# Elasticsearch index not getting created when add\_field is used

**URL:** <https://discuss.elastic.co/t/elasticsearch-index-not-getting-created-when-add-field-is-used/243825>\
**Category:** Logstash\
**Created:** [August 5, 2020, 8:31am UTC](https://discuss.elastic.co/t/elasticsearch-index-not-getting-created-when-add-field-is-used/243825 "2020-08-05T08:31:45Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![pranayv66](https://avatars.discourse-cdn.com/v4/letter/p/7ba0ec/32.png) [@pranayv66](https://discuss.elastic.co/u/pranayv66)\
**Post date:** [August 5, 2020, 8:31am UTC](https://discuss.elastic.co/t/elasticsearch-index-not-getting-created-when-add-field-is-used/243825/1 "2020-08-05T08:31:45Z")

</div>

Hi,

I'm facing a problem when creating an elasticsearch index. I'm new to this, so please let me know what I could do to fix this.  
I'm pasting the two config files which I've used for reference. The one at the top is working, which I used just to see whether a simple load is working or not.

```auto
      file {
        path => "C:/Users/pranay/data.csv"
        start_position => "beginning"
      }
    }

    filter {
          csv {
            columns => ["Desc","time","util","data"]
         }
         mutate {convert => ["time", "float"] }
         mutate {convert => ["util", "float"] }
        }

    output {
      elasticsearch { 
      hosts => ["localhost:9200"] 
      index => "network"
      }
     }

```

This seems to be working fine. However when I use the below block, since I need to create a kibana visualization based on certain values from the fields, I'm using this

```auto
    input {
    	file {
    		path => "C:\Users\pranay\data.csv"
    		start_position => "beginning"
    	}
    }

    filter {
    	csv {
    		columns => ["Desc","time","util","data"]

    	}

    	mutate {convert => ["time", "float"] }
         mutate {convert => ["util", "float"] }

      if [data] == "data_one" {
    		mutate {
    		add_field => ["Desc", "Snap"]
    		}
    	}
    	else if [data] == "data_two" {
    		mutate {
    		add_field => ["Desc", "Snaptwo"]
    		}
    	}
    	else if [data] == "data_three" {
    		mutate {
    		add_field => ["Description", "Snapthree"]
    		}
    	}
    } 
    output {
    	elasticsearch {
    		hosts => ["localhost:9200"]
    		index => "test"
    	}
    }

```

I've also checked the logstash console, it doesn't give any tracebacks per se.

Any help on this will be appreciated.

Thanks,  
Pranay.

---

<div class="post-metadata">

**Author:** ![christiancj](https://avatars.discourse-cdn.com/v4/letter/c/258eb7/32.png) [@christiancj](https://discuss.elastic.co/u/christiancj)\
**Post date:** [August 5, 2020, 12:17pm UTC](https://discuss.elastic.co/t/elasticsearch-index-not-getting-created-when-add-field-is-used/243825/2 "2020-08-05T12:17:11Z")

</div>

looks to me the error is around the else if conditions and the way to set the add field, instead you should use nested else conditions, try this below,

```auto
if "data_one" in [data] {
    		mutate {
				add_field => { "Desc" => ["Snap"] }
    		}
    	} # end if "data_one"
    	else {
			if "data_two" in [data] {
				mutate {
					add_field => { "Desc" => ["Snaptwo"] }
				}
			} # end if "data_two"
			else {
				if "data_three" in [data] {
					mutate {
						add_field => { "Description" => ["Snapthree"] }
					}
				} # end if "data_three"		
			} # end 2nd else
		} # end 1st else

```

also, another similar post

> [@Multiple IF conditions - Logstash](https://discuss.elastic.co/t/multiple-if-conditions-logstash/166186):
>
> Hi, I am fixing bigger logstash config file where I have custom grok patterns but that is just tip of the iceberg regarding my problems. In Filebeat I have multiple log files and some of them (their log events) are visible in Kibana ok, and some not because their content ends up in the message field. Some log events are not even visible in Kibana when I try to filter it by tags in Kibana. I can fix stuff if I have one IF statement but when multiple IF statements are involved I am not sure wha…

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 5, 2020, 2:32pm UTC](https://discuss.elastic.co/t/elasticsearch-index-not-getting-created-when-add-field-is-used/243825/3 "2020-08-05T14:32:24Z")

</div>

> [@pranayv66](#):
>
> `path => "C:\Users\pranay\data.csv"`

Do not use backslash in the path option of a file filter, it is treated as an escape. Use forward slash.

---

<div class="post-metadata">

**Author:** ![pranayv66](https://avatars.discourse-cdn.com/v4/letter/p/7ba0ec/32.png) [@pranayv66](https://discuss.elastic.co/u/pranayv66)\
**Post date:** [August 6, 2020, 4:24am UTC](https://discuss.elastic.co/t/elasticsearch-index-not-getting-created-when-add-field-is-used/243825/4 "2020-08-06T04:24:21Z")

</div>

@Badger No, that is not a problem here, as I stated above, in both of the codes, I've used a similar path for the input file and I get the index generated for the 1st one, whereas couldn't get that in the second one. So clearly there is something wrong in the later part of it.

Thanks,  
Pranay.

---

<div class="post-metadata">

**Author:** ![pranayv66](https://avatars.discourse-cdn.com/v4/letter/p/7ba0ec/32.png) [@pranayv66](https://discuss.elastic.co/u/pranayv66)\
**Post date:** [August 6, 2020, 5:10am UTC](https://discuss.elastic.co/t/elasticsearch-index-not-getting-created-when-add-field-is-used/243825/5 "2020-08-06T05:10:33Z")

</div>

@christiancj I've tried this and unfortunately this also does not create an index ☹  
Could you suggest anything else that I can give a shot?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 6, 2020, 1:41pm UTC](https://discuss.elastic.co/t/elasticsearch-index-not-getting-created-when-add-field-is-used/243825/7 "2020-08-06T13:41:33Z")

</div>

> [@pranayv66](#):
>
> @Badger No, that is not a problem here, as I stated above, in both of the codes, I've used a similar path for the input file and I get the index generated for the 1st one, whereas couldn't get that in the second one.

No, you have not use a similar path. In the first one you used

```
path => "C:/Users/pranay/data.csv"

```

with forward slash, and it worked. In the second one you used

```
path => "C:\Users\pranay\data.csv"

```

with backslash and it did not work. Change the backslashes to forward slash.

---

<div class="post-metadata">

**Author:** ![pranayv66](https://avatars.discourse-cdn.com/v4/letter/p/7ba0ec/32.png) [@pranayv66](https://discuss.elastic.co/u/pranayv66)\
**Post date:** [August 6, 2020, 1:46pm UTC](https://discuss.elastic.co/t/elasticsearch-index-not-getting-created-when-add-field-is-used/243825/8 "2020-08-06T13:46:24Z")

</div>

@Badger I did replace the '' with '/' and it is still stuck there.

---

<div class="post-metadata">

**Author:** ![christiancj](https://avatars.discourse-cdn.com/v4/letter/c/258eb7/32.png) [@christiancj](https://discuss.elastic.co/u/christiancj)\
**Post date:** [August 6, 2020, 1:49pm UTC](https://discuss.elastic.co/t/elasticsearch-index-not-getting-created-when-add-field-is-used/243825/9 "2020-08-06T13:49:09Z")

</div>

@pranayv66 - here is a conf that is working in my end, a sample index created with the if and columns conversion executed.

```auto
   input {
    	file {
			path => "C:/Users/pranay/data.csv"
    		start_position => "beginning"
			sincedb_path => "C:/Users/pranay/.since.sample.log"
    	}
    }

    filter {
	
    	csv { 
			columns => ["Desc","time","util","data"] 
			convert => {
				"time" => "float"
				"util" => "float"
			}
			
			}

    if "data_one" in [data] {
    		mutate {
				add_field => { "Description" => ["Snap"] }
    		}
    	} # end if "data_one"
    else {
			if "data_two" in [data] {
				mutate {
					add_field => { "Description" => ["Snaptwo"] }
				}
			} # end if "data_two"
			else {
				if "data_three" in [data] {
					mutate {
						add_field => { "Description" => ["Snapthree"] }
					}
				} # end if "data_three"		
			} # end 2nd else
		} # end 1st else
		
	mutate {
		remove_field => ["column1","column2","column3","column4"] 
	}
	
    }
	
    output {
   
	  stdout { codec => json }
    
         elasticsearch {
			hosts => ["localhost:9200"]
			index => "test"
		}
	}

```

sample csv - don't include column/header names in the file, just the data to ingest

```auto
abc,20.8,19.75,data_three
xya,34.5,19.5,data_two

```

as suggestion, don't forget to delete your sincedb path file when you're running testing (reload objects), this file track the last object/row processed.

---

<div class="post-metadata">

**Author:** ![pranayv66](https://avatars.discourse-cdn.com/v4/letter/p/7ba0ec/32.png) [@pranayv66](https://discuss.elastic.co/u/pranayv66)\
**Post date:** [August 7, 2020, 4:49am UTC](https://discuss.elastic.co/t/elasticsearch-index-not-getting-created-when-add-field-is-used/243825/10 "2020-08-07T04:49:53Z")

</div>

@christiancj Thanks for the solution. This worked perfectly well !!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2020, 4:49am UTC](https://discuss.elastic.co/t/elasticsearch-index-not-getting-created-when-add-field-is-used/243825/11 "2020-09-04T04:49:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
