# For ELK,sometimes Logstash says “no such index”, how to set automatic create index in ES while “no such index”?

**URL:** <https://discuss.elastic.co/t/for-elk-sometimes-logstash-says-no-such-index-how-to-set-automatic-create-index-in-es-while-no-such-index/62713>\
**Category:** Logstash\
**Created:** [October 11, 2016, 12:56pm UTC](https://discuss.elastic.co/t/for-elk-sometimes-logstash-says-no-such-index-how-to-set-automatic-create-index-in-es-while-no-such-index/62713 "2016-10-11T12:56:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![RJ\_W](https://avatars.discourse-cdn.com/v4/letter/r/f14d63/32.png) [@RJ\_W](https://discuss.elastic.co/u/RJ_W)\
**Post date:** [October 11, 2016, 12:56pm UTC](https://discuss.elastic.co/t/for-elk-sometimes-logstash-says-no-such-index-how-to-set-automatic-create-index-in-es-while-no-such-index/62713/1 "2016-10-11T12:56:41Z")

</div>

I found some pb with ELK, can anyone help me? thanks!

logstash 2.4.0  
elasticsearch 2.4.0  
3 elasticsearch instance for cluster

some time logstash warning  
“ "status"=\>404, "error"=\>{"type"=\>"index\_not\_found\_exception", "reason"=\>"no such index", ...”,  
and it doesn't work. curl -XGET ES indices, it truly not have the index. when this happen, i must kill -9 logstash, and start it again, then it can create a index in ES and it works ok again.

so, my question is how to set automatic create index in ES while “no such index”?

my logstash conf is:

input {  
tcp {  
port =\> 10514  
codec =\> "json"  
}  
}

output {  
elasticsearch {  
hosts =\> ["[9200.xxxxxx.com:9200](http://9200.xxxxxx.com:9200)" ]  
index =\> "log001-%{+YYYY.MM.dd}"  
}

---

<div class="post-metadata">

**Author:** ![RJ\_W](https://avatars.discourse-cdn.com/v4/letter/r/f14d63/32.png) [@RJ\_W](https://discuss.elastic.co/u/RJ_W)\
**Post date:** [October 11, 2016, 12:59pm UTC](https://discuss.elastic.co/t/for-elk-sometimes-logstash-says-no-such-index-how-to-set-automatic-create-index-in-es-while-no-such-index/62713/2 "2016-10-11T12:59:16Z")

</div>

this often happen in the new day , "{+YYYY.MM.dd} " .....  
and this time there is no error log in ES.  
only logstash seems in pb.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 11, 2016, 8:39pm UTC](https://discuss.elastic.co/t/for-elk-sometimes-logstash-says-no-such-index-how-to-set-automatic-create-index-in-es-while-no-such-index/62713/3 "2016-10-11T20:39:42Z")

</div>

Can you trace exactly which HTTP request that fails? Use e.g. Wireshark or Packetbeat. Elasticsearch should normally create indexes automatically as part of indexing requests.

---

<div class="post-metadata">

**Author:** ![RJ\_W](https://avatars.discourse-cdn.com/v4/letter/r/f14d63/32.png) [@RJ\_W](https://discuss.elastic.co/u/RJ_W)\
**Post date:** [October 12, 2016, 1:39am UTC](https://discuss.elastic.co/t/for-elk-sometimes-logstash-says-no-such-index-how-to-set-automatic-create-index-in-es-while-no-such-index/62713/4 "2016-10-12T01:39:32Z")

</div>

OK,I will trace it by Wireshark next time ,thanks !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:34am UTC](https://discuss.elastic.co/t/for-elk-sometimes-logstash-says-no-such-index-how-to-set-automatic-create-index-in-es-while-no-such-index/62713/5 "2017-07-06T04:34:39Z")

</div>


