# Filebeat logstash index not creating

**URL:** <https://discuss.elastic.co/t/filebeat-logstash-index-not-creating/141702>\
**Category:** Logstash\
**Created:** [July 26, 2018, 6:45am UTC](https://discuss.elastic.co/t/filebeat-logstash-index-not-creating/141702 "2018-07-26T06:45:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jamesarems](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesarems/32/33753_2.png) [@jamesarems](https://discuss.elastic.co/u/jamesarems)\
**Post date:** [July 26, 2018, 6:45am UTC](https://discuss.elastic.co/t/filebeat-logstash-index-not-creating/141702/1 "2018-07-26T06:45:08Z")

</div>

Hi,  
Good day..!  
I have configured ELK on a CentOS 7 machine.  
Initially i have got index in elastic search and accessed logs from kibana.  
Once i removed all index data from elastic search , problem started.  
I have checked all logs but no errors.  
My current logstash conf is given below. While checking logstash-plain.log file i can see incoming logs from filebeat.

```
# input section
input {
 beats {
   port => 5044
   ssl => true
   #start_position => "beginning"
   #sincedb_path => "/opt/dbflile"
   ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
   ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
  #congestion_threshold => "40"
  }
}
# Filter section
filter {
if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGLINE}" }
    }
    date {
match => ["timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]

}
  }
}
# output section
output {
  elasticsearch {
   hosts => "127.0.0.1:9200"
#index => "dailyserver-%{+YYYY.MM.dd}"
# document_type => "dailyserver"
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
}
}

```

I am using ELK 5.6.5 , i tried to reinstall several time. But no luck.  
Please help me to find the solution.

---

<div class="post-metadata">

**Author:** ![jamesarems](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesarems/32/33753_2.png) [@jamesarems](https://discuss.elastic.co/u/jamesarems)\
**Post date:** [July 26, 2018, 7:22am UTC](https://discuss.elastic.co/t/filebeat-logstash-index-not-creating/141702/2 "2018-07-26T07:22:52Z")

</div>

Hi,  
But while directly connecting from Filebeat to Elasticsearch, it is creating index file .  
I think something is related to logstash permission.  
Anybody have similar experience..?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2018, 7:22am UTC](https://discuss.elastic.co/t/filebeat-logstash-index-not-creating/141702/3 "2018-08-23T07:22:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
