# Logstash is not create indexes

**URL:** <https://discuss.elastic.co/t/logstash-is-not-create-indexes/81568>\
**Category:** Logstash\
**Created:** [April 7, 2017, 6:15am UTC](https://discuss.elastic.co/t/logstash-is-not-create-indexes/81568 "2017-04-07T06:15:32Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![igormarqs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igormarqs/32/17678_2.png) [@igormarqs](https://discuss.elastic.co/u/igormarqs)\
**Post date:** [April 7, 2017, 6:15am UTC](https://discuss.elastic.co/t/logstash-is-not-create-indexes/81568/1 "2017-04-07T06:15:32Z")

</div>

hi, i have started with ELK but i have some error.  
when i start kibana and look for some index name or pattern, can't find any logstash-\*

if i use option **"Use event times to create index names [DEPRECATED]"** with name _"logstash"_\* i can find it on kibana.

Attempted to match the following indices and aliases:  
{"index":"logstash-2017.04.04","min":1491264000000,"max":1491350399999}  
{"index":"logstash-2017.04.05","min":1491350400000,"max":1491436799999}  
{"index":"logstash-2017.04.06","min":1491436800000,"max":1491523199999}  
{"index":"logstash-2017.04.07","min":1491523200000,"max":1491609599999}  
{"index":"logstash-2017.04.08","min":1491609600000,"max":1491695999999}  
{"index":"logstash-2017.04.09","min":1491696000000,"max":1491782399999}  
{"index":"logstash-2017.04.10","min":1491782400000,"max":1491868799999}

**here is my logstash.yml =\>** [https://ptpb.pw/Y0vb](https://ptpb.pw/Y0vb)  
**and here my pipeline.conf**

```
input {   
        file {
                path => "/home/reversal/fakelogs/*.log"
                start_position => beginning 
                ignore_older => 0
        }
        beats {
                port => "5043"
        }
}
filter {
        grok {
                match => { "message" => "%{COMBINEDAPACHELOG}" }
        }
         date {
                match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]
        }
        geoip {
                source => "clientip"
        }
}
output {
        elasticsearch {
                hosts => ["129.129.129.137:63200"]
                index => "logstash-%{+yyyy/MM/dd HH:mm:ss Z||yyyy/MM/dd Z}"
}
}

```

**and here is my logstash log:**

```
> [2017-04-07T03:10:31,600][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[http://129.129.129.137:63200/]}}
> [2017-04-07T03:10:31,604][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck_url=>http://129.129.129.137:63200/, :path=>"/"}
> [2017-04-07T03:10:31,696][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=>#<URI::HTTP:0x726ba01a URL:http://129.129.129.137:63200/>}
> [2017-04-07T03:10:31,698][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=>nil}
> [2017-04-07T03:10:31,741][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage_template=>{"template"=>"logstash-*", "version"=>50001, "settings"=>{"index.refresh_interval"=>"5s"}, "mappings"=>{"_default_"=>{"_all"=>{"enabled"=>true, "norms"=>false}, "dynamic_templates"=>[{"message_field"=>{"path_match"=>"message", "match_mapping_type"=>"string", "mapping"=>{"type"=>"text", "norms"=>false}}}, {"string_fields"=>{"match"=>"*", "match_mapping_type"=>"string", "mapping"=>{"type"=>"text", "norms"=>false, "fields"=>{"keyword"=>{"type"=>"keyword"}}}}}], "properties"=>{"@timestamp"=>{"type"=>"date", "include_in_all"=>false}, "@version"=>{"type"=>"keyword", "include_in_all"=>false}, "geoip"=>{"dynamic"=>true, "properties"=>{"ip"=>{"type"=>"ip"}, "location"=>{"type"=>"geo_point"}, "latitude"=>{"type"=>"half_float"}, "longitude"=>{"type"=>"half_float"}}}}}}}}
> [2017-04-07T03:10:31,746][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>[#<URI::Generic:0x2e671c80 URL://129.129.129.137:63200>]}
> [2017-04-07T03:10:31,792][INFO][logstash.filters.geoip] Using geoip database {:path=>"/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-filter-geoip-4.0.4-java/vendor/GeoLite2-City.mmdb"}
> [2017-04-07T03:10:31,805][INFO][logstash.pipeline] Starting pipeline {"id"=>"main", "pipeline.workers"=>4, "pipeline.batch.size"=>125, "pipeline.batch.delay"=>5, "pipeline.max_inflight"=>500}
> [2017-04-07T03:10:32,461][INFO][logstash.inputs.beats] Beats inputs: Starting input listener {:address=>"0.0.0.0:5043"}
> [2017-04-07T03:10:32,506][INFO][logstash.pipeline] Pipeline main started
> [2017-04-07T03:10:32,613][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=>63001}
> [reversal@rv03prd ~]$ 

```

what i missing?  
i appreciate any help.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 7, 2017, 6:35am UTC](https://discuss.elastic.co/t/logstash-is-not-create-indexes/81568/2 "2017-04-07T06:35:07Z")

</div>

> [@igormarqs](#):
>
> index =\> "logstash-%{+yyyy/MM/dd HH:mm:ss Z||yyyy/MM/dd Z}"

This is wrong. What is it you are trying to achieve? What is wrong with the default pattern?

---

<div class="post-metadata">

**Author:** ![igormarqs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igormarqs/32/17678_2.png) [@igormarqs](https://discuss.elastic.co/u/igormarqs)\
**Post date:** [April 7, 2017, 6:43am UTC](https://discuss.elastic.co/t/logstash-is-not-create-indexes/81568/3 "2017-04-07T06:43:01Z")

</div>

It does not work, i have tried

no index. i can try again and post outputs

i have used  
`index => "logstash-%{+YYYY.MM.dd}"`

but not working and without `index => "logstash-%{+YYYY.MM.dd}"` same thing

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 7, 2017, 7:17am UTC](https://discuss.elastic.co/t/logstash-is-not-create-indexes/81568/4 "2017-04-07T07:17:31Z")

</div>

Can you remove the index specification from the elastic search output (default will be used) as well as the `ignore_older` statement for the file input in order to see if this makes a difference? You may also need to remove the `sincedb` file in order to get the files processed again.

---

<div class="post-metadata">

**Author:** ![igormarqs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igormarqs/32/17678_2.png) [@igormarqs](https://discuss.elastic.co/u/igormarqs)\
**Post date:** [April 7, 2017, 1:06pm UTC](https://discuss.elastic.co/t/logstash-is-not-create-indexes/81568/5 "2017-04-07T13:06:19Z")

</div>

ok, i comment that options like this:

```
[reversal@rv03prd ~]$ sudo cat /etc/logstash/conf.d/pipeline.conf
input {   
        file {
                path => "/home/reversal/fakelogs/*.log"
                start_position => beginning 
                #ignore_older => 0
        }
        beats {
                port => "5043"
        }
}
filter {
        grok {
                match => { "message" => "%{COMBINEDAPACHELOG}" }
        }
         date {
                match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]
        }
        geoip {
                source => "clientip"
        }
}
output {
        elasticsearch {
                hosts => ["129.129.129.137:63200"]
                #index => "logstash-%{+yyyy/MM/dd HH:mm:ss Z||yyyy/MM/dd Z}"
}
#stdout { codec => rubydebug}
}

```

and restart logstash but still cant find "logstash-\*"

sorry to ask but how can i delete `sincedb`?

```
[reversal@rv03prd ~]$ sudo find / -name sincedb
[reversal@rv03prd ~]$

```

**and kibana \> dev tools**

```
DELETE sincedb
{
  "error": {
    "root_cause": [
      {
        "type": "index_not_found_exception",
        "reason": "no such index",
        "resource.type": "index_or_alias",
        "resource.id": "sincedb",
        "index_uuid": "_na_",
        "index": "sincedb"
      }
    ],
    "type": "index_not_found_exception",
    "reason": "no such index",
    "resource.type": "index_or_alias",
    "resource.id": "sincedb",
    "index_uuid": "_na_",
    "index": "sincedb"
  },
  "status": 404
}
```

---

<div class="post-metadata">

**Author:** ![igormarqs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igormarqs/32/17678_2.png) [@igormarqs](https://discuss.elastic.co/u/igormarqs)\
**Post date:** [April 7, 2017, 1:24pm UTC](https://discuss.elastic.co/t/logstash-is-not-create-indexes/81568/6 "2017-04-07T13:24:51Z")

</div>

sorry, find info about it on [https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html)

stop logstash and now i remove `sincedb` after find it on:

```
[root@rv03prd reversal]# find / -name .sincedb*
/var/lib/logstash/plugins/inputs/file/.sincedb_79a16c88523e2ae2caee8f60623d8fbc
[root@rv03prd reversal]# sudo rm -f /var/lib/logstash/plugins/inputs/file/.sincedb_79a16c88523e2ae2caee8f60623d8fbc 
[root@rv03prd reversal]#

```

start logstash again but cant find any "logstash\*" index

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2017, 2:13pm UTC](https://discuss.elastic.co/t/logstash-is-not-create-indexes/81568/8 "2017-05-05T14:13:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
