# Logstash is not creating Indexes - SOLVED

**URL:** <https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984>\
**Category:** Logstash\
**Created:** [August 14, 2016, 5:25am UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984 "2016-08-14T05:25:27Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [August 14, 2016, 5:25am UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/1 "2016-08-14T05:25:27Z")

</div>

i have logstash running and its suddnely stopped creating indexes. I have installed logstash from the repository on Centos7.  
service logstash configtest is ok  
sudo service logstash start

starts log stash properly. In /var/log/logstash.log i can see {:timestamp=\>"2016-08-13T14:51:56.499000+0000", :message=\>"Pipeline main started"}

Below is my conf file  
input {  
file {  
path =\> "/etc/httpd/logs/access\_log"  
start\_position =\> "beginning"  
}  
}

filter {  
if [path] =~ "access" {  
mutate { replace =\> { "type" =\> "apache\_access" } }  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }  
}  
}  
date {  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
}  
}

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
}  
stdout { codec =\> rubydebug}  
}

when i do curl -XGET [http://localhost:9200/\_cat/indices?v](http://localhost:9200/_cat/indices?v) | grep logstash  
i can only see old ones and not the new one day something like  
logstash-2016.08.14 but i do not see any index also there is no error in logs as well.

I do not know what wrong i am doing here it was working fine. Please help

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 14, 2016, 2:07pm UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/2 "2016-08-14T14:07:59Z")

</div>

Have you looked in the Logstash log files for clues (they're usually in /var/log/logstash)? Is data actually being added to the end of /etc/httpd/logs/access\_log?

---

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [August 14, 2016, 2:54pm UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/3 "2016-08-14T14:54:58Z")

</div>

Sir,  
Yes i did check the logs and all it says pipeline started. To answer your other question yes access\_logs generating the data as i have few websites and one web based monitoring system running. So basically it should create and index logstash-2016.08.14 for today but there is nothing.  
Please help

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 14, 2016, 3:00pm UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/4 "2016-08-14T15:00:44Z")

</div>

Try increase the logging verbosity with `--verbose` and see if there are more clues in the log. If that doesn't help, increase it even more with `--debug`.

---

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [August 14, 2016, 3:02pm UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/5 "2016-08-14T15:02:21Z")

</div>

so one more thing i am starting logstash from systemd.  
sudo service logstash start.  
should i start it from bin directory bin/logstash -v -f /etc/logstsh/conf.d/file.conf ?

---

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [August 14, 2016, 4:10pm UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/6 "2016-08-14T16:10:32Z")

</div>

ok i have just noticed one thing, when i run logstash from command like as user say  
tom$ sudo service logstash start

it doesnt generate anything , then if i run it like below  
tom$ bin/logstash --verbose -f /etc/logstash/conf.d/webserver.conf

it doesnt do anything

however when i log in as root and do this  
root$ bin/logstash --verbose -f /etc/logstash/conf.d/webserver.conf

it generates logs and also generates index, so this means its a permission problem ?. One more thing is if even root i start as  
root$ service logstash start  
it doesnt again generate the data in index. Whats the issue in here ? Please help

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 14, 2016, 6:34pm UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/7 "2016-08-14T18:34:57Z")

</div>

> should i start it from bin directory bin/logstash -v -f /etc/logstsh/conf.d/file.conf ?

That can be useful for debugging, but eventually you'll want to run it via systemd.

> it generates logs and also generates index, so this means its a permission problem ?

Yes, probably. Does the logstash user have read access to the log files?

> is if even root i start as  
> root$ service logstash start  
> it doesnt again generate the data in index.

Which user runs `service logstash start` doesn't affect which user the service runs as.

---

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [August 29, 2016, 10:04am UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/8 "2016-08-29T10:04:08Z")

</div>

ok here is one more info if i run below  
curl -XGET localhost:9200/logstash-\*/\_field\_stats?fields=@timestamp

i get below  
{"\_shards":{"total":40,"successful":40,"failed":0},"indices":{"\_all":{"fields":{"@timestamp":{"max\_doc":9114,"doc\_count":9114,"density":100,"sum\_doc\_freq":36456,"sum\_total\_term\_freq":-1,"min\_value":1470571575000,"min\_value\_as\_string":"2016-08-07T12:06:15.000Z","max\_value":1471190833000,"max\_value\_as\_string":"2016-08-14T16:07:13.000Z"}}}}}

as you can see the index is there only till 14th Aug and its not generating now. At this time logstash / elasticsearch/ kibana all running fine and i cant see any error. Whats wrong in here any more inputs ?.  
Should i remove all three and do it again ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 29, 2016, 11:12am UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/9 "2016-08-29T11:12:55Z")

</div>

Is the file input that tails /etc/httpd/logs/access\_log your only input? Has the file been updated since Aug 14? Has Logstash been running since then? What's Logstash's current position in that file (according to the sincedb file)?

---

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [August 29, 2016, 11:15am UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/10 "2016-08-29T11:15:34Z")

</div>

Yes sir the file updates everyday and with lots of log  
And yes logstash was running all the time. I am now doing a fresh install of ELK on the same machine removed everything as it's not been working since long. I must have done something wrong somewhere so let's see if a fresh setup will work.  
Thank you for your time and effort and i will update you if the new setup is working.

---

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [August 29, 2016, 12:18pm UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/11 "2016-08-29T12:18:55Z")

</div>

Now even the fresh installation of everything is not creating the index. Arrgggh  
My conf file is at /etc/logstash/conf.d/01-webserver.conf

input {

file {

path =\> "/etc/httpd/logs/access\_log"

start\_position =\> "beginning"

}

}

filter {

if [type] == "apache-access"

{

grok {

match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }

}

}

date {

match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]

}

}

output {

elasticsearch {

hosts =\> ["localhost:9200"]

}  
input {

file {

path =\> "/etc/httpd/logs/access\_log"

start\_position =\> "beginning"

}

}

filter {

if [type] == "apache-access"

{

grok {

match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }

}

}

date {

match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]

}

}

output {

elasticsearch {

hosts =\> ["localhost:9200"]

}  
input {

file {

path =\> "/etc/httpd/logs/access\_log"

start\_position =\> "beginning"

}

}

filter {

if [type] == "apache-access"

{

grok {

match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }

}

}

date {

match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]

}

}

output {

elasticsearch {

hosts =\> ["localhost:9200"]

}  
stdout { codec =\> rubydebug }

}

is there is anything wrong with this it ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 29, 2016, 12:49pm UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/12 "2016-08-29T12:49:00Z")

</div>

Repeating things I've said before that I don't think you've answered:

- Try increase the logging verbosity with `--verbose` and see if there are more clues in the log. If that doesn't help, increase it even more with `--debug`.
- Does the logstash user have read access to the log files?

---

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [August 29, 2016, 12:52pm UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/13 "2016-08-29T12:52:51Z")

</div>

ok sir let me paste you some more logs in a while To answer your last question i added the logstash user to adm group

sudo gpasswd -a logstash adm

so i guess this part is ok ? . Now let me post few more logs with --verbose and --debug

---

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [August 29, 2016, 12:57pm UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/14 "2016-08-29T12:57:23Z")

</div>

Here is the output of bin/logstash --verbose -f /etc/logstash/conf.d/webserver.conf. This is the only conf file i have for now. Once i run this i have clicked on my web pages to generate the logs and i can see using tail that access logs generating the data.Please see below link for the --verbose output

> <https://gist.github.com/anonymous/74fa56e21bd8bb2b3020269967bc8413>

---

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [August 29, 2016, 1:05pm UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/15 "2016-08-29T13:05:16Z")

</div>

Logstash --debug ouput

> <https://gist.github.com/anonymous/59edf7935d87aaddef7b5f6e2827b9c9>

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 29, 2016, 1:25pm UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/16 "2016-08-29T13:25:10Z")

</div>

> ```
> {:timestamp=>"2016-08-29T13:02:19.163000+0000", :message=>"_globbed_files: /etc/httpd/logs/access_log: glob is: []", :level=>:debug, :file=>"filewatch/watch.rb", :line=>"346", :method=>"_globbed_files"}
> 
> ```

This indicates that /etc/httpd/logs/access\_log either doesn't exist or that one of the directories leading up to that file isn't accessible to the user Logstash runs as.

---

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [August 29, 2016, 1:45pm UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/17 "2016-08-29T13:45:37Z")

</div>

ok i got the point in here as when i ran the command  
sudo bin/logstash --debug -f /etc/logstash/conf.d/webserver.conf it worked and generated the index. So i have added logstash user to adm group which means it should have read access to the apache log files. Can you please tell me what group i should add logstash user to so that it works ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 29, 2016, 2:01pm UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/18 "2016-08-29T14:01:45Z")

</div>

> Can you please tell me what group i should add logstash user to so that it works ?

Well, what _are_ the permissions and ownerships of the files and directories in question?

---

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [August 29, 2016, 2:18pm UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/19 "2016-08-29T14:18:26Z")

</div>

so for the directory

drwx------ 2 root root 4096 Aug 28 03:33 httpd

and for file

-rw-r--r-- 1 root root 428540 Aug 29 14:16 access\_log

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 29, 2016, 2:21pm UTC](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984/20 "2016-08-29T14:21:46Z")

</div>

Then only the root user can access files in the httpd directory. /etc, /etc/httpd, and /etc/httpd/logs all need to be readable and executable to the logstash user.

To access a file in a directory you normally only need it to be executable but since Logstash attempts to resolve wildcards I'd assume that it also requires the read bit to be set even if you're not using any wildcards.

[Next page](https://discuss.elastic.co/t/logstash-is-not-creating-indexes-solved/57984.md?page=2)
