# Index not being created in elasticsearch

**URL:** <https://discuss.elastic.co/t/index-not-being-created-in-elasticsearch/95423>\
**Category:** Logstash\
**Created:** [August 1, 2017, 10:18pm UTC](https://discuss.elastic.co/t/index-not-being-created-in-elasticsearch/95423 "2017-08-01T22:18:24Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![pravinnair](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pravinnair/32/32496_2.png) [@pravinnair](https://discuss.elastic.co/u/pravinnair)\
**Post date:** [August 1, 2017, 10:18pm UTC](https://discuss.elastic.co/t/index-not-being-created-in-elasticsearch/95423/1 "2017-08-01T22:18:24Z")

</div>

Simple ELK setup

I have created the GROK expression for IIB server logs and it works fine.

Only problem is the output filter is not creating an index on elasticsearch its always defaults to logstash-\* index

My plugin below this one does not create index  
input { stdin { } }  
filter {  
grok {  
match =\> {"message" =\> "^%{SYSLOGTIMESTAMP:timestamp} %{HOSTNAME:hostname} %{USERNAME:user}?:%{LOGLEVEL:log\_level}?|%{LOGLEVEL:log\_level} %{PROG:program}[%{POSINT:pid}]?: %{CISCO\_REASON:IIB\_Version} (%{NOTSPACE:Broker}.%{NOTSPACE:Execution\_Grp}) %{SYSLOG5424SD:Thread} (%{GREEDYDATA:msg}) %{NOTSPACE:errrCode}?: %{GREEDYDATA:message}"}  
}

}  
output {

elasticsearch {  
hosts =\> ["127.0.0.1:9200"]  
action =\> "index"  
index =\> "Broker-%{+YYYY.MM.dd}"

}  
stdout { codec =\> rubydebug }

}

This one works fine  
input { stdin { } }  
filter {  
grok {  
match =\> {"message" =\> "^%{SYSLOGTIMESTAMP:timestamp} %{HOSTNAME:hostname} %{USERNAME:user}?:%{LOGLEVEL:log\_level}?|%{LOGLEVEL:log\_level} %{PROG:program}[%{POSINT:pid}]?: %{CISCO\_REASON:IIB\_Version} (%{NOTSPACE:Broker}.%{NOTSPACE:Execution\_Grp}) %{SYSLOG5424SD:Thread} (%{GREEDYDATA:msg}) %{NOTSPACE:errrCode}?: %{GREEDYDATA:message}"}  
}

}  
output {

elasticsearch {  
hosts =\> ["127.0.0.1:9200"]  
}  
stdout { codec =\> rubydebug }

}

Here is where I am stuck now.

---

<div class="post-metadata">

**Author:** ![pravinnair](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pravinnair/32/32496_2.png) [@pravinnair](https://discuss.elastic.co/u/pravinnair)\
**Post date:** [August 2, 2017, 4:00pm UTC](https://discuss.elastic.co/t/index-not-being-created-in-elasticsearch/95423/2 "2017-08-02T16:00:29Z")

</div>

Resolved cannot use uppercase in index name.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 30, 2017, 4:00pm UTC](https://discuss.elastic.co/t/index-not-being-created-in-elasticsearch/95423/3 "2017-08-30T16:00:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
