# Filebeat - It is not creating index on Kibana

**URL:** <https://discuss.elastic.co/t/filebeat-it-is-not-creating-index-on-kibana/74402>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 8, 2017, 3:56pm UTC](https://discuss.elastic.co/t/filebeat-it-is-not-creating-index-on-kibana/74402 "2017-02-08T15:56:59Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sujith](https://avatars.discourse-cdn.com/v4/letter/s/77aa72/32.png) [@Sujith](https://discuss.elastic.co/u/Sujith)\
**Post date:** [February 8, 2017, 3:56pm UTC](https://discuss.elastic.co/t/filebeat-it-is-not-creating-index-on-kibana/74402/1 "2017-02-08T15:56:59Z")

</div>

Hello!

I am using ELK stack version 5.2 latest.

I'm trying to configure the FIlebeat. My configuration is Filebeat \> Elasticsearch \> Kibana.  
However there is something wrong and I couldn't figure it out. There are some errors in the log and the index is not created on Kibana.

I have configured index template file for Filebeat.

I have deleted data by curl -XDELETE '[http://localhost:9200/filebeat-\*](http://localhost:9200/filebeat-*)' and configured filebeat index template by using below command, but still index issue persists.  
PS C:\Program Files\Filebeat\> Invoke-WebRequest -Method Put -InFile filebeat.template.json -Uri [http://localhost:9200/\_template/filebeat?pretty](http://localhost:9200/_template/filebeat?pretty)

please find [http://localhost:9200/\_template/filebeat?pretty](http://localhost:9200/_template/filebeat?pretty) data below.

```auto
{
  "filebeat" : {
    "order" : 0,
    "template" : "filebeat-*",
    "settings" : {
      "index" : {
        "mapping" : {
          "total_fields" : {
            "limit" : "10000"
          }
        },
        "refresh_interval" : "5s"
      }
    },
    "mappings" : {
      "_default_" : {
        "_meta" : {
          "version" : "5.2.0"
        },
        "dynamic_templates" : [
          {
            "strings_as_keyword" : {
              "mapping" : {
                "ignore_above" : 1024,
                "type" : "keyword"
              },
              "match_mapping_type" : "string"
            }
          }
        ],
        "_all" : {
          "norms" : false
        },
        "properties" : {
          "@timestamp" : {
            "type" : "date"
          },
          "offset" : {
            "type" : "long"
          },
          "meta" : {
            "properties" : {
              "cloud" : {
                "properties" : {
                  "machine_type" : {
                    "ignore_above" : 1024,
                    "type" : "keyword"
                  },
                  "availability_zone" : {
                    "ignore_above" : 1024,
                    "type" : "keyword"
                  },
                  "instance_id" : {
                    "ignore_above" : 1024,
                    "type" : "keyword"
                  },
                  "project_id" : {
                    "ignore_above" : 1024,
                    "type" : "keyword"
                  },
                  "provider" : {
                    "ignore_above" : 1024,
                    "type" : "keyword"
                  },
                  "region" : {
                    "ignore_above" : 1024,
                    "type" : "keyword"
                  }
                }
              }
            }
          },
          "beat" : {
            "properties" : {
              "hostname" : {
                "ignore_above" : 1024,
                "type" : "keyword"
              },
              "name" : {
                "ignore_above" : 1024,
                "type" : "keyword"
              },
              "version" : {
                "ignore_above" : 1024,
                "type" : "keyword"
              }
            }
          },
          "input_type" : {
            "ignore_above" : 1024,
            "type" : "keyword"
          },
          "source" : {
            "ignore_above" : 1024,
            "type" : "keyword"
          },
          "message" : {
            "norms" : false,
            "type" : "text"
          },
          "type" : {
            "ignore_above" : 1024,
            "type" : "keyword"
          },
          "tags" : {
            "ignore_above" : 1024,
            "type" : "keyword"
          }
        }
      }
    },
    "aliases" : { }
  }
}

```

Please help us in creating filebeat index pattern.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 8, 2017, 10:18pm UTC](https://discuss.elastic.co/t/filebeat-it-is-not-creating-index-on-kibana/74402/2 "2017-02-08T22:18:53Z")

</div>

> [@Sujith](#):
>
> There are some errors in the log and the index is not created on Kibana.

What are the errors?

---

<div class="post-metadata">

**Author:** ![Sujith](https://avatars.discourse-cdn.com/v4/letter/s/77aa72/32.png) [@Sujith](https://discuss.elastic.co/u/Sujith)\
**Post date:** [February 9, 2017, 9:41am UTC](https://discuss.elastic.co/t/filebeat-it-is-not-creating-index-on-kibana/74402/3 "2017-02-09T09:41:28Z")

</div>

I am finidng below error in filebeat logs

2017-02-09T02:27:34-06:00 DBG Check file for harvesting: D:\Team\logs\SystemOut\_17.02.07\_13.16.49.log  
2017-02-09T02:27:34-06:00 DBG Update existing file for harvesting: D:\Team\logs\SystemOut\_17.02.07\_13.16.49.log, offset: 1048570  
2017-02-09T02:27:34-06:00 DBG File didn't change: D:\Team\logs\SystemOut\_17.02.07\_13.16.49.log  
2017-02-09T02:27:34-06:00 DBG Check file for harvesting: D:\Team\logs\ARSGBCGLOBAL\_SecurityUpdateEventHandler\_2016-12-20.log  
2017-02-09T02:27:34-06:00 DBG Update existing file for harvesting: D:\Team\logs\ARSGBCGLOBAL\_SecurityUpdateEventHandler\_2016-12-20.log, offset: 52117551  
2017-02-09T02:27:34-06:00 DBG File didn't change: D:\Team\logs\ARSGBCGLOBAL\_SecurityUpdateEventHandler\_2016-12-20.log  
2017-02-09T02:27:34-06:00 DBG Prospector states cleaned up. Before: 42, After: 42  
2017-02-09T02:27:39-06:00 DBG Flushing spooler because of timeout. Events flushed: 0  
2017-02-09T02:27:44-06:00 DBG Flushing spooler because of timeout. Events flushed: 0  
2017-02-09T02:27:44-06:00 DBG Run prospector  
2017-02-09T02:27:44-06:00 DBG Start next scan

---

<div class="post-metadata">

**Author:** ![Sujith](https://avatars.discourse-cdn.com/v4/letter/s/77aa72/32.png) [@Sujith](https://discuss.elastic.co/u/Sujith)\
**Post date:** [February 9, 2017, 9:43am UTC](https://discuss.elastic.co/t/filebeat-it-is-not-creating-index-on-kibana/74402/4 "2017-02-09T09:43:24Z")

</div>

I have deleted data using curl -XDELETE '[http://localhost:9200/filebeat-\*](http://localhost:9200/filebeat-*)'

and also configured template manually by using below command  
PS C:\Program Files\Filebeat\> Invoke-WebRequest -Method Put -InFile filebeat.template.json -Uri [http://localhost:9200/\_template/filebeat?pretty](http://localhost:9200/_template/filebeat?pretty)

still we could not able to index filebeat in kibana.

Before some days back we can able to and now we could not able to.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 9, 2017, 2:21pm UTC](https://discuss.elastic.co/t/filebeat-it-is-not-creating-index-on-kibana/74402/5 "2017-02-09T14:21:27Z")

</div>

There are no errors in the log output you posted. Perhaps no new data is coming into the file?

Deleting the `filebeat-*` indicies does not cause filebeat to resend all data. Filebeat stores state info on the host in a [file](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-global-options.html#_registry_file). You can stop filebeat, delete the file, then restart filebeat to make it resend all data.

---

<div class="post-metadata">

**Author:** ![Sujith](https://avatars.discourse-cdn.com/v4/letter/s/77aa72/32.png) [@Sujith](https://discuss.elastic.co/u/Sujith)\
**Post date:** [February 11, 2017, 2:41pm UTC](https://discuss.elastic.co/t/filebeat-it-is-not-creating-index-on-kibana/74402/6 "2017-02-11T14:41:11Z")

</div>

Thank you Andrewkroh for your update. I ahve deleted old records and inserted new data so its fixed now. I can index filebeat now 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 11, 2017, 2:41pm UTC](https://discuss.elastic.co/t/filebeat-it-is-not-creating-index-on-kibana/74402/7 "2017-03-11T14:41:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
