# Do these "could not index" errors actually end up in Elastic anywhere?

**URL:** <https://discuss.elastic.co/t/do-these-could-not-index-errors-actually-end-up-in-elastic-anywhere/306582>\
**Category:** Logstash\
**Created:** [June 7, 2022, 3:18pm UTC](https://discuss.elastic.co/t/do-these-could-not-index-errors-actually-end-up-in-elastic-anywhere/306582 "2022-06-07T15:18:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ckes](https://avatars.discourse-cdn.com/v4/letter/c/9f8e36/32.png) [@ckes](https://discuss.elastic.co/u/ckes)\
**Post date:** [June 7, 2022, 3:18pm UTC](https://discuss.elastic.co/t/do-these-could-not-index-errors-actually-end-up-in-elastic-anywhere/306582/1 "2022-06-07T15:18:38Z")

</div>

I've noticed quite a few of these errors with the elastic output plugin in /var/log/logstash/logstash-plain.log:

> "Could not index event to Elasticsearch. {:status=\>400, :action=\>["create", ...

The solution to fix the error itself is pretty well-documented. I'm concerned about how to monitor and address these issues as they appear.

When a log isn't able to be indexed like this, does a summary of the error get index into Elastic? Or would I need to come up with my own solution to proactively fix these errors?

Like sending this log to elastic myself (with a grok pattern to properly parse the logs, if a plugin isn't available), or writing some sort of a script to periodically grep the log?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 7, 2022, 3:34pm UTC](https://discuss.elastic.co/t/do-these-could-not-index-errors-actually-end-up-in-elastic-anywhere/306582/2 "2022-06-07T15:34:48Z")

</div>

Hi @ckes Have you looked at the [Dead Letter Queue](https://www.elastic.co/guide/en/logstash/current/dead-letter-queues.html)?

---

<div class="post-metadata">

**Author:** ![ckes](https://avatars.discourse-cdn.com/v4/letter/c/9f8e36/32.png) [@ckes](https://discuss.elastic.co/u/ckes)\
**Post date:** [June 7, 2022, 3:58pm UTC](https://discuss.elastic.co/t/do-these-could-not-index-errors-actually-end-up-in-elastic-anywhere/306582/3 "2022-06-07T15:58:40Z")

</div>

exactly what I need! I'll see if it's enabled now or not. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2022, 3:58pm UTC](https://discuss.elastic.co/t/do-these-could-not-index-errors-actually-end-up-in-elastic-anywhere/306582/4 "2022-07-05T15:58:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
