

cat 30-elasticsearch-output.conf  
output {  
if [@metadata][pipeline] {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
pipeline =\> "%{[@metadata][pipeline]}"  
}  
} else {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Priyanka4](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@Priyanka4](https://discuss.elastic.co/u/Priyanka4)\
**Post date:** [September 13, 2022, 5:19am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188/3 "2022-09-13T05:19:47Z")

</div>

Can anyone share your knowledge on my above post please. so it will be useful for me..

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 13, 2022, 7:53am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188/4 "2022-09-13T07:53:32Z")

</div>

Welcome to our community! 😃

Please share the entire error.

---

<div class="post-metadata">

**Author:** ![Priyanka4](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@Priyanka4](https://discuss.elastic.co/u/Priyanka4)\
**Post date:** [September 13, 2022, 8:13am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188/5 "2022-09-13T08:13:52Z")

</div>

Thanks for your reply

ELK Version :

{  
"name" : "[elk.hyperbig.com](http://elk.hyperbig.com)",  
"cluster\_name" : "elasticsearch",  
"cluster\_uuid" : "h4hGPTKrTxmbZOuSD8C92w",  
"version" : {  
"number" : "7.17.6",  
"build\_flavor" : "default",  
"build\_type" : "deb",  
"build\_hash" : "f65e9d338dc1d07b642e14a27f338990148ee5b6",  
"build\_date" : "2022-08-23T11:08:48.893373482Z",  
"build\_snapshot" : false,  
"lucene\_version" : "8.11.1",  
"minimum\_wire\_compatibility\_version" : "6.8.0",  
"minimum\_index\_compatibility\_version" : "6.0.0-beta1"  
},  
"tagline" : "You Know, for Search"  
}

Logstash Version

Using bundled JDK: /usr/share/logstash/jdk  
logstash 7.17.6

root@elk:/etc/logstash/conf.d# cat 02-beats-input.conf  
input {  
beats {  
port =\> 5044  
}  
}  
root@elk:/etc/logstash/conf.d# cat 30-elasticsearch-output.conf  
output {  
if [@metadata][pipeline] {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
pipeline =\> "%{[@metadata][pipeline]}"  
}  
} else {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
}  
}  
}  
root@elk:/etc/logstash/conf.d#

I m getting logs like this

message:  
[2022-09-13T07:53:30,403][WARN][logstash.outputs.elasticsearch][main][2a206be8e9b0598adfe625bef432d5a7f49b90230ff74f12fb3baf9c5024173f] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"filebeat-7.15.1-2022.09.13", :routing=\>nil, :pipeline=\>"filebeat-7.15.1-apache-access-pipeline"}, {"agent"=\>{"hostname"=\>"target.server", "type"=\>"filebeat", "name"=\>"target.server", "id"=\>"767014ec-beb9-4fed-99ab-e62af52a8336", "version"=\>"7.15.1", "ephemeral\_id"=\>"34a50a37-38f0-40bf-854c-332353815e22"}, "log"=\>{"file"=\>{"path"=\>"/var/log/sysadmin.requests.log"}, "offset"=\>131684}, "host"=\>{"hostname"=\>"target.server", "architecture"=\>"x86\_64", "name"=\>"target.server", "containerized"=\>false, "id"=\>"a0d63ac56c5f4acc84a3c4d4d2b892e4", "mac"=\>

Could not index event to Elasticsearch

please give me the solution

---

<div class="post-metadata">

**Author:** ![Priyanka4](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@Priyanka4](https://discuss.elastic.co/u/Priyanka4)\
**Post date:** [September 13, 2022, 8:16am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188/6 "2022-09-13T08:16:10Z")

</div>

I need remote server apache logs and graph has to show in dashboard but not showing that is my problem

---

<div class="post-metadata">

**Author:** ![Priyanka4](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@Priyanka4](https://discuss.elastic.co/u/Priyanka4)\
**Post date:** [September 13, 2022, 8:21am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188/7 "2022-09-13T08:21:01Z")

</div>

2022-09-13T13:47:29.511+0530 WARN beater/filebeat.go:178 Filebeat is unable to load the Ingest Node pipelines for the configured modules because the Elasticsearch output is not configured/enabled. If you have already loaded the Ingest Node pipelines or are using Logstash pipelines, you can ignore this warning.

2022-09-13T13:47:29.511+0530 ERROR instance/beat.go:989 Exiting: Index management requested but the Elasticsearch output is not configured/enabled  
Exiting: Index management requested but the Elasticsearch output is not configured/enabled

---

<div class="post-metadata">

**Author:** ![Priyanka4](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@Priyanka4](https://discuss.elastic.co/u/Priyanka4)\
**Post date:** [September 13, 2022, 8:54am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188/8 "2022-09-13T08:54:19Z")

</div>

Can you give me any update please

---

<div class="post-metadata">

**Author:** ![Priyanka4](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@Priyanka4](https://discuss.elastic.co/u/Priyanka4)\
**Post date:** [September 13, 2022, 9:59am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188/9 "2022-09-13T09:59:34Z")

</div>

@warkolm

Please give me apache filter file inorder to configure from our end

---

<div class="post-metadata">

**Author:** ![cheshirecat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheshirecat/32/109532_2.png) [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Post date:** [September 13, 2022, 10:01am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188/10 "2022-09-13T10:01:12Z")

</div>

Please use \</\> for code. It will be easier to analyze.

> [@Priyanka4](#):
>
> Exiting: Index management requested but the Elasticsearch output is not configured/enabled

Please share your `filebeat.yml`.

---

<div class="post-metadata">

**Author:** ![Priyanka4](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@Priyanka4](https://discuss.elastic.co/u/Priyanka4)\
**Post date:** [September 13, 2022, 10:03am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188/11 "2022-09-13T10:03:24Z")

</div>

# ------------------------------ Logstash Output -------------------------------

output.logstash:

# The Logstash hosts

hosts: ["103.77.232.85:5044"]

# Optional SSL. By default is off.

# List of root certificates for HTTPS server verifications

#ssl.certificate\_authorities: ["/etc/pki/root/ca.pem"]

# Certificate for SSL client authentication

#ssl.certificate: "/etc/pki/client/cert.pem"

# Client Certificate Key

#ssl.key: "/etc/pki/client/cert.key"

# ================================= Processors =================================

processors:

- add\_host\_metadata:  
when.not.contains.tags: forwarded
- add\_cloud\_metadata: ~
- add\_docker\_metadata: ~
- add\_kubernetes\_metadata: ~

---

<div class="post-metadata">

**Author:** ![cheshirecat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheshirecat/32/109532_2.png) [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Post date:** [September 13, 2022, 10:05am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188/12 "2022-09-13T10:05:32Z")

</div>

Did you read my post? 🙂

---

<div class="post-metadata">

**Author:** ![Priyanka4](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@Priyanka4](https://discuss.elastic.co/u/Priyanka4)\
**Post date:** [September 13, 2022, 10:07am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188/13 "2022-09-13T10:07:35Z")

</div>

> [@Priyanka4](#):
>
> Elasticsearch

Sorry i didn't get it what you are asking

---

<div class="post-metadata">

**Author:** ![Priyanka4](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@Priyanka4](https://discuss.elastic.co/u/Priyanka4)\
**Post date:** [September 13, 2022, 10:12am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188/14 "2022-09-13T10:12:10Z")

</div>

@cheshirecat @warkolm

\<Hi Can i get an update please

[2022-09-13T11:14:25,373][WARN][logstash.outputs.elasticsearch][main][f5ace9c97b8565874cb73e7b856d6e96dbf0a0d5b5059053b6c522c64890b7f5] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"filebeat-7.17.6-2022.09.13", :routing=\>nil, :pipeline=\>"filebeat-7.17.6-apache-access-pipeline"}, {"@timestamp"=\>2022-09-13T11:11:11.130Z, "tags"=\>["beats\_input\_codec\_plain\_applied"], "service"=\>{"type"=\>"apache"}, "input"=\>{"type"=\>"log"}, "fileset"=\>{"name"=\>"access"}, "type"=\>"random\_logs", "log"=\>{"file"=\>{"path"=\>"/var/log/sysadminaccess.log"}, "offset"=\>184186}, "@version"=\>"1", "event"=\>{"module"=\>"apache", "dataset"=\>"apache.access"}, "agent"=\>{"hostname"=\>"target.server", "id"=\>"767014ec-beb9-4fed-99ab-e62af52a8336", "type"=\>"filebeat", "ephemeral\_id"=\>"3d97261f-863b-495e-8f7b-94e15204976e", "name"=\>"target.server", "version"=\>"7.17.6"}, "host"=\>{"hostname"=\>"target.server", "id"=\>"a0d63ac56c5f4acc84a3c4d4d2b892e4", "mac"=\>["00:0c:29:5f:1b:d5"], "architecture"=\>"x86\_64", "os"=\>{"kernel"=\>"3.10.0-1160.71.1.el7.x86\_64", "type"=\>"linux", "platform"=\>"centos", "family"=\>"redhat", "version"=\>"7 (Core)", "name"=\>"CentOS Linux", "codename"=\>"Core"}, "name"=\>"target.server", "containerized"=\>false, "ip"=\>["173.208.192.93", "fe80::3ec8:c6bd:d570:ee56"]}, "ecs"=\>{"version"=\>"1.12.0"}, "message"=\>"201.150.180.250 - - [13/Sep/2022:16:41:03 +0530] "GET / HTTP/1.1" 200 160 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10\_11\_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7""}], :response=\>{"index"=\>{"\_index"=\>"filebeat-7.17.6-2022.09.13", "\_type"=\>"\_doc", "\_id"=\>nil, "status"=\>400, "error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"pipeline with id [filebeat-7.17.6-apache-access-pipeline] does not exist"}}}}

**reason"=\>"pipeline with id [filebeat-7.17.6-apache-access-pipeline] does not exist"}}}}**

please give me solution for this  
/\>

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 13, 2022, 12:42pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188/15 "2022-09-13T12:42:43Z")

</div>

Hello,

People in this forum are volunteers, do not keep bumping your post or pinging people, just post your question and wait, people will answer when they have the time to do it, there is no SLA in this forum.

Also, you need to help people help you, do not post your configuration or logs unformatted, it will make things very hard to understand, post your config, select the entire text and click in the `</>` button, this will correct the format.

Your question is really confusing at this time because you shared a lot of things without any context.

You have issues with both Filebeat and Logstash, what is your current issue now since you probably change somethings?

Please share your entire filebeat.yml file using the format as mentioned above and your logstash configuration using the format, the `</>` button.

> **reason"=\>"pipeline with id [filebeat-7.17.6-apache-access-pipeline] does not exist"}}}}**

Did you run filebeat setup before anything else? If you are going to use a filebeat module you need to run filebeat setup, to do that you will need to temporarily change your filebeat output to elasticsearch, please read this [part of documentation](https://www.elastic.co/guide/en/beats/filebeat/7.16/filebeat-installation-configuration.html#setup-assets).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 11, 2022, 12:43pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188/16 "2022-10-11T12:43:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
