# Logstash index is not creating

**URL:** <https://discuss.elastic.co/t/logstash-index-is-not-creating/56276>\
**Category:** Logstash\
**Created:** [July 25, 2016, 8:48am UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276 "2016-07-25T08:48:10Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![ramanamohan](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@ramanamohan](https://discuss.elastic.co/u/ramanamohan)\
**Post date:** [July 25, 2016, 8:48am UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276/1 "2016-07-25T08:48:10Z")

</div>

Hi,

I am unable to get the Logstash index created with my Logstash conf file.  
Below is the configuration file,

input {  
file {  
path =\> "/logs/exampledata\_01.log"  
type =\> "json"  
start\_position =\> beginning  
ignore\_older =\> 0  
}  
}

filter{  
json{  
source =\> "message"  
}  
}  
output {  
stdout {  
codec =\> rubydebug  
}  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "logstash-json"  
}  
}

I get the below output in cmd promt,

C:\logstash-2.3.4\logstash-2.3.4\bin\>logstash -f C:\logstash-2.3.4\logstash-2.3.4\bin\logstash.conf  
io/console not supported; tty will not be manipulated  
Settings: Default pipeline workers: 4  
Pipeline main started

After that it is supposed to show me the index created rite. But nothing happens after that.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 25, 2016, 8:53am UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276/2 "2016-07-25T08:53:48Z")

</div>

it may be [https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#\_tracking\_of\_current\_position\_in\_watched\_files](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#_tracking_of_current_position_in_watched_files)

---

<div class="post-metadata">

**Author:** ![ramanamohan](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@ramanamohan](https://discuss.elastic.co/u/ramanamohan)\
**Post date:** [July 25, 2016, 11:49am UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276/3 "2016-07-25T11:49:10Z")

</div>

I tried

1. sincedb\_path =\> null
2. Manually deleted the sincedb file

Still the same situation.

The index is not getting created.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 25, 2016, 9:41pm UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276/4 "2016-07-25T21:41:36Z")

</div>

What about [https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-ignore\_older](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-ignore_older)

---

<div class="post-metadata">

**Author:** ![Sri\_ram](https://avatars.discourse-cdn.com/v4/letter/s/3da27b/32.png) [@Sri\_ram](https://discuss.elastic.co/u/Sri_ram)\
**Post date:** [July 25, 2016, 9:57pm UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276/5 "2016-07-25T21:57:53Z")

</div>

> [@ramanamohan](#):
>
> output { stdout { codec =\> rubydebug } elasticsearch { hosts =\> "localhost:9200" index =\> "logstash-json" }}

Can you try adding `action => "index"` to your output section. By specifying this line under hosts should work.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 25, 2016, 10:34pm UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276/6 "2016-07-25T22:34:48Z")

</div>

Why? That is the default action anyway.

---

<div class="post-metadata">

**Author:** ![niraj\_kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/niraj_kumar/32/4130_2.png) [@niraj\_kumar](https://discuss.elastic.co/u/niraj_kumar)\
**Post date:** [July 25, 2016, 10:47pm UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276/7 "2016-07-25T22:47:12Z")

</div>

just curious, can you put the hosts in array something like ["localhost:9200"] and remove manually specifying of index. Let logstash create its own index and then the meantime have a watch at both elasticsearch and logstash logs simultaneously .

---

<div class="post-metadata">

**Author:** ![ramanamohan](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@ramanamohan](https://discuss.elastic.co/u/ramanamohan)\
**Post date:** [July 26, 2016, 8:39am UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276/8 "2016-07-26T08:39:37Z")

</div>

Added Path value as array,  
path =\> ["/logs/exampledata\_01.json"]

sincedb value as string  
sincedb\_path =\> "null"

Configuration is fine, but index is not creating,

C:\logstash-2.3.4\bin\>logstash agent -f C:\logstash-2.3.4\bin\exampleConf.conf  
io/console not supported; tty will not be manipulated  
Settings: Default pipeline workers: 4  
Pipeline main started

---

<div class="post-metadata">

**Author:** ![ramanamohan](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@ramanamohan](https://discuss.elastic.co/u/ramanamohan)\
**Post date:** [July 26, 2016, 8:40am UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276/9 "2016-07-26T08:40:51Z")

</div>

Ya tried as you suggested,

output {  
stdout {  
codec =\> rubydebug  
}  
elasticsearch {  
hosts =\> ["localhost:9200"]  
}  
}

Still no index creation,

C:\logstash-2.3.4\bin\>logstash agent -f C:\logstash-2.3.4\bin\exampleConf.conf  
io/console not supported; tty will not be manipulated  
Settings: Default pipeline workers: 4  
Pipeline main started

Stops after this.

---

<div class="post-metadata">

**Author:** ![ramanamohan](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@ramanamohan](https://discuss.elastic.co/u/ramanamohan)\
**Post date:** [July 26, 2016, 8:43am UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276/10 "2016-07-26T08:43:49Z")

</div>

Tried adding as you suggested,

output {  
stdout {  
codec =\> rubydebug  
}  
elasticsearch {  
hosts =\> ["localhost:9200"]  
action =\> "index"  
index =\> "exampleIndex"  
}  
}

Nothing happens after this,

C:\logstash-2.3.4\bin\>logstash agent -f C:\logstash-2.3.4\bin\exampleConf.conf  
io/console not supported; tty will not be manipulated  
Settings: Default pipeline workers: 4  
Pipeline main started

And how can I overcome the "io/console not supported; tty will not be manipulated" message. ?

---

<div class="post-metadata">

**Author:** ![Sri\_ram](https://avatars.discourse-cdn.com/v4/letter/s/3da27b/32.png) [@Sri\_ram](https://discuss.elastic.co/u/Sri_ram)\
**Post date:** [July 26, 2016, 1:41pm UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276/11 "2016-07-26T13:41:36Z")

</div>

When you executed your conf file, were you able to see the output written to console (stdout). If you are able to see the output then it should create a index as per your config file. If not, try updating the log file by adding new lines and see.

---

<div class="post-metadata">

**Author:** ![niraj\_kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/niraj_kumar/32/4130_2.png) [@niraj\_kumar](https://discuss.elastic.co/u/niraj_kumar)\
**Post date:** [July 26, 2016, 4:47pm UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276/12 "2016-07-26T16:47:04Z")

</div>

What does ur ES log show? And can you start logstash with debug and see if you find something unusual.

---

<div class="post-metadata">

**Author:** ![ramanamohan](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@ramanamohan](https://discuss.elastic.co/u/ramanamohan)\
**Post date:** [July 27, 2016, 8:50am UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276/13 "2016-07-27T08:50:00Z")

</div>

I was getting "high disk watermark [90%] exceeded on" warning.

I made space in the disk and the warning is rectified.

I am unable to run the logstash in debug mode, I am getting some UsageError.

---

<div class="post-metadata">

**Author:** ![ramanamohan](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@ramanamohan](https://discuss.elastic.co/u/ramanamohan)\
**Post date:** [July 27, 2016, 8:54am UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276/14 "2016-07-27T08:54:04Z")

</div>

No I do not see the output on my console.

What new lines I should add and into which file ?

I even tried the example log and Conf files (first-pipeline.conf) provided in the Logstash setting page.

I don't see anything after "Pipeline main started".

---

<div class="post-metadata">

**Author:** ![ramanamohan](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@ramanamohan](https://discuss.elastic.co/u/ramanamohan)\
**Post date:** [July 27, 2016, 9:11am UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276/15 "2016-07-27T09:11:00Z")

</div>

I am able to create the index with the input as stdin.

But when I feed the input through some log files, the index is not created.

I think it is something related to sincedb, but don't know what is the exact issue.!!!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 30, 2016, 9:39am UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276/16 "2016-07-30T09:39:46Z")

</div>

> sincedb\_path =\> "null"

No, that does not disable sincedb. Use "nul" on Windows and "/dev/null" on all other platforms.

This thread is impossible to follow. If you still haven't resolved this please post your current configuration.

Until you've gotten the file input to read files properly you should disable the elasticsearch output and only keep the stdout output. I also suggest you enable verbose Logstash logging by starting it with `--debug`. Look for log lines containing "discover" and post them here.

---

<div class="post-metadata">

**Author:** ![ramanamohan](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@ramanamohan](https://discuss.elastic.co/u/ramanamohan)\
**Post date:** [August 1, 2016, 9:44am UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276/17 "2016-08-01T09:44:30Z")

</div>

Hi All,

Thanks for your support. I got the issue resolved.  
Had some issue with the input file Path. Gave full file path and it worked fine.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:45am UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276/18 "2017-07-06T04:45:38Z")

</div>


