# Logstash elasticsearch output problem

**URL:** <https://discuss.elastic.co/t/logstash-elasticsearch-output-problem/234577>\
**Category:** Logstash\
**Created:** [May 27, 2020, 3:49pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-problem/234577 "2020-05-27T15:49:22Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![Rasoul\_Ahmadi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rasoul_ahmadi/32/68520_2.png) [@Rasoul\_Ahmadi](https://discuss.elastic.co/u/Rasoul_Ahmadi)\
**Post date:** [May 27, 2020, 9:51pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-problem/234577/6 "2020-05-27T21:51:46Z")

</div>

what could be wrong with this particular config?  
i have multiple configs just like this and everything is working except this one

```auto
input {
    file {
        path => ["${LL_LOG_IMPORT_NGINX:/var/log/remote/ingress-nginx/nginx-access.log}"]
        type => "nginx"
        sincedb_path => "${LL_SINCEDB_IMPORT_NGINX:/var/lib/logstash/plugins/inputs/file/nginx-import.sincedb}"
    }
}
filter {
    if [type] == "nginx" {
        grok {
          match => {
             "message" => "%{TIMESTAMP_ISO8601:loggedtime} %{IPORHOST:host } %{PROG:program}(?:\[%{POSINT:pid}\])?: %{HTTPD_COMBINEDLOG}"
          }
        }
       date {
           locale => "en"
           match => ["timestamp", "MMM dd yyyy HH:mm:ss", "MMM d yyyy HH:mm:ss", "dd/MMM/yyyy:HH:mm:ss Z", "ISO8601"]
       }
       geoip {
           source => "clientip"
       }
       useragent {
           source => "agent"
           prefix => "useragent_"
       }
       mutate {
           convert => { "bytes" => "integer" }
       }
    }
}
output {
    elasticsearch {
        hosts => ["http://localhost:9200"]
        index => "logstash-%{type}-%{+YYYY.MM}"
    }
}

```

---

_[View the full topic](https://discuss.elastic.co/t/logstash-elasticsearch-output-problem/234577)._
