# How to get rid of wrongly named index that must be lower case

**URL:** <https://discuss.elastic.co/t/how-to-get-rid-of-wrongly-named-index-that-must-be-lower-case/52550>\
**Category:** Logstash\
**Created:** [June 13, 2016, 12:55am UTC](https://discuss.elastic.co/t/how-to-get-rid-of-wrongly-named-index-that-must-be-lower-case/52550 "2016-06-13T00:55:28Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![ikovalev](https://avatars.discourse-cdn.com/v4/letter/i/3bc359/32.png) [@ikovalev](https://discuss.elastic.co/u/ikovalev)\
**Post date:** [June 13, 2016, 12:55am UTC](https://discuss.elastic.co/t/how-to-get-rid-of-wrongly-named-index-that-must-be-lower-case/52550/1 "2016-06-13T00:55:28Z")

</div>

Wrong index name esm\_DMZ\_results was put into Logstash config file /opt/logstash/first-pipeline.conf . After that elasticsearch log /data/elastic/logs/elastic\_concept.log start showing "Invalid index name [esm\_DMZ\_results], must be lowercase" . I renamed index to lower case,  
cleared all cache: curl -XPOST '[http://wsp02051056wss.nam.nsroot.net:9200/\_cache/clear](http://wsp02051056wss.nam.nsroot.net:9200/_cache/clear)'  
checked on renamed index: curl -XGET '[http://wsp02051056wss.nam.nsroot.net:9200/esm\_dmz\_results/](http://wsp02051056wss.nam.nsroot.net:9200/esm_dmz_results/) '  
verified that old index does not exist: curl -XGET '[http://wsp02051056wss.nam.nsroot.net:9200/esm\_DMZ\_results/](http://wsp02051056wss.nam.nsroot.net:9200/esm_DMZ_results/) '  
checked on aliases: curl [http://wsp02051056wss.nam.nsroot.net:9200/\_aliases](http://wsp02051056wss.nam.nsroot.net:9200/_aliases)  
and list all indexes I have: curl '[wsp02051056wss.nam.nsroot.net:9200/\_cat/indices?v](http://wsp02051056wss.nam.nsroot.net:9200/_cat/indices?v)'

Old index is not there, but the same error message in the log keeps coming.

What am I missing, how to get rid of old index name?

Could this error be the reason why I do not see anything on Kibana?

---

<div class="post-metadata">

**Author:** ![Glen\_Smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glen_smith/32/111656_2.png) [@Glen\_Smith](https://discuss.elastic.co/u/Glen_Smith)\
**Post date:** [June 14, 2016, 1:58am UTC](https://discuss.elastic.co/t/how-to-get-rid-of-wrongly-named-index-that-must-be-lower-case/52550/2 "2016-06-14T01:58:22Z")

</div>

What does your Logstash config look like? Particularly the es-output.

---

<div class="post-metadata">

**Author:** ![ikovalev](https://avatars.discourse-cdn.com/v4/letter/i/3bc359/32.png) [@ikovalev](https://discuss.elastic.co/u/ikovalev)\
**Post date:** [June 14, 2016, 1:59pm UTC](https://discuss.elastic.co/t/how-to-get-rid-of-wrongly-named-index-that-must-be-lower-case/52550/3 "2016-06-14T13:59:39Z")

</div>

Here is complete config. For testing I have stdout there.

Separate issue is that even when I have both, "start\_position =\> beginning" and "ignore\_older =\> 0" in input clause, only new entries in the file are processed, not the whole file from the beginning.

/opt/logstash/first-pipeline.conf  
input {  
file {  
path =\> "/data/elastic/data/DMZ\_events.csv"  
start\_position =\> beginning

```
}

```

}  
filter {  
csv {  
columns =\> [  
"Region",  
"Starttime",  
"Finishtime",  
"PolicyName",  
"DomainName",  
"Agentname",  
"Managername",  
"Title",  
"Namevalue",  
"information",  
"Contact\_Group",  
"Primary\_contact",  
"Primary\_Contact\_SOEID",  
"Secondary\_Contact",  
"Secondary\_Contact\_SOEID",  
"OS\_Code",  
"Tier"  
]  
separator =\> ","  
remove\_field =\> ["DomainName"]  
}  
}  
output {  
elasticsearch {  
hosts =\> ["[wsp02051056wss.nam.nsroot.net:9200](http://wsp02051056wss.nam.nsroot.net:9200)"]  
action =\> "index"  
index =\> "esm\_dmz\_results"  
}  
stdout { }  
}

---

<div class="post-metadata">

**Author:** ![Glen\_Smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glen_smith/32/111656_2.png) [@Glen\_Smith](https://discuss.elastic.co/u/Glen_Smith)\
**Post date:** [June 14, 2016, 10:47pm UTC](https://discuss.elastic.co/t/how-to-get-rid-of-wrongly-named-index-that-must-be-lower-case/52550/4 "2016-06-14T22:47:06Z")

</div>

Is it possible you have a Logstash instance still running with the old config?

---

<div class="post-metadata">

**Author:** ![Glen\_Smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glen_smith/32/111656_2.png) [@Glen\_Smith](https://discuss.elastic.co/u/Glen_Smith)\
**Post date:** [June 14, 2016, 10:48pm UTC](https://discuss.elastic.co/t/how-to-get-rid-of-wrongly-named-index-that-must-be-lower-case/52550/5 "2016-06-14T22:48:23Z")

</div>

Also, moved to Logstash.

---

<div class="post-metadata">

**Author:** ![ikovalev](https://avatars.discourse-cdn.com/v4/letter/i/3bc359/32.png) [@ikovalev](https://discuss.elastic.co/u/ikovalev)\
**Post date:** [June 15, 2016, 1:49pm UTC](https://discuss.elastic.co/t/how-to-get-rid-of-wrongly-named-index-that-must-be-lower-case/52550/6 "2016-06-15T13:49:32Z")

</div>

No-no, Glen. I was restarting processes. I did not understand your last suggestion ( "move to logstash" ).

---

<div class="post-metadata">

**Author:** ![Glen\_Smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glen_smith/32/111656_2.png) [@Glen\_Smith](https://discuss.elastic.co/u/Glen_Smith)\
**Post date:** [June 15, 2016, 5:41pm UTC](https://discuss.elastic.co/t/how-to-get-rid-of-wrongly-named-index-that-must-be-lower-case/52550/7 "2016-06-15T17:41:02Z")

</div>

Hehe. I was only remarking that I moved the thread to the "Logstash" category, because it seems more relevant to your issue.

What response do you get if you post a document to the index directly?

```auto
POST http://wsp02051056wss.nam.nsroot.net:9200/esm_dmz_results/test_data
{
    "Region": "Foo"
}

```

---

<div class="post-metadata">

**Author:** ![ikovalev](https://avatars.discourse-cdn.com/v4/letter/i/3bc359/32.png) [@ikovalev](https://discuss.elastic.co/u/ikovalev)\
**Post date:** [June 16, 2016, 1:05am UTC](https://discuss.elastic.co/t/how-to-get-rid-of-wrongly-named-index-that-must-be-lower-case/52550/8 "2016-06-16T01:05:32Z")

</div>

# curl -XPOST '[http://wsp02051056wss.nam.nsroot.net:9200/esm\_dmz\_results/test\_data](http://wsp02051056wss.nam.nsroot.net:9200/esm_dmz_results/test_data) { "Region": "Foo" }'

curl: (52) Empty reply from server

Note that I did found already how to retrieve this index in Kibana web interface. This cancels my question “Could this error be the reason why I do not see anything on Kibana?”  
I still would appreciate advise how to get rid of the errors in the log related to wrong incorrect index name “esm\_DMZ\_results”.

Thank you.

Ivan

---

<div class="post-metadata">

**Author:** ![Glen\_Smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glen_smith/32/111656_2.png) [@Glen\_Smith](https://discuss.elastic.co/u/Glen_Smith)\
**Post date:** [June 17, 2016, 12:05am UTC](https://discuss.elastic.co/t/how-to-get-rid-of-wrongly-named-index-that-must-be-lower-case/52550/9 "2016-06-17T00:05:05Z")

</div>

If you can sort out why you can't curl the request, and then report how Elasticsearch responds to the request, that will be a step in the right direction.

---

<div class="post-metadata">

**Author:** ![ikovalev](https://avatars.discourse-cdn.com/v4/letter/i/3bc359/32.png) [@ikovalev](https://discuss.elastic.co/u/ikovalev)\
**Post date:** [June 17, 2016, 12:51am UTC](https://discuss.elastic.co/t/how-to-get-rid-of-wrongly-named-index-that-must-be-lower-case/52550/10 "2016-06-17T00:51:16Z")

</div>

This query, for example :  
curl -XGET '[http://wsp02051056wss.nam.nsroot.net:9200/esm\_dmz\_results/](http://wsp02051056wss.nam.nsroot.net:9200/esm_dmz_results/) '  
or that:  
curl -XPOST '[http://wsp02051056wss.nam.nsroot.net:9200/esm\_dmz\_results/\_search?pretty](http://wsp02051056wss.nam.nsroot.net:9200/esm_dmz_results/_search?pretty)' -d '{ "query": {"match\_all": {} } } '  
give valid results. I am newbie and not sure of the syntax, but looks like your test statement should be modified.

Thank you.

Ivan

---

<div class="post-metadata">

**Author:** ![Glen\_Smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glen_smith/32/111656_2.png) [@Glen\_Smith](https://discuss.elastic.co/u/Glen_Smith)\
**Post date:** [June 17, 2016, 2:15am UTC](https://discuss.elastic.co/t/how-to-get-rid-of-wrongly-named-index-that-must-be-lower-case/52550/11 "2016-06-17T02:15:12Z")

</div>

Sorry. I provided Sense format.

When converting it to a curl command, you shouldn't include the body in the quotes with the URL, you should pass it as binary data, as you did the match\_all query in your comment.

I hope that helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:52am UTC](https://discuss.elastic.co/t/how-to-get-rid-of-wrongly-named-index-that-must-be-lower-case/52550/12 "2017-07-06T04:52:25Z")

</div>


