# Index Patterns: Please specify a default index pattern

**URL:** <https://discuss.elastic.co/t/index-patterns-please-specify-a-default-index-pattern/140310>\
**Category:** Logstash\
**Created:** [July 17, 2018, 11:00am UTC](https://discuss.elastic.co/t/index-patterns-please-specify-a-default-index-pattern/140310 "2018-07-17T11:00:07Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aziz\_Sahnoun](https://avatars.discourse-cdn.com/v4/letter/a/d6d6ee/32.png) [@Aziz\_Sahnoun](https://discuss.elastic.co/u/Aziz_Sahnoun)\
**Post date:** [July 17, 2018, 11:00am UTC](https://discuss.elastic.co/t/index-patterns-please-specify-a-default-index-pattern/140310/1 "2018-07-17T11:00:07Z")

</div>

hello  
i'm using ELK on my virtual machine centos 7 using vSphere client  
i have some logs to visualise /var/log/secure  
i've connected my kibana via inginx and its working fine !  
i've set this configuration for /etc/logstash/conf.d/sshd.conf  
input {  
file {  
type =\> "secure\_log"  
path =\> "/var/log/secure"  
}  
}  
filter {  
include "pattern.txt"  
grok {  
add\_tag =\> ["sshd\_fail"]  
match =\> { "message" =\> "Failed %{WORD:sshd\_auth\_type} for %{USERNAME:sshd\_invalid\_user} from %{IP:sshd\_client\_ip} port %{NUMBER:sshd\_port} %{GREEDYDATA:sshd\_protocol}" }  
}  
}

output {  
elasticsearch {  
index =\> "sshd\_fail-%{+YYYY.MM}"  
}  
}

and i made a file .txt called pattern where i entred the pattern for my logs  
/etc/logstash/pattern/pattern.txt

%{SYSLOGTIMESTAMP:system.auth.timestamp} %{SYSLOGHOST:system.auth.hostname} sshd(?:\[%{POSINT:system.auth.pid}\])?: %{DATA:system.auth.ssh.event} %{DATA:system.auth.ssh.method} for (invalid user )?%{DATA:system.auth.user} from %{IPORHOST:system.auth.ip} port %{NUMBER:system.auth.port} ssh2(: %{GREEDYDATA:system.auth.ssh.signature})?

and i still have nthg

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/a/5a3fc9d9192fae7ef84110e60f54bd7b88fc44b9.png)

---

<div class="post-metadata">

**Author:** ![ons1](https://avatars.discourse-cdn.com/v4/letter/o/e79b87/32.png) [@ons1](https://discuss.elastic.co/u/ons1)\
**Post date:** [July 17, 2018, 11:13am UTC](https://discuss.elastic.co/t/index-patterns-please-specify-a-default-index-pattern/140310/3 "2018-07-17T11:13:33Z")

</div>

I have the same problem ..help please

---

<div class="post-metadata">

**Author:** ![tgaudin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tgaudin/32/32583_2.png) [@tgaudin](https://discuss.elastic.co/u/tgaudin)\
**Post date:** [July 17, 2018, 11:20am UTC](https://discuss.elastic.co/t/index-patterns-please-specify-a-default-index-pattern/140310/4 "2018-07-17T11:20:31Z")

</div>

> [@Aziz\_Sahnoun](#):
>
> output {  
> elasticsearch {  
> index =\> "sshd\_fail-%{+YYYY.MM}"  
> }  
> }

You should create an index pattern for `sshd_fail-*`, as this is the index Logstash is pushing the events to.

---

<div class="post-metadata">

**Author:** ![Aziz\_Sahnoun](https://avatars.discourse-cdn.com/v4/letter/a/d6d6ee/32.png) [@Aziz\_Sahnoun](https://discuss.elastic.co/u/Aziz_Sahnoun)\
**Post date:** [July 17, 2018, 11:23am UTC](https://discuss.elastic.co/t/index-patterns-please-specify-a-default-index-pattern/140310/5 "2018-07-17T11:23:46Z")

</div>

can you explain how to do that please ?

---

<div class="post-metadata">

**Author:** ![tgaudin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tgaudin/32/32583_2.png) [@tgaudin](https://discuss.elastic.co/u/tgaudin)\
**Post date:** [July 17, 2018, 11:27am UTC](https://discuss.elastic.co/t/index-patterns-please-specify-a-default-index-pattern/140310/6 "2018-07-17T11:27:01Z")

</div>

In the screenshot you shared (which tells you how to configure index patterns), replace `logstash-*` with `sshd_fail-*` in the text field.  
That would then match any index in Elasticsearch beginning with `sshd_fail-`.

---

<div class="post-metadata">

**Author:** ![Aziz\_Sahnoun](https://avatars.discourse-cdn.com/v4/letter/a/d6d6ee/32.png) [@Aziz\_Sahnoun](https://discuss.elastic.co/u/Aziz_Sahnoun)\
**Post date:** [July 17, 2018, 11:32am UTC](https://discuss.elastic.co/t/index-patterns-please-specify-a-default-index-pattern/140310/7 "2018-07-17T11:32:27Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/5/e/5eedddd13510562c223cedd2283d7fa05a5e2a67.png)

same problem ☹

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 17, 2018, 11:37am UTC](https://discuss.elastic.co/t/index-patterns-please-specify-a-default-index-pattern/140310/8 "2018-07-17T11:37:49Z")

</div>

Have you got any data indexed at all into Elasticsearch (use the [cat indices API](https://www.elastic.co/guide/en/elasticsearch/reference/6.3/cat-indices.html) to find out)? If not, have a look at how `synced_path` and `start_position` parameters are used with the file input plugin in [this tutorial](https://www.elastic.co/blog/a-practical-introduction-to-logstash).

---

<div class="post-metadata">

**Author:** ![tgaudin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tgaudin/32/32583_2.png) [@tgaudin](https://discuss.elastic.co/u/tgaudin)\
**Post date:** [July 17, 2018, 11:38am UTC](https://discuss.elastic.co/t/index-patterns-please-specify-a-default-index-pattern/140310/9 "2018-07-17T11:38:49Z")

</div>

Does your Logstash start correctly? Because this configuration

> [@Aziz\_Sahnoun](#):
>
> filter {  
> include "pattern.txt"

seems wrong to me, `include` is not a directive.

(Also, you should rework your grok configuration, the `patterns.txt` isn't the place for the complete pattern to match a log line, but for individuals patterns used in the `match` parameter)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2018, 11:38am UTC](https://discuss.elastic.co/t/index-patterns-please-specify-a-default-index-pattern/140310/10 "2018-08-14T11:38:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
