Importing indicies for filebeat

I've deleted all data from elasticsearch which included indicies
invoke-webrequest -method delete http://localhost:9200/*
After the deletion the server was rebooted
I'm able to see filebeat-6.2.4 under http://localhost:9200/_template but it is not showing in kibana

GET _cat/indices
yellow open winlogbeat-6.2.4-2018.06.20 bpfQeGqlTpWBkGv8Jf7Ctw 3 1 192 0 912.7kb 912.7kb
green open .kibana -TZavKI7RduCG6pjgwqw5A 1 0 3 1 24.3kb 24.3kb

Is there a way to import the indicies back ?

Hi @alexserd,

Indices and templates are something different. You should have indices back as soon as you start shipping new logs to your Elasticsearch.

Best regards

ok I guess I need to troubleshoot filebeat shipping - I'm able to start the service
here is flebeat.yml file


  • type: log
    - C:\inetpub\logs\LogFiles\W3SVC200*
    iis: true
    hosts: ["sna-wsus01:5044"]

The filebeat log file is empty

It looks like filebeat is shipping the logs, when I run .\filebeat.exe -c filebeat.yml -e -d "*" I get the following output:

2018-06-21T09:02:01.617-0700 INFO instance/beat.go:308 filebeat stopped.
2018-06-21T09:02:01.618-0700 INFO [monitoring] log/log.go:132 Total non-zero metrics {"monitoring": {"metrics
": {"beat":{"cpu":{"system":{"ticks":250,"time":250},"total":{"ticks":1062,"time":1062,"value":1062},"user":{"ticks":812
2018-06-21T09:02:01.620-0700 INFO [monitoring] log/log.go:133 Uptime: 3m0.9502076s
2018-06-21T09:02:01.620-0700 INFO [monitoring] log/log.go:110 Stopping metrics logging.

I still see no indices in Kibana

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.