# Logstash not able to read data from elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-not-able-to-read-data-from-elasticsearch/94185>\
**Category:** Logstash\
**Created:** [July 22, 2017, 2:55am UTC](https://discuss.elastic.co/t/logstash-not-able-to-read-data-from-elasticsearch/94185 "2017-07-22T02:55:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sushil1016](https://avatars.discourse-cdn.com/v4/letter/s/67e7ee/32.png) [@sushil1016](https://discuss.elastic.co/u/sushil1016)\
**Post date:** [July 22, 2017, 2:55am UTC](https://discuss.elastic.co/t/logstash-not-able-to-read-data-from-elasticsearch/94185/1 "2017-07-22T02:55:44Z")

</div>

Hello There,

I've a pre-populated elasticsearch and I am trying to use logstash to further analyse the data from elasticsearch. But whenever i run logstash, it never process any events, neither do i see anything in elasticsearch logs.

My conf file is:  
input {

# Read all documents from Elasticsearch matching the given query

elasticsearch {  
hosts =\> ["localhost:9200"]  
query =\> '{ "query": { "match": { "func\_name": "MPMComponentAudioStopDecodingReal" } }, "sort": ["\_doc"] }'  
}  
}

output {  
stdout { codec =\> rubydebug }  
}

when i run logstash in windows 10.  
logstash.bat -f logstash-elastic.conf  
Sending Logstash's logs to C:/Users/sushiku2/Downloads/ELK/logstash-5.4.0/logs which is now configured via log4j2.properties  
[2017-07-22T08:22:21,972][INFO][logstash.pipeline] Starting pipeline {"id"=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>5, "pipeline.max\_inflight"=\>500}  
[2017-07-22T08:22:22,629][INFO][logstash.pipeline] Pipeline main started  
[2017-07-22T08:22:22,801][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

I am facing same problem in Ubuntu system as well.  
I have the default .yml file for both elasticsearch and logstash.

Any help in this is much appreciated.

---

<div class="post-metadata">

**Author:** ![sushil1016](https://avatars.discourse-cdn.com/v4/letter/s/67e7ee/32.png) [@sushil1016](https://discuss.elastic.co/u/sushil1016)\
**Post date:** [July 22, 2017, 3:32am UTC](https://discuss.elastic.co/t/logstash-not-able-to-read-data-from-elasticsearch/94185/2 "2017-07-22T03:32:37Z")

</div>

I've found the solution for this problem when i ran logstash in debug mode and analysed its logs, looks like if you don't mention any index in input plugin for elastic search, it takes a default index of "logstash-\*". However in my case the index was 77777. I modified my conf file and it solved the problem.

input {

# Read all documents from Elasticsearch matching the given query

elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "77777"  
query =\> '{ "query": { "match": { "func\_name": "MPMComponentAudioStopDecodingReal" } }, "sort": ["\_doc"] }'  
}  
}

output {  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 19, 2017, 3:32am UTC](https://discuss.elastic.co/t/logstash-not-able-to-read-data-from-elasticsearch/94185/3 "2017-08-19T03:32:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
