# Elk does not see indexes

**URL:** <https://discuss.elastic.co/t/elk-does-not-see-indexes/315012>\
**Category:** Logstash\
**Tags:** windows\
**Created:** [September 23, 2022, 11:31am UTC](https://discuss.elastic.co/t/elk-does-not-see-indexes/315012 "2022-09-23T11:31:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![holpa](https://avatars.discourse-cdn.com/v4/letter/h/9de0a6/32.png) [@holpa](https://discuss.elastic.co/u/holpa)\
**Post date:** [September 23, 2022, 11:31am UTC](https://discuss.elastic.co/t/elk-does-not-see-indexes/315012/1 "2022-09-23T11:31:52Z")

</div>

Hello. I'm just learning how to work at ELK. I want to set up the transfer of logs from AD  
Installed on 1 server: elasticsearch, kibana, logstash 8.4 v  
2 server - windows forwarding event - winlogbeat

```auto
winlogbeat.event_logs:
winlogbeat.event_logs:
- name: ForwardedEvents
  forwarded: true

 # ignore_older: 72h

tags: ["winsrvad"]
output.logstash:
  hosts: ["192.169.1.30:5044"]

#logging.level: info
#logging.to_files: true
logging.files:
  path: C:\ProgramData\winlogbeat\logs
 # name: winlogbeat.log
 # keepfiles: 3

```

logstash config:

```auto
filter {
    if "winsrvad" in [tags] {
        if [winlog][event_id] != "5136" and [winlog][event_id] != "5139" and [winlog][event_id] != "5141" and [winlog][event_id] != "5137" and [winlog][event_id] != "4741" and [winlog][event_id] != "4742" and [winlog][event_id$
        drop { }
        }
    }
}

```

```auto
input {
        beats {
        port => 5044
        }
}

```

```auto
output {
    if [type] == "winsrvad" {
        elasticsearch {
            host => "localhost:9200"
            index => "winsrvas-%{+YYYY.MM.dd}"
            user => Logstash
            password => xxxxxxxxx
        }
    ]
}

```

Data View - create a data view against hidden, system or default indices. - no endex  
curl -XGET '[http://localhost:9200/\_search?size=10000&pretty](http://localhost:9200/_search?size=10000&pretty)'

```auto
{
  "took" : 0,
  "timed_out" : false,
  "_shards" : {
    "total" : 0,
    "successful" : 0,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 0,
      "relation" : "eq"
    },
    "max_score" : 0.0,
    "hits" : []
  }
}

```

Please help

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 23, 2022, 12:38pm UTC](https://discuss.elastic.co/t/elk-does-not-see-indexes/315012/2 "2022-09-23T12:38:56Z")

</div>

> [@holpa](#):
>
> `if [type] == "winsrvad"`

Where is the `type` field comming from? Does this field really exists in your message?

You are not adding it anywhere in the configurations you shared.

You have `winsrvad` as a tag, you could use it in your output conditional

```auto
output {
    if "winsrvad" in [tags] {
        elasticsearch { ...}
    }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 21, 2022, 12:39pm UTC](https://discuss.elastic.co/t/elk-does-not-see-indexes/315012/3 "2022-10-21T12:39:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
