# Could not locate that index-pattern (id: filebeat-\*)

**URL:** https://discuss.elastic.co/t/could-not-locate-that-index-pattern-id-filebeat/249447
**Category:** Elasticsearch
**Created:** [September 22, 2020, 5:24am UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-id-filebeat/249447 "2020-09-22T05:24:26Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Mobin](https://avatars.discourse-cdn.com/v4/letter/m/df788c/32.png) [@Mobin](https://discuss.elastic.co/u/Mobin)
#### Post date: [September 22, 2020, 5:24am UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-id-filebeat/249447/1 "2020-09-22T05:24:26Z")

</div>

Dear Team,

I am new to Elastic stack and recently I created a elastic stack setup using file beat. My intention is to monitor the Linux server logs, So I installed Elasticsearch, Logstash,filebeat, and Kibana on server and filebeat on clients. After configuration, I am able to see client logs in the elastic stack but visualization is getting failed with the message `"Could not locate that index-pattern (id: filebeat-*) [click here to re-create it](#/management/kibana/index_pattern)]` . I tried to delete the index-pattern and created new but no luck. Can somebody guide me to confiure it

```auto
logstash-7.0.1-1.noarch
elasticsearch-7.0.1-1.x86_64
kibana-7.0.1-1.x86_64
filebeat-7.0.1-1.x86_64

```

logstash config

```auto
input {
  beats {
    port => 5044
  }
}

filter {
  if [fileset][module] == "system" {
    if [fileset][name] == "auth" {
      grok {
        match => { "message" => ["%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:\[%{POSINT:[system][auth][pid]}\])?: %{DATA:[system][auth][ssh][event]} %{DATA:[system][auth][ssh][method]} for (invalid user )?%{DATA:[system][auth][user]} from %{IPORHOST:[system][auth][ssh][ip]} port %{NUMBER:[system][auth][ssh][port]} ssh2(: %{GREEDYDATA:[system][auth][ssh][signature]})?",
                  "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:\[%{POSINT:[system][auth][pid]}\])?: %{DATA:[system][auth][ssh][event]} user %{DATA:[system][auth][user]} from %{IPORHOST:[system][auth][ssh][ip]}",
                  "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:\[%{POSINT:[system][auth][pid]}\])?: Did not receive identification string from %{IPORHOST:[system][auth][ssh][dropped_ip]}",
                  "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sudo(?:\[%{POSINT:[system][auth][pid]}\])?: \s*%{DATA:[system][auth][user]} :( %{DATA:[system][auth][sudo][error]} ;)? TTY=%{DATA:[system][auth][sudo][tty]} ; PWD=%{DATA:[system][auth][sudo][pwd]} ; USER=%{DATA:[system][auth][sudo][user]} ; COMMAND=%{GREEDYDATA:[system][auth][sudo][command]}",
                  "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} groupadd(?:\[%{POSINT:[system][auth][pid]}\])?: new group: name=%{DATA:system.auth.groupadd.name}, GID=%{NUMBER:system.auth.groupadd.gid}",
                  "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} useradd(?:\[%{POSINT:[system][auth][pid]}\])?: new user: name=%{DATA:[system][auth][user][add][name]}, UID=%{NUMBER:[system][auth][user][add][uid]}, GID=%{NUMBER:[system][auth][user][add][gid]}, home=%{DATA:[system][auth][user][add][home]}, shell=%{DATA:[system][auth][user][add][shell]}$",
                  "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} %{DATA:[system][auth][program]}(?:\[%{POSINT:[system][auth][pid]}\])?: %{GREEDYMULTILINE:[system][auth][message]}"] }
        pattern_definitions => {
          "GREEDYMULTILINE"=> "(.|\n)*"
        }
        remove_field => "message"
      }
      date {
        match => ["[system][auth][timestamp]", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]
      }
      geoip {
        source => "[system][auth][ssh][ip]"
        target => "[system][auth][ssh][geoip]"
      }
    }
    else if [fileset][name] == "syslog" {
      grok {
        match => { "message" => ["%{SYSLOGTIMESTAMP:[system][syslog][timestamp]} %{SYSLOGHOST:[system][syslog][hostname]} %{DATA:[system][syslog][program]}(?:\[%{POSINT:[system][syslog][pid]}\])?: %{GREEDYMULTILINE:[system][syslog][message]}"] }
        pattern_definitions => { "GREEDYMULTILINE" => "(.|\n)*" }
        remove_field => "message"
      }
      date {
        match => ["[system][syslog][timestamp]", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]
      }
    }
  }
}

output {
    elasticsearch {
        hosts => ["localhost:9200"]
        manage_template => false
        index => "filebeat-%{+YYYY.MM.dd}"  
    }
}

```

* * *

---

<div class="post-metadata">

### Author: ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)
#### Post date: [September 22, 2020, 7:34am UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-id-filebeat/249447/2 "2020-09-22T07:34:56Z")

</div>

See [https://www.elastic.co/guide/en/beats/filebeat/7.8/filebeat-template.html#load-template-manually](https://www.elastic.co/guide/en/beats/filebeat/7.8/filebeat-template.html#load-template-manually)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 20, 2020, 7:35am UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-id-filebeat/249447/3 "2020-10-20T07:35:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
