# Logstash does not create Index in ELasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-does-not-create-index-in-elasticsearch/152555>\
**Category:** Logstash\
**Created:** [October 15, 2018, 8:53pm UTC](https://discuss.elastic.co/t/logstash-does-not-create-index-in-elasticsearch/152555 "2018-10-15T20:53:24Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![kunalwagh](https://avatars.discourse-cdn.com/v4/letter/k/e19b73/32.png) [@kunalwagh](https://discuss.elastic.co/u/kunalwagh)\
**Post date:** [October 15, 2018, 8:53pm UTC](https://discuss.elastic.co/t/logstash-does-not-create-index-in-elasticsearch/152555/1 "2018-10-15T20:53:24Z")

</div>

Logstash Pipeline is running successfully. Elasticsearch and Kibana are running successfully.  
Have apache\_access\_xxxx.log files in logstash/event-data

Checked [http://localhost:9200/\_cat/indices](http://localhost:9200/_cat/indices) and could not find logstash indices.

**Pipeline.conf**  
input {  
file {  
path =\> "C:/ELK-Stack/logstash/event-data/apache\_\*.log"  
start\_position =\> "beginning"  
codec =\> plain{charset =\> 'UTF-16BE'}  
}  
http {  
host =\> "localhost"  
port =\> 8088  
}  
}

filter {  
if [headers][request\_uri] =~ "error" or [path] =~ "errors" {  
mutate {  
replace =\> { type =\> "error" }  
}  
} else {  
mutate {  
replace =\> { type =\> "access" }  
}

```
	grok {
		match => { "message" => '%{HTTPD_COMMONLOG} "%{GREEDYDATA:referrer}" "%{GREEDYDATA:agent}"' }
	}

	if "_grokparsefailure" in [tags] {
		drop { }
	}

	useragent {
		source => "agent"
		target => "ua"
	}

	# Admin pages
	if [request] =~ /^\/admin\// {
		drop { }
	}

	# Static files
	if [request] =~ /^\/js\//
		or [request] =~ /^\/css\//
		or [request] in ["/robots.txt", "/favicon.ico"] {
		drop { }
	}

	# Crawlers
	if [ua][device] == "Spider" {
		drop { }
	}

	mutate {
		convert => {
			"response" => "integer"
			"bytes" => "integer"
		}
	}

	date {
		match => ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z"]
		remove_field => ["timestamp"]
	}

	geoip {
		source => "clientip"
	}
}

mutate {
	remove_field => ["headers", "@version", "host"]
}

```

}

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
document\_type =\> "default"  
#index =\> "%{type}-%{+YYYY.MM.dd}"  
http\_compression =\> true  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 12, 2018, 9:07pm UTC](https://discuss.elastic.co/t/logstash-does-not-create-index-in-elasticsearch/152555/2 "2018-11-12T21:07:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
