# Index is not detting generated

**URL:** <https://discuss.elastic.co/t/index-is-not-detting-generated/169417>\
**Category:** Logstash\
**Created:** [February 21, 2019, 1:20pm UTC](https://discuss.elastic.co/t/index-is-not-detting-generated/169417 "2019-02-21T13:20:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![cppatel](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@cppatel](https://discuss.elastic.co/u/cppatel)\
**Post date:** [February 21, 2019, 1:20pm UTC](https://discuss.elastic.co/t/index-is-not-detting-generated/169417/1 "2019-02-21T13:20:36Z")

</div>

Index is not getting generated . Please find the following configurations related to the issue. I am not getting any error in logstash logs.  
Elasticsearch - 6.2.2  
Logstash - 6.2.2  
logstash.conf

input {  
file  
{  
path =\>["/log/X/Y/_", "/log/P/Q/_"]  
tags =\> ["Test"]  
}  
}

filter {

if "Test" in [tags]  
{  
grok {  
match =\> { "message" =\> "(%{TIMESTAMP\_ISO8601:timestamp}),%{NUMBER:milisecond} - iims.services.PolicyServiceHandler - INFO - UserCode %{DATA:UserId} | PolicyNumber %{NUMBER:PolicyNumber} | Premium %{NUMBER:Premium} | productcode %{WORD:ProductCode}" }  
remove\_field =\> ["message" , "milisecond"]  
}

```
date {
    match => ["timestamp" , "yyyy-MM-dd HH:mm:ss"]
    timezone => "Asia/Kolkata"
     }
	 
mutate {
     convert => { "Premium" => "integer" }
     }
	 
translate
    {
    field => "UserId"
    destination => "User"
    dictionary_path => "/etc/logstash/userdictionary.yml"
    fallback => "Others"
    exact => "true"
    regex => "true"
    }
	
}

```

}

output {

if "Test" in [tags]  
{  
elasticsearch {  
hosts =\> ["elkmonpt1.newindia.co.in:9200"]  
index =\> "niacorepremium-%{+YYYY.MM.dd}"  
user =\> logxxxx  
password =\> TYYYY  
}  
}

}

Logs I am trying to parse is :

2019-02-21 17:04:19,567 - iifs.services.PolicyServiceHandler - INFO - UserCode AG\_MNJSPQ | PolicyNumber 45210331180100010129 | Premium 1361 | productcode XY

Thanks for the help.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 21, 2019, 2:25pm UTC](https://discuss.elastic.co/t/index-is-not-detting-generated/169417/2 "2019-02-21T14:25:45Z")

</div>

Your grok pattern does not match your data. Your pattern has iims.services. and your data has iifs.services.

Are you saying the index does not get created or that the data in the index does not have the fields that you want?

---

<div class="post-metadata">

**Author:** ![cppatel](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@cppatel](https://discuss.elastic.co/u/cppatel)\
**Post date:** [February 22, 2019, 4:26am UTC](https://discuss.elastic.co/t/index-is-not-detting-generated/169417/3 "2019-02-22T04:26:54Z")

</div>

iifs.services in the data is modified by me only when I created the topic here. so, it is not the issue. My data is matching with my pattern. It is already checked on the grok debugger. My Index is just not getting created that is the issue. If grok pattern is different then logstash gives some error in logs. But in my case my pipeline is running successfully.  
The path from which I am fetching the data is like,

path =\> ["/log/folder1/X/ _", "/log/folder1/Y/_ "]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2019, 4:26am UTC](https://discuss.elastic.co/t/index-is-not-detting-generated/169417/4 "2019-03-22T04:26:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
