# Logstash has started but no elastic search index created in kibana

**URL:** <https://discuss.elastic.co/t/logstash-has-started-but-no-elastic-search-index-created-in-kibana/151497>\
**Category:** Logstash\
**Created:** [October 8, 2018, 5:18pm UTC](https://discuss.elastic.co/t/logstash-has-started-but-no-elastic-search-index-created-in-kibana/151497 "2018-10-08T17:18:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rakeshcse590](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rakeshcse590/32/20893_2.png) [@Rakeshcse590](https://discuss.elastic.co/u/Rakeshcse590)\
**Post date:** [October 8, 2018, 5:18pm UTC](https://discuss.elastic.co/t/logstash-has-started-but-no-elastic-search-index-created-in-kibana/151497/1 "2018-10-08T17:18:04Z")

</div>

Hi ,

I am trying to push csv data into elastic search db from log stash, I am able to see the message successfully started logstash, But elastic search index was not created.

* * *

below is my logstash config file

input {  
file{  
path =\> "C:\Users\RAKESH\Desktop\Kibana\Data\JMeterRes.csv"  
start\_position =\> "beginning"  
sincedb\_path =\> "nul"  
}  
}  
filter {  
if ([timeStamp] == "timeStamp")  
{  
drop {}  
}else{  
csv{  
columns =\> ["timeStamp","elapsed","label","responseCode","threadName","success","bytes","sentBytes","grpThreads","allThreads","Latency","SampleCount","ErrorCount","Hostname","Connect"]  
separator =\> ","  
skip\_header =\> true  
convert =\> {"elapsed" =\> "integer"  
"bytes" =\> "integer"  
"sentBytes" =\> "integer"  
"SampleCount" =\> "integer"  
"ErrorCount" =\> "integer"  
"grpThreads" =\> "integer"  
"allThreads" =\> "integer"  
}  
}  
}  
mutate {  
rename =\> {  
"timeStamp" =\> "time\_stamp"  
"elapsed" =\> "response\_time"  
"label" =\> "transaction\_name"  
"responseCode" =\> "response\_code"  
"threadName" =\> "thread\_name"  
"success" =\> "success\_status"  
"sentBytes" =\> "sent\_bytes"  
"grpThreads" =\> "grp\_threads"  
"allThreads" =\> "active\_users"  
"Latency" =\> "latency"  
"SampleCount" =\> "sample\_count"  
"ErrorCount" =\> "error\_count"  
"Hostname" =\> "loadagent\_name"  
"Connect" =\> "connect"  
}  
}  
}  
output {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "Rakesh-%{+YYYY.MM.dd}"

}  
stdout { codec =\> rubydebug }  
}

* * *

Below is the debug log of logstash.

[2018-10-08T22:19:25,906][DEBUG][logstash.outputs.elasticsearch] Normalizing http path {:path=\>nil, :normalized=\>nil}  
[2018-10-08T22:19:28,996][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2018-10-08T22:19:29,011][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
[2018-10-08T22:19:30,275][DEBUG][logstash.instrument.periodicpoller.jvm] collector name {:name=\>"ParNew"}  
[2018-10-08T22:19:30,275][DEBUG][logstash.instrument.periodicpoller.jvm] collector name {:name=\>"ConcurrentMarkSweep"}  
[2018-10-08T22:19:31,149][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
[2018-10-08T22:19:31,913][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>6}  
[2018-10-08T22:19:31,929][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2018-10-08T22:19:31,991][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//localhost:9200](https://localhost:9200)"]}  
[2018-10-08T22:19:32,038][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
[2018-10-08T22:19:32,038][DEBUG][logstash.filters.csv] CSV parsing options {:col\_sep=\>",", :quote\_char=\>"""}  
[2018-10-08T22:19:32,116][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
[2018-10-08T22:19:32,225][DEBUG][logstash.outputs.elasticsearch] Found existing Elasticsearch template. Skipping template management {:name=\>"logstash"}  
[2018-10-08T22:19:33,927][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x4e7d0981 sleep\>"}  
[2018-10-08T22:19:34,005][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections  
[2018-10-08T22:19:34,161][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>[]}  
[2018-10-08T22:19:34,208][DEBUG][logstash.agent] Starting puma  
[2018-10-08T22:19:34,224][DEBUG][logstash.agent] Trying to start WebServer {:port=\>9600}  
[2018-10-08T22:19:34,286][DEBUG][logstash.api.service] [api-service] start  
[2018-10-08T22:19:35,280][DEBUG][logstash.instrument.periodicpoller.jvm] collector name {:name=\>"ParNew"}  
[2018-10-08T22:19:35,280][DEBUG][logstash.instrument.periodicpoller.jvm] collector name {:name=\>"ConcurrentMarkSweep"}  
[2018-10-08T22:19:35,390][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2018-10-08T22:19:38,932][DEBUG][logstash.pipeline] Pushing flush onto pipeline {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x4e7d0981 sleep\>"}  
[2018-10-08T22:19:40,289][DEBUG][logstash.instrument.periodicpoller.jvm] collector name {:name=\>"ParNew"}  
[2018-10-08T22:19:40,305][DEBUG][logstash.instrument.periodicpoller.jvm] collector name {:name=\>"ConcurrentMarkSweep"}  
[2018-10-08T22:19:43,952][DEBUG][logstash.pipeline] Pushing flush onto pipeline {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x4e7d0981 sleep\>"}  
[2018-10-08T22:19:45,318][DEBUG][logstash.instrument.periodicpoller.jvm] collector name {:name=\>"ParNew"}  
[2018-10-08T22:19:45,318][DEBUG][logstash.instrument.periodicpoller.jvm] collector name {:name=\>"ConcurrentMarkSweep"}  
[2018-10-08T22:19:48,953][DEBUG][logstash.pipeline] Pushing flush onto pipeline {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x4e7d0981 sleep\>"}  
[2018-10-08T22:19:50,334][DEBUG][logstash.instrument.periodicpoller.jvm] collector name {:name=\>"ParNew"}  
[2018-10-08T22:19:50,334][DEBUG][logstash.instrument.periodicpoller.jvm] collector name {:name=\>"ConcurrentMarkSweep"}

---

<div class="post-metadata">

**Author:** ![balumurari1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/balumurari1/32/39203_2.png) [@balumurari1](https://discuss.elastic.co/u/balumurari1)\
**Post date:** [October 9, 2018, 4:42am UTC](https://discuss.elastic.co/t/logstash-has-started-but-no-elastic-search-index-created-in-kibana/151497/2 "2018-10-09T04:42:22Z")

</div>

change the path as shown below,

path =\> "C:/Users/RAKESH/Desktop/Kibana/Data/JMeterRes.csv"

---

<div class="post-metadata">

**Author:** ![Rakeshcse590](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rakeshcse590/32/20893_2.png) [@Rakeshcse590](https://discuss.elastic.co/u/Rakeshcse590)\
**Post date:** [October 9, 2018, 1:33pm UTC](https://discuss.elastic.co/t/logstash-has-started-but-no-elastic-search-index-created-in-kibana/151497/3 "2018-10-09T13:33:34Z")

</div>

Thank you so much @balumurari1. It worked with rge forward slash.  
Could you please explain why the path taking forward slash.

Thanks,  
Rakesh

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 6, 2018, 1:33pm UTC](https://discuss.elastic.co/t/logstash-has-started-but-no-elastic-search-index-created-in-kibana/151497/4 "2018-11-06T13:33:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
