# Logstash failed to push data (create indices) to elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-failed-to-push-data-create-indices-to-elasticsearch/131266>\
**Category:** Logstash\
**Created:** [May 10, 2018, 8:09am UTC](https://discuss.elastic.co/t/logstash-failed-to-push-data-create-indices-to-elasticsearch/131266 "2018-05-10T08:09:07Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![elsnewbie](https://avatars.discourse-cdn.com/v4/letter/e/f04885/32.png) [@elsnewbie](https://discuss.elastic.co/u/elsnewbie)\
**Post date:** [May 10, 2018, 8:09am UTC](https://discuss.elastic.co/t/logstash-failed-to-push-data-create-indices-to-elasticsearch/131266/1 "2018-05-10T08:09:07Z")

</div>

I am newbie in ELK. I am having a problem to create indices in ES which data coming from logstash (cloudwatch plugin). I use logstash 6.1.4 and ES 6.2.4. The config of logstash likes following

//input {  
// cloudwatch {  
// access\_key\_id =\> "XXXXXX"  
// secret\_access\_key =\> "YYYY"  
// interval =\> 300  
// namespace =\> "AWS/CloudFront"  
// metrics =\> ["4xxErrorRate", "5xxErrorRate", "BytesDownloaded", "BytesUploaded", "Requests", "TotalErrorRate"]  
// region =\> "us-east-1"  
// filters =\> {  
// "Region" =\> "Global"  
// }  
// add\_field =\> {  
// "Region" =\> "Global"  
// "techstack" =\> "XXXXXXX"  
// "source" =\> "CloudWatch"  
// "region" =\> "us-east-1"  
// }  
// }  
//}  
//output {  
// elasticsearch {  
// hosts =\> ["127.0.0.1:9200"]  
// user =\> "OOOOOO"  
// password =\> "XXXXXXXX"  
// }  
//}

I am pretty sure this setup works fine because that config copied from another production ELK farm (the indices are dynamically created). The problem is that I can only find .monitoring-[es|logstash|kibana]-6- and some .watcher-history-7- indcies. However, logstash- is missing. From the logstash log, I see the following

//[2018-05-10T03:34:50,345][DEBUG][logstash.pipeline] Pushing flush onto pipeline {:pipeline\_id=\>".monitoring-logstash", //:thread=\>"#\<Thread:0x6c9b339a@/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:245 sleep\>"}  
//[2018-05-10T03:34:51,252][DEBUG][logstash.pipeline] Pushing flush onto pipeline {:pipeline\_id=\>"main", //:thread=\>"#\<Thread:0x25b9ae90@/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:245 sleep\>"}  
//[2018-05-10T03:34:54,505][WARN][logstash.shutdownwatcher] {"inflight\_count"=\>0, "stalling\_thread\_info"=\>{"other"=\>[{"thread\_id"=\>36, "name"=\>"[main]\<cloudwatch", //"current\_call"=\>"[...]/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/interval.rb:89:in `sleep'"}, {"thread_id"=>37, "name"=>"[main]<cloudwatch", //"current_call"=>"[...]/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/interval.rb:89:in`sleep'"}, ............ {"thread\_id"=\>35, "name"=\>nil, //"current\_call"=\>"[...]/logstash-core/lib/logstash/util/wrapped\_synchronous\_queue.rb:133:in `initialize'"}]}}

How could I fix this problem?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2018, 8:13am UTC](https://discuss.elastic.co/t/logstash-failed-to-push-data-create-indices-to-elasticsearch/131266/2 "2018-06-07T08:13:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
