# Logstash not able to create index on Elastic

**URL:** <https://discuss.elastic.co/t/logstash-not-able-to-create-index-on-elastic/170417>\
**Category:** Logstash\
**Created:** [February 28, 2019, 10:37pm UTC](https://discuss.elastic.co/t/logstash-not-able-to-create-index-on-elastic/170417 "2019-02-28T22:37:35Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![vijayakrishna.rg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vijayakrishna.rg/32/36798_2.png) [@vijayakrishna.rg](https://discuss.elastic.co/u/vijayakrishna.rg)\
**Post date:** [February 28, 2019, 10:37pm UTC](https://discuss.elastic.co/t/logstash-not-able-to-create-index-on-elastic/170417/1 "2019-02-28T22:37:35Z")

</div>

Hi,

I have installed logstash on my elastic machine and pointed to one of the log file as input, i have started logstash service, i don't see any logs coming into elastic either index in elastic, when i tail logstash log file looks everything fine.

**logstash log file**

_[2019-02-28T22:35:18,311][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.5.4"}_  
_[2019-02-28T22:35:22,278][WARN][logstash.outputs.elasticsearch] You are using a deprecated config setting "document\_type" set in elasticsearch. Deprecated settings will continue to work, but are scheduled for removal from logstash in the future. Document types are being deprecated in Elasticsearch 6.0, and removed entirely in 7.0. You should avoid this feature If you have any questions about this, please visit the #logstash channel on freenode irc. {:name=\>"document\_type", :plugin=\>\<LogStash::Outputs::ElasticSearch ssl\_certificate\_verification=\>false, template\_name=\>"loadtesttemaplate", hosts=\>[[//localhost:9200](https://localhost:9200)], index=\>"loadtest-%{+YYYY.MM.dd}", manage\_template=\>false, id=\>"36c65c8187301c6a89bc9244fd69799a8a5b1dad38e50222e3e434e76cf0ec63", document\_type=\>"loadtest", enable\_metric=\>true, codec=\>\<LogStash::Codecs::Plain id=\>"plain\_7b56ecc4-666d-4d9e-8ca9-3753ddcfbaae", enable\_metric=\>true, charset=\>"UTF-8"\>, workers=\>1, template\_overwrite=\>false, doc\_as\_upsert=\>false, script\_type=\>"inline", script\_lang=\>"painless", script\_var\_name=\>"event", scripted\_upsert=\>false, retry\_initial\_interval=\>2, retry\_max\_interval=\>64, retry\_on\_conflict=\>1, action=\>"index", sniffing=\>false, sniffing\_delay=\>5, timeout=\>60, pool\_max=\>1000, pool\_max\_per\_route=\>100, resurrect\_delay=\>5, validate\_after\_inactivity=\>10000, http\_compression=\>false\>}_  
_[2019-02-28T22:35:22,332][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>8, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50}_  
_[2019-02-28T22:35:22,919][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}_  
_[2019-02-28T22:35:23,172][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}_  
_[2019-02-28T22:35:23,256][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>6}_  
\_[2019-02-28T22:35:23,262][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document _type {:es\_version=\>6}_  
_[2019-02-28T22:35:23,299][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//localhost:9200](https://localhost:9200)"]}_  
_[2019-02-28T22:35:23,797][INFO][logstash.inputs.file] No sincedb\_path set, generating one based on the "path" setting {:sincedb\_path=\>"/var/lib/logstash/plugins/inputs/file/.sincedb\_10d87552dcaaf428d07d4ce3882b5665", :path=\>["/root/benchmark"]}_  
_[2019-02-28T22:35:23,873][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0xde916db run\>"}_  
_[2019-02-28T22:35:23,968][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>[]}_  
_[2019-02-28T22:35:23,992][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections_  
_[2019-02-28T22:35:24,403][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}_

here are the config files on elasticsearch machine for logstash  
**cat 02-beats-input.conf**

input {  
file {  
path =\> "/root/benchmark"  
}  
}

**cat 10-syslog-filter.conf**

filter {  
dissect {  
mapping =\> { "message" =\> "%{topic} %{records\_pushed} %{records\_sec} %{avg\_latency} %{max\_latency} %{percentile\_50} %{percentile\_95} %{percentile\_99} %{percentile\_99\_9}" }  
}  
}

**cat 30-elasticsearch-output.conf**

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
ssl\_certificate\_verification =\> false  
manage\_template =\> false  
document\_type =\> "loadtest"  
index =\> "loadtest-%{+YYYY.MM.dd}"  
template\_name =\> "loadtesttemaplate"  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 28, 2019, 10:59pm UTC](https://discuss.elastic.co/t/logstash-not-able-to-create-index-on-elastic/170417/2 "2019-02-28T22:59:43Z")

</div>

Are you appending lines to /root/benchmark?

If you want to see what filewatch is doing then enable --log.level trace (debug is not enough).

---

<div class="post-metadata">

**Author:** ![vijayakrishna.rg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vijayakrishna.rg/32/36798_2.png) [@vijayakrishna.rg](https://discuss.elastic.co/u/vijayakrishna.rg)\
**Post date:** [February 28, 2019, 11:20pm UTC](https://discuss.elastic.co/t/logstash-not-able-to-create-index-on-elastic/170417/3 "2019-02-28T23:20:21Z")

</div>

yes, i am appending lines manually to file, does it fetch appended lines like filebeat?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 28, 2019, 11:41pm UTC](https://discuss.elastic.co/t/logstash-not-able-to-create-index-on-elastic/170417/4 "2019-02-28T23:41:06Z")

</div>

> [@vijayakrishna.rg](#):
>
> does it fetch appended lines like filebeat?

Yes. Try enabling --log.level trace and see if filewatch notices the new lines.

---

<div class="post-metadata">

**Author:** ![vijayakrishna.rg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vijayakrishna.rg/32/36798_2.png) [@vijayakrishna.rg](https://discuss.elastic.co/u/vijayakrishna.rg)\
**Post date:** [February 28, 2019, 11:45pm UTC](https://discuss.elastic.co/t/logstash-not-able-to-create-index-on-elastic/170417/5 "2019-02-28T23:45:41Z")

</div>

it's not finding any logs from the file i have created manually and also am keep amending lines into that file, given permissions as expected and group and user to that file is logstash, still not getting any data from that file.

if i point to logstash log file then it's collecting all the logs from it.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 28, 2019, 11:53pm UTC](https://discuss.elastic.co/t/logstash-not-able-to-create-index-on-elastic/170417/6 "2019-02-28T23:53:48Z")

</div>

--log.level trace will show if it finds the file, how big it thinks the file is etc.

---

<div class="post-metadata">

**Author:** ![vijayakrishna.rg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vijayakrishna.rg/32/36798_2.png) [@vijayakrishna.rg](https://discuss.elastic.co/u/vijayakrishna.rg)\
**Post date:** [March 1, 2019, 12:03am UTC](https://discuss.elastic.co/t/logstash-not-able-to-create-index-on-elastic/170417/7 "2019-03-01T00:03:52Z")

</div>

Thanks looks like it's working.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2019, 12:03am UTC](https://discuss.elastic.co/t/logstash-not-able-to-create-index-on-elastic/170417/8 "2019-03-29T00:03:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
