# Could not index event to Elasticsearch. "reason"=\>"if \_id is specified it must not be empty"}

**URL:** <https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-if-id-is-specified-it-must-not-be-empty/234181>\
**Category:** Logstash\
**Created:** [May 25, 2020, 4:18pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-if-id-is-specified-it-must-not-be-empty/234181 "2020-05-25T16:18:14Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![tenet\_testuser1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tenet_testuser1/32/67526_2.png) [@tenet\_testuser1](https://discuss.elastic.co/u/tenet_testuser1)\
**Post date:** [May 25, 2020, 4:18pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-if-id-is-specified-it-must-not-be-empty/234181/1 "2020-05-25T16:18:14Z")

</div>

Hello,

I have setup a logstash pipeline. It works fine bringing the updates and refreshing the index. However, it throws an error while bringing updates. I am trying to understand the reasons behind.

output {  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
index =\> "contactsx"  
document\_type =\> "contactx"  
document\_id =\> "%{symbol}"  
}

[2020-05-25T11:59:13,962][WARN][logstash.outputs.elasticsearch][company\_listing] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>"", :\_index=\>"contactsx", :routing=\>nil, :\_type=\>"contactx"}, #LogStash::Event:0x56578469], :response=\>{"index"=\>{"\_index"=\>"contactsx", "\_type"=\>"contactx", "\_id"=\>"", "status"=\>400, "error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"if \_id is specified it must not be empty"}}}}

by changing it to this "with a constant "\_Z", document\_id =\> "%{symbol}\_z", there are no errors.

output {  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
index =\> "contactsx"  
document\_type =\> "contactx"  
document\_id =\> "%{symbol}\_z"  
}

Can you please explain what's going on here?  
The column symbol is primary key in the db.  
Why does logstash say id is NULL in the first setting?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 25, 2020, 6:06pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-if-id-is-specified-it-must-not-be-empty/234181/2 "2020-05-25T18:06:17Z")

</div>

Apparently you have an event where the symbol field exists but is empty.

---

<div class="post-metadata">

**Author:** ![tenet\_testuser1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tenet_testuser1/32/67526_2.png) [@tenet\_testuser1](https://discuss.elastic.co/u/tenet_testuser1)\
**Post date:** [May 25, 2020, 6:19pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-if-id-is-specified-it-must-not-be-empty/234181/3 "2020-05-25T18:19:26Z")

</div>

Symbol is one of the columns in the SQL statement. And it is primary key. So it's not empty or null, also it's unique

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 25, 2020, 7:53pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-if-id-is-specified-it-must-not-be-empty/234181/4 "2020-05-25T19:53:42Z")

</div>

When you use

```
 document_id => "%{symbol}_z"

```

it seems likely you have a document with id equal to "\_z". What does that document look like if check the JSON tab in an expanded event in the Discover interface of kibana?

---

<div class="post-metadata">

**Author:** ![tenet\_testuser1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tenet_testuser1/32/67526_2.png) [@tenet\_testuser1](https://discuss.elastic.co/u/tenet_testuser1)\
**Post date:** [May 27, 2020, 6:39pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-if-id-is-specified-it-must-not-be-empty/234181/5 "2020-05-27T18:39:36Z")

</div>

The pipeline config , and the sql for document\_id =\> "%{symbol}\_z"  
and document\_id =\> "%{symbol}".

The sql has a few columns from a table, with symbol being the primary key, so it's unique and not null.

However, when I set document\_id =\> "%{symbol}" it gives the aforementioned error.

Since it said NULL for id, I thought let me add a constant like "\_Z" and with this added, there are no errors.

The end result in both cases are the same. However, one gives a WARNING in the logs, while the other is clear.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 27, 2020, 6:54pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-if-id-is-specified-it-must-not-be-empty/234181/6 "2020-05-27T18:54:40Z")

</div>

> [@tenet\_testuser1](#):
>
> Since it said NULL for id, I thought let me add a constant like "\_Z" and with this added, there are no errors.

Right. What does the resulting document look like?

---

<div class="post-metadata">

**Author:** ![tenet\_testuser1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tenet_testuser1/32/67526_2.png) [@tenet\_testuser1](https://discuss.elastic.co/u/tenet_testuser1)\
**Post date:** [May 27, 2020, 8:08pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-if-id-is-specified-it-must-not-be-empty/234181/7 "2020-05-27T20:08:00Z")

</div>

With \_Z appended to the pipeline directive

symbol:  
HCHC  
@version:  
1  
@timestamp:  
2020-05-27  
companyname:  
HC2 Holdings, Inc.  
\_id:  
HCHC\_z  
\_type:  
contactx  
\_index:  
contactsx  
\_score:  
0  
################################################################

Without \_Z appended  
#####################

symbol:  
HCHC  
companyname:  
HC2 Holdings, Inc.  
@timestamp:  
2020-05-27  
@version:  
1  
\_id:  
HCHC  
\_type:  
contactx  
\_index:  
contactsx  
\_score:  
0

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 27, 2020, 8:14pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-if-id-is-specified-it-must-not-be-empty/234181/8 "2020-05-27T20:14:49Z")

</div>

You are saying that the "Without \_Z appended" event results in an illegal\_argument\_exception?

---

<div class="post-metadata">

**Author:** ![tenet\_testuser1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tenet_testuser1/32/67526_2.png) [@tenet\_testuser1](https://discuss.elastic.co/u/tenet_testuser1)\
**Post date:** [May 28, 2020, 7:07pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-if-id-is-specified-it-must-not-be-empty/234181/9 "2020-05-28T19:07:47Z")

</div>

yes. exactly.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 28, 2020, 7:37pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-if-id-is-specified-it-must-not-be-empty/234181/10 "2020-05-28T19:37:56Z")

</div>

I cannot imagine why elasticsearch would do that. I suggest you ask a question over in the elasticsearch forum.

---

<div class="post-metadata">

**Author:** ![tenet\_testuser1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tenet_testuser1/32/67526_2.png) [@tenet\_testuser1](https://discuss.elastic.co/u/tenet_testuser1)\
**Post date:** [May 28, 2020, 8:16pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-if-id-is-specified-it-must-not-be-empty/234181/11 "2020-05-28T20:16:34Z")

</div>

Ok thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 25, 2020, 8:16pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-if-id-is-specified-it-must-not-be-empty/234181/12 "2020-06-25T20:16:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
