# Data of logstash isn't preserved by elastisearch

**URL:** <https://discuss.elastic.co/t/data-of-logstash-isnt-preserved-by-elastisearch/57995>\
**Category:** Logstash\
**Created:** [August 15, 2016, 1:50am UTC](https://discuss.elastic.co/t/data-of-logstash-isnt-preserved-by-elastisearch/57995 "2016-08-15T01:50:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![111127](https://avatars.discourse-cdn.com/v4/letter/1/ea666f/32.png) [@111127](https://discuss.elastic.co/u/111127)\
**Post date:** [August 15, 2016, 1:50am UTC](https://discuss.elastic.co/t/data-of-logstash-isnt-preserved-by-elastisearch/57995/1 "2016-08-15T01:50:14Z")

</div>

Hi all

I'm using  
・filebeat-1.2.3-1.x86\_64(centos6.4)  
・logstash-2.3.2-1.noarch.rpm(amazon linux)  
・elasticsearch-2.3.5-1.noarch(amazon linux)  
・kibana-4.5.4-1.x86\_64(amazon linux)

Access log of nginx, it's set as LTSV and it's being sent to logstash by filebeat.  
And LTSV sent from filebeat, parse is being done and it's being sent to elasticach by the following setting, data of elasticache isn't preserved.

Are there any problems with setting for this?

【logstash setting】  
input {  
beats {  
port =\> 5044  
}  
}

filter {  
kv {  
field\_split =\> "\t"  
value\_split =\> ":"  
}  
date {  
match =\> [time, "'['dd/MMM/YYYY:HH:mm:ss Z']'"]  
locale =\> us  
}  
useragent {  
source =\> ua  
prefix =\> "ua."  
}  
mutate {  
convert =\> {  
status =\> integer  
reqtime =\> integer  
size =\> integer  
}  
}  
}

#output {

# stdout {

# codec =\> rubydebug

# }

#}  
output {  
elasticsearch {  
hosts =\> "host-ip-address:9200"  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 15, 2016, 1:51am UTC](https://discuss.elastic.co/t/data-of-logstash-isnt-preserved-by-elastisearch/57995/2 "2016-08-15T01:51:23Z")

</div>

What is your problem?

---

<div class="post-metadata">

**Author:** ![111127](https://avatars.discourse-cdn.com/v4/letter/1/ea666f/32.png) [@111127](https://discuss.elastic.co/u/111127)\
**Post date:** [August 15, 2016, 4:24am UTC](https://discuss.elastic.co/t/data-of-logstash-isnt-preserved-by-elastisearch/57995/3 "2016-08-15T04:24:21Z")

</div>

nginx(access-log format ltsv)filebeat =\> logstash(parse)=\> elasticsearch

But it isn't possible to register with elasticsearch with data.

How can data be registered now with elasticsearch?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:43am UTC](https://discuss.elastic.co/t/data-of-logstash-isnt-preserved-by-elastisearch/57995/4 "2017-07-06T04:43:31Z")

</div>


