# Logstash don't create index

**URL:** <https://discuss.elastic.co/t/logstash-dont-create-index/107441>\
**Category:** Logstash\
**Created:** [November 13, 2017, 4:53pm UTC](https://discuss.elastic.co/t/logstash-dont-create-index/107441 "2017-11-13T16:53:56Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ahmedcharef](https://avatars.discourse-cdn.com/v4/letter/a/9de053/32.png) [@ahmedcharef](https://discuss.elastic.co/u/ahmedcharef)\
**Post date:** [November 13, 2017, 4:53pm UTC](https://discuss.elastic.co/t/logstash-dont-create-index/107441/1 "2017-11-13T16:53:56Z")

</div>

Hi,  
I run ELK services on ubuntu 16.04.  
I have a csv file and I want to add it to elasticsearch, I use logstash for that:  
First this is my conf file:

> input {  
> file {  
> path =\> "/home/ahmed/Desktop/PopulationGenre.csv"  
> start\_position =\> "beginning"  
> sincedb\_path =\> "/dev/null"  
> }  
> }  
> filter {  
> csv {  
> separator =\> ","  
> columns =\> ["Year", "Population", "Male", "Female", "Density (km²)"]  
> }  
> }
> 
> output {  
> elasticsearch {  
> hosts =\> "[http://localhost:9200](http://localhost:9200)"  
> index =\> "popu"  
> document\_type =\> "populationDensity"  
> }  
> stdout {}  
> }

I run this command for the logststash:

`sudo /usr/share/logstash/bin/logstash --path.settings=/etc/logstash/ -f /home/ahmed/Desktop/population.conf`

This is the output of the command line:

> Sending Logstash's logs to /var/log/logstash which is now configured via log4j2.properties

Any help please !

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 13, 2017, 5:50pm UTC](https://discuss.elastic.co/t/logstash-dont-create-index/107441/2 "2017-11-13T17:50:59Z")

</div>

Are there any errors in /var/log/logstash/logstash-plain.log? I am thinking of a 'multiple instances' error, for example.

---

<div class="post-metadata">

**Author:** ![ahmedcharef](https://avatars.discourse-cdn.com/v4/letter/a/9de053/32.png) [@ahmedcharef](https://discuss.elastic.co/u/ahmedcharef)\
**Post date:** [November 13, 2017, 6:30pm UTC](https://discuss.elastic.co/t/logstash-dont-create-index/107441/3 "2017-11-13T18:30:19Z")

</div>

```
[2017-11-13T15:45:09,275][INFO][logstash.modules.scaffold] Initializing module {:module_name=>"netflow", :directory=>"/usr/share/logstash/mod$
[2017-11-13T15:45:09,284][INFO][logstash.modules.scaffold] Initializing module {:module_name=>"fb_apache", :directory=>"/usr/share/logstash/m$
[2017-11-13T15:45:09,294][INFO][logstash.setting.writabledirectory] Creating directory {:setting=>"path.queue", :path=>"/var/lib/logstash/que$
[2017-11-13T15:45:09,295][INFO][logstash.setting.writabledirectory] Creating directory {:setting=>"path.dead_letter_queue", :path=>"/var/lib/$
[2017-11-13T15:45:09,321][INFO][logstash.agent] No persistent UUID file found. Generating new UUID {:uuid=>"bea36a1f-5a5a-41e2-b88$
[2017-11-13T15:45:09,461][ERROR][logstash.agent] Cannot create pipeline {:reason=>"Expected one of #, {, ,, ] at line 14, column 32$
[2017-11-13T15:47:37,131][INFO][logstash.modules.scaffold] Initializing module {:module_name=>"netflow", :directory=>"/usr/share/logstash/mod$
[2017-11-13T15:47:37,138][INFO][logstash.modules.scaffold] Initializing module {:module_name=>"fb_apache", :directory=>"/usr/share/logstash/m$
[2017-11-13T15:47:37,351][ERROR][logstash.agent] Cannot create pipeline {:reason=>"Expected one of #, {, ,, ] at line 14, column 32$
[2017-11-13T15:51:32,594][INFO][logstash.modules.scaffold] Initializing module {:module_name=>"netflow", :directory=>"/usr/share/logstash/mod$
[2017-11-13T15:51:32,608][INFO][logstash.modules.scaffold] Initializing module {:module_name=>"fb_apache", :directory=>"/usr/share/logstash/m$
[2017-11-13T15:51:33,023][ERROR][logstash.agent] Cannot create pipeline {:reason=>"Expected one of #, {, ,, ] at line 14, column 32$
[2017-11-13T16:28:46,335][INFO][logstash.modules.scaffold] Initializing module {:module_name=>"netflow", :directory=>"/usr/share/logstash/mod$
[2017-11-13T16:28:46,364][INFO][logstash.modules.scaffold] Initializing module {:module_name=>"fb_apache", :directory=>"/usr/share/logstash/m$
[2017-11-13T16:28:46,660][INFO][logstash.modules.scaffold] Initializing module {:module_name=>"arcsight", :directory=>"/usr/share/logstash/ve$
[2017-11-13T16:28:47,099][INFO][logstash.agent] No config files found in path {:path=>"/etc/logstash/conf.d/*"}

```

I think the import log is:

- 

```
No config files found in path {:path=>"/etc/logstash/conf.d/*"}

```

The folder /etc/logstash/conf.d is **empty**.

---

<div class="post-metadata">

**Author:** ![ahmedcharef](https://avatars.discourse-cdn.com/v4/letter/a/9de053/32.png) [@ahmedcharef](https://discuss.elastic.co/u/ahmedcharef)\
**Post date:** [November 13, 2017, 7:02pm UTC](https://discuss.elastic.co/t/logstash-dont-create-index/107441/4 "2017-11-13T19:02:48Z")

</div>

```
[2017-11-13T19:59:44,330][ERROR][logstash.outputs.elasticsearch] Encountered a retryable error. Will Retry with exponential backoff {:code=>401, :url=>"http://127.0.0.1:9200/_bulk"}
[2017-11-13T19:59:46,834][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck_url=>http://127.0.0.1:9200/, :path=>"/"}
[2017-11-13T19:59:46,838][WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"http://127.0.0.1:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=>"Got response code '401' contacting Elasticsearch at URL 'http://127.0.0.1:9200/'"}

```

Also I found error to attempt elasticsearch from logstash.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 13, 2017, 9:39pm UTC](https://discuss.elastic.co/t/logstash-dont-create-index/107441/5 "2017-11-13T21:39:16Z")

</div>

You pass the path to the conf file on the command line, so it should not matter that there is not one in the default directory. What is the complete text of the "Cannot create pipeline" ERROR?

---

<div class="post-metadata">

**Author:** ![ahmedcharef](https://avatars.discourse-cdn.com/v4/letter/a/9de053/32.png) [@ahmedcharef](https://discuss.elastic.co/u/ahmedcharef)\
**Post date:** [November 14, 2017, 8:15am UTC](https://discuss.elastic.co/t/logstash-dont-create-index/107441/6 "2017-11-14T08:15:55Z")

</div>

I have just change the path of hosts in elasticsearch field in the config file.

> hosts =\> ["[http://elastic:changeme@127.0.0.1:9200](http://elastic:changeme@127.0.0.1:9200)"]

and it works fine.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2017, 8:15am UTC](https://discuss.elastic.co/t/logstash-dont-create-index/107441/7 "2017-12-12T08:15:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
