# Logstash failed to index data in elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-failed-to-index-data-in-elasticsearch/172495>\
**Category:** Logstash\
**Created:** [March 15, 2019, 9:21am UTC](https://discuss.elastic.co/t/logstash-failed-to-index-data-in-elasticsearch/172495 "2019-03-15T09:21:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [March 15, 2019, 9:21am UTC](https://discuss.elastic.co/t/logstash-failed-to-index-data-in-elasticsearch/172495/1 "2019-03-15T09:21:41Z")

</div>

HI Team,  
I'm wondering with my configuration. Logstash is up and running but fail to parse data into elasticsearch, please find my conf below and correct me if am i doing any wrong,

I'm running using windows

```
input {
  file {
    path => "C:\Ganesh\logs\log\database.log"
	codec => multiline {
		pattern => "[\[A-Z\]]+ [0-9- :,]+"
		negate => "true"
		what => "next"
	}
	start_position => "beginning"
  }
}
filter{
	grok {
    match => { "message" => "\[%{WORD:debug}] %{TIMESTAMP_ISO8601:timestamp} \[%{GREEDYDATA:thread}\] %{WORD:LogType} \{sessionId=%{INT:SessionID}\} - ?(?<errorDescription>[a-zA-Z0-9 \n\s-`!@#$%^&*':\".,(){}\[\]~]+)" }
  }
}
output {
  elasticsearch {
    hosts => ["http://localhost:9200"]
    index => "t24-%{+YYYY.MM.dd}"
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2019, 9:21am UTC](https://discuss.elastic.co/t/logstash-failed-to-index-data-in-elasticsearch/172495/2 "2019-04-12T09:21:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
