# Index creation failed

**URL:** <https://discuss.elastic.co/t/index-creation-failed/159710>\
**Category:** Logstash\
**Created:** [December 6, 2018, 10:48am UTC](https://discuss.elastic.co/t/index-creation-failed/159710 "2018-12-06T10:48:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sanchit\_Gupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sanchit_gupta/32/38108_2.png) [@Sanchit\_Gupta](https://discuss.elastic.co/u/Sanchit_Gupta)\
**Post date:** [December 6, 2018, 10:48am UTC](https://discuss.elastic.co/t/index-creation-failed/159710/1 "2018-12-06T10:48:57Z")

</div>

Hi Experts,

I am new to Elasticsearch and facing some error while creating the index.  
my flow is like filebeat --\> logstash --\> elasticsearch --\> kibana.

I am trying to read the SOA (weblogic) logs, below is my logstash conf file.

input:

```
input {
beats {
port => 5044
ssl => true
ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
}
}

```

Filter:

```
  filter {
  if [message] !~ /^####/ {
	drop {
	}
  }

  grok {
	match => { "message" => "\#\#\#\#\<%{DATA:msg_timestamp}\> \<%{DATA:msg_severity}\> \<%{DATA:msg_subsystem}\>%{GREEDYDATA:msg_details}" }
  }
  date {
	match => ["msg_timestamp", "MMM dd yyyy"]
  }
}

```

output:

```
output {
elasticsearch {
hosts => ["xx.xxx.xx.xxx:9200"]
sniffing => true
manage_template => false
index => "te_%{[@metadata][beat]}-%{+YYYY.MM.dd}"
document_type => "%{[@metadata][type]}"
}
stdout { codec => rubydebug }
}

```

Index Creation:

```
PUT _template/template_1
{
  "index_patterns": ["te*", "bar*"],
  "settings": {
	"number_of_shards": 1
  },
   "msg_timestamp": {
		  "type": "date",
		  "format": "MMM dd yyyy"
		}
	  }

```

using the above files i am facing the below error:

[2018-12-06T16:01:34,626][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"te\_filebeat-2018.12.06", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x6341c77b], :response=\>{"index"=\>{"\_index"=\>"te\_filebeat-2018.12.06", "\_type"=\>"doc", "\_id"=\>"ASwSg2cBLCbRLhh1nfvO", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse [msg\_timestamp]", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"Invalid format: "Mar 16, 2018 12:59:33 AM CDT""}}}}}

---

<div class="post-metadata">

**Author:** ![Sanchit\_Gupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sanchit_gupta/32/38108_2.png) [@Sanchit\_Gupta](https://discuss.elastic.co/u/Sanchit_Gupta)\
**Post date:** [December 7, 2018, 5:00am UTC](https://discuss.elastic.co/t/index-creation-failed/159710/2 "2018-12-07T05:00:29Z")

</div>

What is the best way to create the index

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 4, 2019, 5:00am UTC](https://discuss.elastic.co/t/index-creation-failed/159710/3 "2019-01-04T05:00:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
