# ES 2.2: index\_not\_found\_exception \[logstash-\*\]

**URL:** <https://discuss.elastic.co/t/es-2-2-index-not-found-exception-logstash/42929>\
**Category:** Logstash\
**Created:** [February 27, 2016, 9:02pm UTC](https://discuss.elastic.co/t/es-2-2-index-not-found-exception-logstash/42929 "2016-02-27T21:02:05Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![alecswan](https://avatars.discourse-cdn.com/v4/letter/a/bc8723/32.png) [@alecswan](https://discuss.elastic.co/u/alecswan)\
**Post date:** [February 27, 2016, 9:02pm UTC](https://discuss.elastic.co/t/es-2-2-index-not-found-exception-logstash/42929/1 "2016-02-27T21:02:05Z")

</div>

Hello,

I am using ES 2.2/Shield 2.2 and for some reason it fails to acknowledge that logstash-\* indexes exist.

Theses are the indexes I currently have:

> curl -u admin 'localhost:9200/\_cat/indices?v'  
> Enter host password for user 'admin':  
> health status index pri rep docs.count docs.deleted store.size pri.store.size  
> yellow open logstash-2016.02.27 5 1 140220 0 33.4mb 33.4mb  
> yellow open logstash-2016.02.26 5 1 634279 0 158.3mb 158.3mb  
> yellow open logstash-2016.02.25 5 1 1323298 0 322.8mb 322.8mb  
> yellow open .kibana 1 1 3 0 12.4kb 12.4kb  
> yellow open logstash-2016.02.24 5 1 1383081 0 338.6mb 338.6mb  
> yellow open logstash-2016.02.23 5 1 382714 0 95.4mb 95.4mb

However, the following command returns index\_not\_found\_exception:

> curl -XGET localhost:9200/logstash-_/\_field\_stats?fields=@timestamp  
> {"error":{"root\_cause":[{"type":"index\_not\_found\_exception","reason":"no such index","index":"[logstash-_]"}],"type":"index\_not\_found\_exception","reason":"no such index","index":"[logstash-\*]"},"status":404}

Thanks,

Alec

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 28, 2016, 12:42am UTC](https://discuss.elastic.co/t/es-2-2-index-not-found-exception-logstash/42929/2 "2016-02-28T00:42:55Z")

</div>

Weird, works fine for me.  
Try wrapping the URL in quotes - `curl -XGET "localhost:9200/logstash-*/_field_stats?fields=@timestamp"`

---

<div class="post-metadata">

**Author:** ![alecswan](https://avatars.discourse-cdn.com/v4/letter/a/bc8723/32.png) [@alecswan](https://discuss.elastic.co/u/alecswan)\
**Post date:** [February 28, 2016, 5:12pm UTC](https://discuss.elastic.co/t/es-2-2-index-not-found-exception-logstash/42929/3 "2016-02-28T17:12:35Z")

</div>

The problem turned out to be similar to [Kibana doesn't work with wildcards since Shield 2.1.0](https://discuss.elastic.co/t/kibana-doesnt-work-with-wildcards-since-shield-2-1-0/35590/14).

It would be nice if [documentation](https://www.elastic.co/guide/en/shield/current/kibana.html#kibana4-user-role) was adjusted to include `indices:data/read/field_stats` privilege for the kibana4 user.

Thanks,  
Alec

---

<div class="post-metadata">

**Author:** ![rocky4bmw](https://avatars.discourse-cdn.com/v4/letter/r/6bbea6/32.png) [@rocky4bmw](https://discuss.elastic.co/u/rocky4bmw)\
**Post date:** [July 10, 2016, 3:21pm UTC](https://discuss.elastic.co/t/es-2-2-index-not-found-exception-logstash/42929/4 "2016-07-10T15:21:42Z")

</div>

@alecswan

I am using shiled 2.3 when I try to test topbeat after installation I get this error.

Should I use same fix as mentioned for 2.2?

curl -XGET '[http://privateip:9200/topbeat-](http://privateip:9200/topbeat-)_/\_search?pretty' -u es\_admin  
Enter host password for user 'es\_admin':  
{  
"error" : {  
"root\_cause" : [ {  
"type" : "index\_not\_found\_exception",  
"reason" : "no such index",  
"index" : "[topbeat-_]"  
} ],  
"type" : "index\_not\_found\_exception",  
"reason" : "no such index",  
"index" : "[topbeat-\*]"  
},  
"status" : 404  
}

In Below /usr/share/elasticsearch/plugins/shield/config/roles.yml

# All cluster rights

# All operations on all indices

admin:  
cluster:  
- all  
indices:  
- names: '\*'  
privileges:  
- all

# monitoring cluster privileges

# All operations on all indices

power\_user:  
cluster:  
- monitor  
indices:  
- names: '\*'  
privileges:  
- all

# Read-only operations on indices

user:  
indices:  
- names: '\*'  
privileges:  
- read

# Defines the required permissions for transport clients

transport\_client:  
cluster:  
- transport\_client

# The required permissions for the kibana 4 server

kibana4\_server:  
cluster:  
- monitor  
indices:

- names: '.kibana'  
privileges:
  - all

# The required role for logstash users

logstash:  
cluster:  
- manage\_index\_templates  
indices:  
- names: 'logstash-\*'  
privileges:  
- write  
- delete  
- create\_index

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 10, 2016, 10:48pm UTC](https://discuss.elastic.co/t/es-2-2-index-not-found-exception-logstash/42929/5 "2016-07-10T22:48:10Z")

</div>

Please start your own thread.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:48am UTC](https://discuss.elastic.co/t/es-2-2-index-not-found-exception-logstash/42929/6 "2017-07-06T04:48:43Z")

</div>


