# Logstash Index error : \[logstash-\*\] IndexNotFoundException\[no such index\]

**URL:** <https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857>\
**Category:** Logstash\
**Created:** [December 23, 2015, 12:43pm UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857 "2015-12-23T12:43:23Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![carmelom](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@carmelom](https://discuss.elastic.co/u/carmelom)\
**Post date:** [December 23, 2015, 12:43pm UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/1 "2015-12-23T12:43:23Z")

</div>

Hello,  
I am new for ELK.  
I am using :  
- elasticsearch-2.1.0  
- logstash-2.1.1  
- kibana-4.3.0-windows  
I tried to configure ELK to monitoring my application logs and I followed different tutorials and different logstash configuration, but I am getting all the time this error :  
[logstash-\*] IndexNotFoundException[no such index]

This is my logstash config:

> input {  
> file {  
> path =\> "/var/logs/\*.log"  
> type =\> "syslog"  
> }  
> }  
> filter {  
> grok {  
> match =\> ["message", "%{COMBINEDAPACHELOG}"]  
> }  
> }  
> output {  
> elasticsearch { hosts =\> localhost }  
> stdout { codec =\> rubydebug }  
> }

I am looking for a very basic configuration, just for start to work with.  
Could someone give a clue?  
Every kind of tips are appreciated

Regards  
Carmelo

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 23, 2015, 10:30pm UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/2 "2015-12-23T22:30:41Z")

</div>

> [@carmelom](#):
>
> [logstash-\*] IndexNotFoundException[no such index]

Where is that error occuring?

---

<div class="post-metadata">

**Author:** ![carmelom](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@carmelom](https://discuss.elastic.co/u/carmelom)\
**Post date:** [December 29, 2015, 9:09am UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/3 "2015-12-29T09:09:08Z")

</div>

I am getting this error when I switch on kibana, and it send the request to the elasticsearch.

I tried to create a several Index for logstash, but no one was working to send the correct index to elasticsearch.

I am using logback and this is the pattern to write my logs:  
`%d{dd-MM-yy kk:mm:ss.SSS} %X{UUID} %X{userId} %-5level %logger - %msg%n`

Every kind of help is appreciate

Regards  
Carmelo

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 29, 2015, 9:10am UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/4 "2015-12-29T09:10:32Z")

</div>

What does the output from show?  
Is there data in ES? Check with `_cat/indices`.

---

<div class="post-metadata">

**Author:** ![carmelom](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@carmelom](https://discuss.elastic.co/u/carmelom)\
**Post date:** [December 29, 2015, 9:12am UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/5 "2015-12-29T09:12:33Z")

</div>

from : `http://localhost:9200/_cat/indices`

this is the result :

`yellow open .kibana 1 1 1 0 3.1kb 3.1kb`

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 29, 2015, 9:14am UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/6 "2015-12-29T09:14:36Z")

</div>

So there is no LS data in ES and you need to sort out your LS output and make sure that works.

From what I can see you do have problems with is, I'd suggest you double check the correct syntax here - [https://www.elastic.co/guide/en/logstash/2.1/plugins-outputs-elasticsearch.html](https://www.elastic.co/guide/en/logstash/2.1/plugins-outputs-elasticsearch.html)

---

<div class="post-metadata">

**Author:** ![carmelom](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@carmelom](https://discuss.elastic.co/u/carmelom)\
**Post date:** [December 29, 2015, 9:16am UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/7 "2015-12-29T09:16:32Z")

</div>

Thank you,  
I will do it.

I tried to use this plugin:  
`http://localhost:9200/_plugin/head/`

but I do not know how can I create a new index and connect it with my log files.

---

<div class="post-metadata">

**Author:** ![carmelom](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@carmelom](https://discuss.elastic.co/u/carmelom)\
**Post date:** [December 29, 2015, 12:34pm UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/8 "2015-12-29T12:34:45Z")

</div>

Hello,  
I deleted all folder and re install

- elasticsearch-2.1. **1**
- logstash-2.1.1
- kibana-4.3.0-windows

I tried to follow this tutorial step by step:  
`https://www.elastic.co/guide/en/logstash/current/advanced-pipeline.html`

Then I didn't received any kind of index, and I got again the `index Error` from `kibana` to `elasticsearch`

Any help ?

Regards  
Carmelo

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 29, 2015, 8:36pm UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/9 "2015-12-29T20:36:47Z")

</div>

Reinstalling won't fix it.

Does data actually exist in `/var/logs/*.log`? Have you tried using `stdin` in the input and then manually entering data?

---

<div class="post-metadata">

**Author:** ![carmelom](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@carmelom](https://discuss.elastic.co/u/carmelom)\
**Post date:** [December 30, 2015, 8:45am UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/10 "2015-12-30T08:45:32Z")

</div>

Yes, I tried this :  
`logstash -e 'input { stdin { } } output { stdout {} }'`  
and it is working fine.

And I added this in my output:  
`output { elasticsearch { hosts => ["localhost:9200"] } stdout { codec => rubydebug } }`  
But still doesn't work. because here:  
`http://localhost:9200/_cat/indices`  
I have only this :  
`yellow open .kibana 1 1 1 0 3.1kb 3.1kb`

---

<div class="post-metadata">

**Author:** ![carmelom](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@carmelom](https://discuss.elastic.co/u/carmelom)\
**Post date:** [December 30, 2015, 11:35am UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/11 "2015-12-30T11:35:23Z")

</div>

I tried the same steps in Ubuntu and it is working immediately.

Thank you for your time

---

<div class="post-metadata">

**Author:** ![carmelom](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@carmelom](https://discuss.elastic.co/u/carmelom)\
**Post date:** [December 30, 2015, 11:44am UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/12 "2015-12-30T11:44:39Z")

</div>

**Errata codices** :  
I tried the same steps in Ubuntu and it was working.  
Than I deleted the index in elasticsearch with :  
`curl -XDELETE http://localhost:9200/logstash-2015.12.30/`  
and try to recreate it with a different config file and logstash wasn't sent the new index to the elasticsearch.

someone know why ?

---

<div class="post-metadata">

**Author:** ![yahoo](https://avatars.discourse-cdn.com/v4/letter/y/898d66/32.png) [@yahoo](https://discuss.elastic.co/u/yahoo)\
**Post date:** [December 30, 2015, 2:13pm UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/13 "2015-12-30T14:13:15Z")

</div>

Hi  
I am in the same situation and having the same problem on windows.  
I followed the instructions and they don't work.  
Logstash is not creating the index in Elasticsearch.  
Why?

---

<div class="post-metadata">

**Author:** ![carmelom](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@carmelom](https://discuss.elastic.co/u/carmelom)\
**Post date:** [December 30, 2015, 2:19pm UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/14 "2015-12-30T14:19:57Z")

</div>

I don't know why.

> To make logstash to read and process your input every time you run logstash, use "sincedb\_path" option to **/dev/null** (cit.)

but I found this solution :  
`input { file { path => "/path/to/logstash-tutorial.log" start_position => beginning sincedb_path => "/dev/null" } }`  
and it is working

---

<div class="post-metadata">

**Author:** ![yahoo](https://avatars.discourse-cdn.com/v4/letter/y/898d66/32.png) [@yahoo](https://discuss.elastic.co/u/yahoo)\
**Post date:** [December 30, 2015, 2:43pm UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/15 "2015-12-30T14:43:57Z")

</div>

Thank you.  
I did  
sincedb\_path =\> "/dev/null"  
and Logstash created the index in Elasticsearch.

However, Logstash keeps reading the file and sending it. As if in a loop.  
I made the input file with oneline.  
Now I have a thousand identical lines (hits) in Elasticsearch

---

<div class="post-metadata">

**Author:** ![carmelom](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@carmelom](https://discuss.elastic.co/u/carmelom)\
**Post date:** [December 30, 2015, 2:47pm UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/16 "2015-12-30T14:47:24Z")

</div>

I tried only this example  
`https://www.elastic.co/guide/en/logstash/current/advanced-pipeline.html`  
with their logs, and it is working fine.

Now I am starting to "play" with different logs.  
I let you know

---

<div class="post-metadata">

**Author:** ![yahoo](https://avatars.discourse-cdn.com/v4/letter/y/898d66/32.png) [@yahoo](https://discuss.elastic.co/u/yahoo)\
**Post date:** [December 30, 2015, 3:25pm UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/17 "2015-12-30T15:25:12Z")

</div>

yes.  
I am trying this example.  
I used the one line they provided.  
When set  
sincedb\_path =\> "/dev/null"  
Logstash kept on sending the content again and again  
because in Windows there is no /dev/null.

I tried  
sincedb\_path =\> "nul"  
and it works so far.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 30, 2015, 9:29pm UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/18 "2015-12-30T21:29:22Z")

</div>

> [@yahoo](#):
>
> sincedb\_path =\> "/dev/null"

You both need to understand that sincedb keeps track of where LS has processed in any file that it reads and by setting that to `/dev/null` you are implying that you don't want to track the progress.

---

<div class="post-metadata">

**Author:** ![yahoo](https://avatars.discourse-cdn.com/v4/letter/y/898d66/32.png) [@yahoo](https://discuss.elastic.co/u/yahoo)\
**Post date:** [December 30, 2015, 9:58pm UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/19 "2015-12-30T21:58:17Z")

</div>

Hi @warkolm,  
Please let me share what I infer from you.  
when set sincedb at nul then every time Logstash is run it will start reading from the beginning of the file. They will cause duplicate entries.  
Right?

The reason I am touching sincedb is that I could not get Logstash to create an index in Elasticsearch.  
Any suggestion to solve this problem?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 1, 2016, 3:50am UTC](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857/20 "2016-01-01T03:50:27Z")

</div>

If you set it to `/dev/null` it will.

[Next page](https://discuss.elastic.co/t/logstash-index-error-logstash-indexnotfoundexception-no-such-index/37857.md?page=2)
