# Elastic doesn't create a new index

**URL:** <https://discuss.elastic.co/t/elastic-doesnt-create-a-new-index/252947>\
**Category:** Elasticsearch\
**Created:** [October 22, 2020, 7:10am UTC](https://discuss.elastic.co/t/elastic-doesnt-create-a-new-index/252947 "2020-10-22T07:10:31Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![AlexOQ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexoq/32/77563_2.png) [@AlexOQ](https://discuss.elastic.co/u/AlexOQ)\
**Post date:** [October 22, 2020, 7:10am UTC](https://discuss.elastic.co/t/elastic-doesnt-create-a-new-index/252947/1 "2020-10-22T07:10:31Z")

</div>

Hi, and thanks for any leads in advance.  
I am using the following output configuration:

```auto
<match **>
      @type rewrite_tag_filter
      @label @LOGTYPE
      <rule>
        key $["logtype"]
        pattern ^applog$
        tag applog
      </rule>
      <rule>
        key $["logtype"]
        pattern ^applog$
        tag system.${tag}
        invert true
      </rule>
    </match>

    <label @LOGTYPE>
    <match applog>
      @type relabel
      @label @APPLOG
    </match>
    <match system.**>
      @type relabel
      @label @SYSTEM
    </match>
    </label>

    <label @APPLOG>
    <match applog>
      @type elasticsearch
      @include out.conf
      logstash_prefix log.applog
    </match>
    </label>

    <label @SYSTEM>
    <match system.**>
      @type elasticsearch
      @include out.conf
      logstash_prefix fluentd.k8s
    </match>
    </label>

```

The symptom is the fact that `system.**` logs get to Kibana (so `rewrite-tag-filter` works), but no logs of `applog` origin are pushed to `log.applog` index. I should note that the permissions on the user used to connect are `admin`, and `log.applog` is yet-uncreated index which I expect to be created (as I've witnessed with previous configurations). Elastic is configured to allow creation of new indices.  
Elastic is deployed via `fluentd-elasticsearch` helm chart. What steps can I perform in order to troubleshoot this issue? Can't seem to find Elastic's logs anywhere.  
BTW, already tried `@type stdout` as well, doesn't work. Yes, there are `applogs` being created by the system, I see them when I reroute them to `@SYSTEM` label. Incredible voodoo, level 85.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 22, 2020, 7:15am UTC](https://discuss.elastic.co/t/elastic-doesnt-create-a-new-index/252947/2 "2020-10-22T07:15:59Z")

</div>

May be it's more a question for fluentd? Not sure we can help here unless someone from the community already implemented that...

---

<div class="post-metadata">

**Author:** ![AlexOQ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexoq/32/77563_2.png) [@AlexOQ](https://discuss.elastic.co/u/AlexOQ)\
**Post date:** [October 22, 2020, 7:19am UTC](https://discuss.elastic.co/t/elastic-doesnt-create-a-new-index/252947/3 "2020-10-22T07:19:12Z")

</div>

How and where can I see Elastic's logs? If I enable `level trace`, I still can't see any logs anywhere.  
Where should they be?

---

<div class="post-metadata">

**Author:** ![AlexOQ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexoq/32/77563_2.png) [@AlexOQ](https://discuss.elastic.co/u/AlexOQ)\
**Post date:** [October 22, 2020, 7:45am UTC](https://discuss.elastic.co/t/elastic-doesnt-create-a-new-index/252947/4 "2020-10-22T07:45:27Z")

</div>

I doubt it's fluentd's side. As I've noted, when I route all the logs to `@SYSTEM` I see them in Kibana. With the changed `tag` and everything. Meaning, fluentd's side is working as expected.  
Where can I find logs for Elastic actions? Debug/trace/what-have-you.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 22, 2020, 7:59am UTC](https://discuss.elastic.co/t/elastic-doesnt-create-a-new-index/252947/5 "2020-10-22T07:59:05Z")

</div>

To briefly explain my answer. I have absolutely no idea what the xml content you shared initially means. It's not coming from any Elastic product configuration AFAIK but I might be wrong.

About Elasticsearch:

> [@AlexOQ](#):
>
> Where can I find logs for Elastic actions? Debug/trace/what-have-you.

It depends on how you installed elasticsearch. For example, here are the path used by debian:

> **[Install Elasticsearch with Debian Package | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/deb.html#deb-layout)**

So it's in `/var/log/elasticsearch` by default.  
You can change the log levels with this:

> **[Logging | Elasticsearch Guide \[7.9\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.9/logging.html#configuring-logging-levels)**

If you want to trace everything which is happening, probably something like:

```auto
PUT /_cluster/settings
{
  "transient": {
    "logger.org.elasticsearch": "trace"
  }
}

```

will do it but I don't think you want this as it will be extremely verbose.

---

<div class="post-metadata">

**Author:** ![AlexOQ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexoq/32/77563_2.png) [@AlexOQ](https://discuss.elastic.co/u/AlexOQ)\
**Post date:** [October 22, 2020, 8:03am UTC](https://discuss.elastic.co/t/elastic-doesnt-create-a-new-index/252947/6 "2020-10-22T08:03:36Z")

</div>

Will try trace config, thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 19, 2020, 8:03am UTC](https://discuss.elastic.co/t/elastic-doesnt-create-a-new-index/252947/7 "2020-11-19T08:03:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
