# I cant put logs in elasticsearch from logstash

**URL:** <https://discuss.elastic.co/t/i-cant-put-logs-in-elasticsearch-from-logstash/79068>\
**Category:** Logstash\
**Created:** [March 17, 2017, 5:19pm UTC](https://discuss.elastic.co/t/i-cant-put-logs-in-elasticsearch-from-logstash/79068 "2017-03-17T17:19:34Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![adrianmc](https://avatars.discourse-cdn.com/v4/letter/a/3ec8ea/32.png) [@adrianmc](https://discuss.elastic.co/u/adrianmc)\
**Post date:** [March 17, 2017, 5:19pm UTC](https://discuss.elastic.co/t/i-cant-put-logs-in-elasticsearch-from-logstash/79068/1 "2017-03-17T17:19:34Z")

</div>

Im using logstash 1.4.2 and ... 🙂  
I have the next logstash.conf  
input {  
udp {  
port =\> 9991  
codec =\> netflow {  
definitions =\> "/home/profucom/logstash-1.4.2/lib/logstash/codecs/netflow/netflow.yaml"  
versions =\> [5]  
}  
}  
}

output {  
stdout { codec =\> rubydebug }  
elasticsearch {  
index =\> logstash-%{+YYYY.MM.dd}  
host =\> "localhost"  
}

}  
When i run "./logstash -f logstash.conf works fine, i get all information from my 2 routers, but im not sure if index =\> logstash-%{+YYYY.MM.dd} write the log.  
the log would be stored in curl 'localhost:9200/\_cat/indices?v ', or not?  
Thanks before all \<-\<

Notes: I run  
1- ./elasticsearch -d  
2- ./logstash -f logstash.conf  
3.- i put a template for logstash-\*  
4.- and of curse this code to get information from my routers

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 17, 2017, 8:16pm UTC](https://discuss.elastic.co/t/i-cant-put-logs-in-elasticsearch-from-logstash/79068/2 "2017-03-17T20:16:12Z")

</div>

> [@adrianmc](#):
>
> Im using logstash

You should _really_ upgrade.

> [@adrianmc](#):
>
> curl 'localhost:9200/\_cat/indices?v '

Does that work?

---

<div class="post-metadata">

**Author:** ![adrianmc](https://avatars.discourse-cdn.com/v4/letter/a/3ec8ea/32.png) [@adrianmc](https://discuss.elastic.co/u/adrianmc)\
**Post date:** [March 17, 2017, 8:41pm UTC](https://discuss.elastic.co/t/i-cant-put-logs-in-elasticsearch-from-logstash/79068/3 "2017-03-17T20:41:33Z")

</div>

Thanks for help!!! but... With  
curl 'localhost:9200/\_cat/indices?v'  
i got this  
health index pri rep docs.count docs.deleted store.size pri.store.size  
yellow kibana-int 5 1  
but i want to put here my index from my routers,  
because kibana dont show me nothing.

and I thought that elasticsearch { index =\> "logstash-%{+YYYY.MM.dd}" host =\> "localhost" } sent the log from my routers to elasticsearch for could read de log on kibana.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 17, 2017, 10:54pm UTC](https://discuss.elastic.co/t/i-cant-put-logs-in-elasticsearch-from-logstash/79068/4 "2017-03-17T22:54:27Z")

</div>

Do you see anything in stdout?

---

<div class="post-metadata">

**Author:** ![adrianmc](https://avatars.discourse-cdn.com/v4/letter/a/3ec8ea/32.png) [@adrianmc](https://discuss.elastic.co/u/adrianmc)\
**Post date:** [March 17, 2017, 11:01pm UTC](https://discuss.elastic.co/t/i-cant-put-logs-in-elasticsearch-from-logstash/79068/5 "2017-03-17T23:01:22Z")

</div>

Do you mean about router information? (in my case)  
Of curse , i can see traffic of my both routers.

But Honestly, im not sure if this part of code  
output {  
stdout { codec =\> rubydebug }  
elasticsearch {  
**index =\> logstash-%{+YYYY.MM.dd}**  
host =\> "localhost"  
}  
}  
let elasticsearch get logs from my router and Kibana can read.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 18, 2017, 2:46am UTC](https://discuss.elastic.co/t/i-cant-put-logs-in-elasticsearch-from-logstash/79068/6 "2017-03-18T02:46:23Z")

</div>

> [@adrianmc](#):
>
> stdout { codec =\> rubydebug }

That is what I mean. Is there anything visible there?

---

<div class="post-metadata">

**Author:** ![adrianmc](https://avatars.discourse-cdn.com/v4/letter/a/3ec8ea/32.png) [@adrianmc](https://discuss.elastic.co/u/adrianmc)\
**Post date:** [March 21, 2017, 3:33pm UTC](https://discuss.elastic.co/t/i-cant-put-logs-in-elasticsearch-from-logstash/79068/7 "2017-03-21T15:33:17Z")

</div>

Yeah man, In the console i can see the out put  
but  
how i can save the output in logs, for show it in kibana.  
I tried with "index =\> logstash-%{+YYYY.MM.dd} but does not works.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 21, 2017, 8:18pm UTC](https://discuss.elastic.co/t/i-cant-put-logs-in-elasticsearch-from-logstash/79068/8 "2017-03-21T20:18:07Z")

</div>

The rest of the config looks ok.  
Can you look at the `_cat` APIs to see if there is data in your cluster?

---

<div class="post-metadata">

**Author:** ![adrianmc](https://avatars.discourse-cdn.com/v4/letter/a/3ec8ea/32.png) [@adrianmc](https://discuss.elastic.co/u/adrianmc)\
**Post date:** [March 21, 2017, 8:38pm UTC](https://discuss.elastic.co/t/i-cant-put-logs-in-elasticsearch-from-logstash/79068/9 "2017-03-21T20:38:02Z")

</div>

Of curse, Mr.

i have the next:

**curl [http://localhost:9200/\_cat/indices?v](http://localhost:9200/_cat/indices?v)**

**health index pri rep doc.count doc.deleted store size pri.store.size**  
**red kibana-int 5 1**

my index should look like logstash-xxx-xxx-xxx, but i dont know why isn't working.

---

<div class="post-metadata">

**Author:** ![adrianmc](https://avatars.discourse-cdn.com/v4/letter/a/3ec8ea/32.png) [@adrianmc](https://discuss.elastic.co/u/adrianmc)\
**Post date:** [March 22, 2017, 6:07pm UTC](https://discuss.elastic.co/t/i-cant-put-logs-in-elasticsearch-from-logstash/79068/10 "2017-03-22T18:07:42Z")

</div>

Man, i can resolved my problem... i dont know how i can, but i only make a new installation.

And finally kibana shows me information about logs

However, Thank you very much :)!!!!!!!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2017, 6:08pm UTC](https://discuss.elastic.co/t/i-cant-put-logs-in-elasticsearch-from-logstash/79068/11 "2017-04-19T18:08:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
