# Elasticsearch input missing \[@metadata\]\[\_index\]

**URL:** <https://discuss.elastic.co/t/elasticsearch-input-missing-metadata-index/223594>\
**Category:** Logstash\
**Created:** [March 13, 2020, 11:55pm UTC](https://discuss.elastic.co/t/elasticsearch-input-missing-metadata-index/223594 "2020-03-13T23:55:10Z")\
**Posts on this page:** 1\
**Showing post:** 13

<div class="post-metadata">

**Author:** ![joaociocca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joaociocca/32/15827_2.png) [@joaociocca](https://discuss.elastic.co/u/joaociocca)\
**Post date:** [March 18, 2020, 1:04pm UTC](https://discuss.elastic.co/t/elasticsearch-input-missing-metadata-index/223594/13 "2020-03-18T13:04:42Z")

</div>

> [@Fabio-sama](#):
>
> Can you share here a sample of the documents you are working on?

I'll try later when I get back to work!

> [@Fabio-sama](#):
>
> Are all the indices identified by that patter structured the same way?

100% positive. This is VPN log. So even if different packet types return different fields, the whole index is the same, all fields considered.

> [@Fabio-sama](#):
>
> In fact, I guess if you try on a single, manual input, it'll always work, won't it?

Yes, when I switch to http input for testing and feed it one of the docs retrieved, it will always work.

I'm gonna try and see if I can convince our infra guys to improve things over there, otherwise I think I'll be stuck =\

---

_[View the full topic](https://discuss.elastic.co/t/elasticsearch-input-missing-metadata-index/223594)._
