# Indices Creation Failed in ES via Logstash from Filebeat

**URL:** <https://discuss.elastic.co/t/indices-creation-failed-in-es-via-logstash-from-filebeat/113666>\
**Category:** Logstash\
**Created:** [December 31, 2017, 6:11pm UTC](https://discuss.elastic.co/t/indices-creation-failed-in-es-via-logstash-from-filebeat/113666 "2017-12-31T18:11:45Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![No\_Name](https://avatars.discourse-cdn.com/v4/letter/n/a4c791/32.png) [@No\_Name](https://discuss.elastic.co/u/No_Name)\
**Post date:** [December 31, 2017, 6:11pm UTC](https://discuss.elastic.co/t/indices-creation-failed-in-es-via-logstash-from-filebeat/113666/1 "2017-12-31T18:11:45Z")

</div>

Greetings, and Happy New Year!

We have 2 filbeats (from different servers, IP\_A and IP\_B) are connecting to Logstash in IP\_C. Then we have the ES and Kibana set up in IP\_C too. The problem I'm facing is that I'm only able to query the logs from filebeat in IP\_A and nothing from the filebeat in IP\_B.

I've ran on debug mode on the filebeat in IP\_B and logstash, I could see the message is pushed across to logstash. However, when I query in ES, there's nothing.

Both filebeats have identical configuration. I'm running on filebeat (version 5.6.3), logstash (version 5.6.2) and ES (version 5.6.2).

I've been scratching my head for a few days now and couldn't figure out the root cause for this. Any help/advice is much appreciated.  
Thank you.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 31, 2017, 6:24pm UTC](https://discuss.elastic.co/t/indices-creation-failed-in-es-via-logstash-from-filebeat/113666/2 "2017-12-31T18:24:10Z")

</div>

May be logstash can not parse the logs from the other server?

---

<div class="post-metadata">

**Author:** ![No\_Name](https://avatars.discourse-cdn.com/v4/letter/n/a4c791/32.png) [@No\_Name](https://discuss.elastic.co/u/No_Name)\
**Post date:** [January 1, 2018, 2:48am UTC](https://discuss.elastic.co/t/indices-creation-failed-in-es-via-logstash-from-filebeat/113666/3 "2018-01-01T02:48:14Z")

</div>

Hi Dave,

The Logstash did received the events from filebeat in IP\_B. The communication there is confirmed successful as I could see the messages in Logstash when running it on debug mode.

I just wonder if there's any known issue behind this kind of design, as I've seen some people raising the exact same issue (unfortunately with no reply).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 1, 2018, 5:38am UTC](https://discuss.elastic.co/t/indices-creation-failed-in-es-via-logstash-from-filebeat/113666/4 "2018-01-01T05:38:42Z")

</div>

I don't know. I moved your question to #logstash in case someone else has an idea.

I think it could help to share some of your logstash debug logs.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 1, 2018, 5:46am UTC](https://discuss.elastic.co/t/indices-creation-failed-in-es-via-logstash-from-filebeat/113666/5 "2018-01-01T05:46:15Z")

</div>

What does you Logstash config look like? Do the data from both Filebeat instances go into the same pipeline?

---

<div class="post-metadata">

**Author:** ![No\_Name](https://avatars.discourse-cdn.com/v4/letter/n/a4c791/32.png) [@No\_Name](https://discuss.elastic.co/u/No_Name)\
**Post date:** [January 1, 2018, 6:07am UTC](https://discuss.elastic.co/t/indices-creation-failed-in-es-via-logstash-from-filebeat/113666/6 "2018-01-01T06:07:52Z")

</div>

Thanks Dave.

Hi Christian,

The Logstash config is as below. Yes, both Filebeat instances are going into the same pipeline.

```
input {
    beats {
        port => 5400
    }
}

filter {
 grok {
   match => { 'message' => '%{IPORHOST:clientip} - - \[%{HTTPDATE:timestamp}\] \"(?:%{WORD:verb} %{URIPATHPARAM:request}(?: HTTP/%{NUMBER:httpversion})?|)\" %{NUMBER:answer} (?:%{NUMBER:byte}|-) (?:\"(?:%{URI:referrer}|-))\" %{QS:agent} "%{IPORHOST:proxyip}" "%{IPORHOST:hostname}" "%{GREEDYDATA:ident}"'}
 }
 mutate {
   convert => ["bytes", "integer"]
 }
 geoip {
   source => "clientip"
   target => "geoip"
   add_tag => ["nginx-geoip"]
 }
 date {
   match => ["timestamp" , "dd/MMM/YYYY:HH:mm:ss Z"]
   remove_field => ["timestamp"]
 }
 useragent {
   source => "agent"
 }
}

output {
 elasticsearch {
   hosts => ["localhost:9200"]
   index => "weblog-%{+YYYY.MM.dd}"
   document_type => "nginx_logs"
 }
 stdout { codec => rubydebug }
}

```

Below are snippets of the DEBUG logs in the Logstash via zgrep:

/var/log/logstash.own/logstash-plain-2017-12-28.log.gz:[2017-12-28T06:31:58,258][DEBUG][logstash.pipeline] output received {"event"=\>{"request"=\>"/app/profile/edit.do?task=doShareChartData", "agent"=\>""Mozilla/5.0 (Linux; Android 6.0.1; OPPO R9s Build/MMB29M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/46.0.2490.76 Mobile Safari/537.36"", "proxyip"=\>"108.xxx.xxx.227", "minor"=\>"0", "ident"=\>"xxxxx777", "os\_minor"=\>"0", "os\_major"=\>"6", "source"=\>"/home/nginxlogs/nginx-access.log", "type"=\>"log", "patch"=\>"2490", "hostname"=\>"[www.xxxx.com](http://www.xxxx.com)", "major"=\>"46", "clientip"=\>"116.xxx.xxx.86", "@version"=\>"1", "beat"=\>{"name"=\>"[fb2.xxx.xxx.com](http://fb2.xxx.xxx.com)", "hostname"=\>"[fb2.xxx.xxx.com](http://fb2.xxx.xxx.com)", "version"=\>"5.6.3"}, "host"=\>"[fb2.xxx.xxx.com](http://fb2.xxx.xxx.com)", "geoip"=\>{"city\_name"=\>"xxx", "timezone"=\>"xxx", "ip"=\>"xxx", "latitude"=\>xxx, "country\_name"=\>"xxx", "country\_code2"=\>"xx", "continent\_code"=\>"xx", "country\_code3"=\>"xx", "region\_name"=\>"xxxx", "location"=\>{"lon"=\>xxx, "lat"=\>xxx}, ......}}

(Apologies, i had to "mask" certain values).  
Thanks for helping out. However, I can't see how the issue is on the Logstash, as I'm able to see the logs which are coming in from Filebeat in IP\_B. I have different name and hostname on the [beat.name](http://beat.name) and beat.hostname elements.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 29, 2018, 6:08am UTC](https://discuss.elastic.co/t/indices-creation-failed-in-es-via-logstash-from-filebeat/113666/7 "2018-01-29T06:08:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
