# Logstash doesn't create index in ES, no errors

**URL:** <https://discuss.elastic.co/t/logstash-doesnt-create-index-in-es-no-errors/32617>\
**Category:** Logstash\
**Created:** [October 20, 2015, 8:17pm UTC](https://discuss.elastic.co/t/logstash-doesnt-create-index-in-es-no-errors/32617 "2015-10-20T20:17:07Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![UsreTX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usretx/32/5388_2.png) [@UsreTX](https://discuss.elastic.co/u/UsreTX)\
**Post date:** [October 20, 2015, 8:17pm UTC](https://discuss.elastic.co/t/logstash-doesnt-create-index-in-es-no-errors/32617/1 "2015-10-20T20:17:07Z")

</div>

I'm having trouble getting logstash to talk to ES.

My log files / console output are here:

**[http://stackoverflow.com/questions/33245721/logstash-cant-create-an-index-in-elasticsearch](http://stackoverflow.com/questions/33245721/logstash-cant-create-an-index-in-elasticsearch)**

In short, ES and Logstash appear to start fine, have no obvious errors in logs and nothing in the error logs, etc. But, my aliases dict is empty and I don't have a logstash index or data in ES. I really have no idea where to look for answers from here.

Help?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 20, 2015, 9:09pm UTC](https://discuss.elastic.co/t/logstash-doesnt-create-index-in-es-no-errors/32617/2 "2015-10-20T21:09:35Z")

</div>

Logstash's file input tails files by default. If you want it to read files from scratch make sure you set `start_position => beginning` and clear existing sincedb entries. See the file input documentation for more information.

General advice: Save yourself time by not attempt to go all the way and connect Logstash to ES until you've established that Logstash gets the messages and processes them correctly. Use a `stdout { codec => rubydebug }` to establish that.

---

<div class="post-metadata">

**Author:** ![UsreTX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usretx/32/5388_2.png) [@UsreTX](https://discuss.elastic.co/u/UsreTX)\
**Post date:** [October 21, 2015, 1:04pm UTC](https://discuss.elastic.co/t/logstash-doesnt-create-index-in-es-no-errors/32617/3 "2015-10-21T13:04:25Z")

</div>

Adding that helped, but only after stopping my service instance of logstash and starting logstash manually via bin/logstash -f [conf file]. Now, everything seems to be working but this isn't the "work around" I wanted.

How can I fix my logstash so it works correctly as a service?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 21, 2015, 2:52pm UTC](https://discuss.elastic.co/t/logstash-doesnt-create-index-in-es-no-errors/32617/4 "2015-10-21T14:52:11Z")

</div>

The reason it worked when you ran Logstash by hand was that sincedb state isn't shared between users so the files were treated as brand new and were processed from the begininning.

Again, if you want to reprocess log files you have to clear the sincedb entries. If you do that it'll work even when you run Logstash as a service.

---

<div class="post-metadata">

**Author:** ![UsreTX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usretx/32/5388_2.png) [@UsreTX](https://discuss.elastic.co/u/UsreTX)\
**Post date:** [October 21, 2015, 3:05pm UTC](https://discuss.elastic.co/t/logstash-doesnt-create-index-in-es-no-errors/32617/5 "2015-10-21T15:05:54Z")

</div>

Where is that file located? I've read it's in the home dir but ls -a | less of my home directory revealed nothing.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 21, 2015, 3:07pm UTC](https://discuss.elastic.co/t/logstash-doesnt-create-index-in-es-no-errors/32617/6 "2015-10-21T15:07:09Z")

</div>

The sincedb files are stored in the home directory of the user running Logstash. If you start Logstash with `--verbose` or `--debug` it'll tell you the exact path to the file being used.

---

<div class="post-metadata">

**Author:** ![UsreTX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usretx/32/5388_2.png) [@UsreTX](https://discuss.elastic.co/u/UsreTX)\
**Post date:** [October 21, 2015, 3:12pm UTC](https://discuss.elastic.co/t/logstash-doesnt-create-index-in-es-no-errors/32617/7 "2015-10-21T15:12:43Z")

</div>

{:timestamp=\>"2015-10-21T08:57:56.694000-0400", :message=\>"No sincedb\_path set, generating one based on the file path", :sincedb\_path=\>"/root/.sincedb\_8f309eb34476af59efaabf28f6aac73a", :path=\>["/var/log/python\_apps/_.log", "/var/log/python\_apps/_.log.\*"], :level=\>:info, :file=\>"logstash/inputs/file.rb", :line=\>"120", :method=\>"register"}

I'm new to linux, so forgive me if this isn't correct:

cd /root/ ; ll

total 4  
-rw-------. 1 root root 1108 Oct 12 12:20 anaconda-ks.cfg

ls -a | less

.  
..  
anaconda-ks.cfg  
.bash\_history  
.bash\_logout  
.bash\_profile  
.bashrc  
.cshrc  
.pki  
.tcshrc  
(END)

Where is it?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 21, 2015, 3:29pm UTC](https://discuss.elastic.co/t/logstash-doesnt-create-index-in-es-no-errors/32617/8 "2015-10-21T15:29:32Z")

</div>

Don't run Logstash as root. Run it as the logstash user (or some other non-privileged user). That's how the RPM and Debian packages set things up for you.

I don't know what's up with the missing sincedb file.

---

<div class="post-metadata">

**Author:** ![UsreTX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usretx/32/5388_2.png) [@UsreTX](https://discuss.elastic.co/u/UsreTX)\
**Post date:** [October 21, 2015, 3:32pm UTC](https://discuss.elastic.co/t/logstash-doesnt-create-index-in-es-no-errors/32617/9 "2015-10-21T15:32:50Z")

</div>

I'm on CentOS-7-x86\_64-Minimal-1503-01.

So something in my init is making logstash run as root, which is causing problems?

Or are you saying run things as user logstash manually, and ¯\_(ツ)\_/¯?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 21, 2015, 3:44pm UTC](https://discuss.elastic.co/t/logstash-doesnt-create-index-in-es-no-errors/32617/10 "2015-10-21T15:44:57Z")

</div>

> So something in my init is making logstash run as root, which is causing problems?

I'm pretty sure the RPMs provided by Elastic create a logstash user that the init scripts are supposed to start Logstash as.

---

<div class="post-metadata">

**Author:** ![UsreTX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usretx/32/5388_2.png) [@UsreTX](https://discuss.elastic.co/u/UsreTX)\
**Post date:** [October 21, 2015, 3:46pm UTC](https://discuss.elastic.co/t/logstash-doesnt-create-index-in-es-no-errors/32617/11 "2015-10-21T15:46:45Z")

</div>

So look in the init and see if it's not using user logstash?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 21, 2015, 3:48pm UTC](https://discuss.elastic.co/t/logstash-doesnt-create-index-in-es-no-errors/32617/12 "2015-10-21T15:48:01Z")

</div>

Yes, something like that. And check what user Logstash _actually_ runs as. Obviously, if HOME is /root but Logstash runs as logstash that would explain why no sincedb file is created.

---

<div class="post-metadata">

**Author:** ![UsreTX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usretx/32/5388_2.png) [@UsreTX](https://discuss.elastic.co/u/UsreTX)\
**Post date:** [October 21, 2015, 4:19pm UTC](https://discuss.elastic.co/t/logstash-doesnt-create-index-in-es-no-errors/32617/13 "2015-10-21T16:19:24Z")

</div>

/etc/init.d/logstash

LS\_USER=logstash  
LS\_GROUP=logstash

Also, if this file existed on my box, I would have found it with find regardless of what directory, which I didn't. And this doesn't explain why logstash said such existed in the root folder, anyway.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:25am UTC](https://discuss.elastic.co/t/logstash-doesnt-create-index-in-es-no-errors/32617/14 "2017-07-06T05:25:51Z")

</div>


